We issue security patches and updates for the latest major version of Bilo Bunker.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
The Bilo Bunker team takes the security of our application, Nostr key handling, and RPC signing operations seriously.
If you discover a security vulnerability in Bilo Bunker:
- Do NOT open a public GitHub issue.
- Email your findings directly to the repository maintainer at
z@emre.xyzor submit a private security advisory via GitHub Security Advisories at https://github.com/workouse/bilo-bunker/security/advisories. - Include details of the vulnerability, steps to reproduce, and any proof-of-concept code.
- Acknowledgment: We aim to acknowledge receipt of vulnerability reports within 24 to 48 hours.
- Assessment & Patch: We will work to verify the vulnerability and issue a patch within 7 days for critical issues.
- Disclosure: Public disclosure will take place after a patch has been released and users have had reasonable time to upgrade.
Thank you for helping keep Bilo Bunker and the Nostr ecosystem secure!