Security fixes are made against the current production branch of PolyELO Bot. Older deployments and forks may not receive fixes.
Do not disclose vulnerabilities, exposed credentials, or personal data in a public GitHub issue or Discord channel.
Use GitHub's private vulnerability-reporting form for reports involving the bot, its API, production data, authentication, authorization, or credentials. Include:
- a concise description of the issue and its potential impact;
- affected components or versions;
- reproduction steps or a proof of concept that does not access other users' data; and
- any suggested mitigation.
When GitHub's private form is unavailable, invoke /staffhelp with no options.
In the modal, enter:
Short summary: Private security report
Detailed description: Please contact me privately.
Optional context: A safe indication of the affected area, if useful
Do not include vulnerability details in that initial Discord request. In
production, /staffhelp relays directly to the server's configured staff-only
channel and configured Helper role without writing a local JSONL copy. The
development beta additionally stores its restricted JSONL feedback record.
Staff will arrange a private follow-up.
For an ordinary privacy access, correction, or deletion request, follow PRIVACY.md instead of the security-reporting process.
We aim to acknowledge a security report within seven days and provide an initial assessment or status update within 14 days. Remediation time depends on severity and complexity. Please allow a reasonable period for investigation and remediation before public disclosure.
If a report identifies unauthorized access to Discord API data, the maintainers will contain the issue, rotate affected credentials, assess the data involved, and notify Discord and affected users when required.
Good-faith testing must avoid service disruption, social engineering, credential theft, persistence, destructive actions, and access to data that does not belong to the reporter. Stop testing and report immediately if personal data or credentials are encountered.