Skip to content

Security: workouse/bilo-bunker

Security

SECURITY.md

Security Policy

Supported Versions

We issue security patches and updates for the latest major version of Bilo Bunker.

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

The Bilo Bunker team takes the security of our application, Nostr key handling, and RPC signing operations seriously.

If you discover a security vulnerability in Bilo Bunker:

  1. Do NOT open a public GitHub issue.
  2. Email your findings directly to the repository maintainer at z@emre.xyz or submit a private security advisory via GitHub Security Advisories at https://github.com/workouse/bilo-bunker/security/advisories.
  3. Include details of the vulnerability, steps to reproduce, and any proof-of-concept code.

Security Response SLA

  • Acknowledgment: We aim to acknowledge receipt of vulnerability reports within 24 to 48 hours.
  • Assessment & Patch: We will work to verify the vulnerability and issue a patch within 7 days for critical issues.
  • Disclosure: Public disclosure will take place after a patch has been released and users have had reasonable time to upgrade.

Thank you for helping keep Bilo Bunker and the Nostr ecosystem secure!

There aren't any published security advisories