Skip to content

Security: aipo-lenshow/NDBot

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Email: AiPo@ailenshow.com

Please include:

  • A short description of the issue.
  • Steps to reproduce.
  • Affected version.
  • Whether the issue exposes user data, credentials, cookies, rclone config, Telegram sessions, or downloaded files.

The project follows coordinated disclosure. Please give the maintainer time to investigate and publish a fix before sharing details publicly.

Sensitive Data

NDBot deployments may contain sensitive runtime data:

  • .env
  • sessions/
  • cookies/
  • downloads/
  • rclone/rclone.conf
  • SQLite databases and Docker volumes

These files are intentionally excluded from the public repository. Never attach them to public issues.

Supported Version

Security fixes target the latest open-source release.

There aren't any published security advisories