Skip to content

Latest commit

 

History

History
58 lines (43 loc) · 2.27 KB

File metadata and controls

58 lines (43 loc) · 2.27 KB

Security Policy

Supported version

Security fixes are made against the current production branch of PolyELO Bot. Older deployments and forks may not receive fixes.

Reporting a vulnerability

Do not disclose vulnerabilities, exposed credentials, or personal data in a public GitHub issue or Discord channel.

Use GitHub's private vulnerability-reporting form for reports involving the bot, its API, production data, authentication, authorization, or credentials. Include:

  • a concise description of the issue and its potential impact;
  • affected components or versions;
  • reproduction steps or a proof of concept that does not access other users' data; and
  • any suggested mitigation.

When GitHub's private form is unavailable, invoke /staffhelp with no options. In the modal, enter:

Short summary: Private security report
Detailed description: Please contact me privately.
Optional context: A safe indication of the affected area, if useful

Do not include vulnerability details in that initial Discord request. In production, /staffhelp relays directly to the server's configured staff-only channel and configured Helper role without writing a local JSONL copy. The development beta additionally stores its restricted JSONL feedback record. Staff will arrange a private follow-up.

For an ordinary privacy access, correction, or deletion request, follow PRIVACY.md instead of the security-reporting process.

What to expect

We aim to acknowledge a security report within seven days and provide an initial assessment or status update within 14 days. Remediation time depends on severity and complexity. Please allow a reasonable period for investigation and remediation before public disclosure.

If a report identifies unauthorized access to Discord API data, the maintainers will contain the issue, rotate affected credentials, assess the data involved, and notify Discord and affected users when required.

Scope and safe harbor

Good-faith testing must avoid service disruption, social engineering, credential theft, persistence, destructive actions, and access to data that does not belong to the reporter. Stop testing and report immediately if personal data or credentials are encountered.