Skip to content

Security: LicenseChain/LicenseChain-TG-Bot

Security

SECURITY.md

Security Policy

Supported Versions

We provide security updates for the following versions:

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

Please report security vulnerabilities to contact@voxhash.dev with the following information:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

We will acknowledge receipt within 48 hours and provide a detailed response within 7 days.

What to Include

  • Type of vulnerability (e.g., XSS, SQL injection, authentication bypass)
  • Affected component or file
  • Proof of concept or detailed steps
  • Potential impact and severity

Disclosure Policy

  • We will acknowledge your report within 48 hours
  • We will keep you informed of the progress
  • We will credit you in the security advisory (unless you prefer to remain anonymous)
  • We will not disclose the vulnerability publicly until a fix is available

Security Best Practices

When using this bot:

  • Keep dependencies up to date
  • Use strong API keys and tokens
  • Enable webhook secret verification when using webhook mode
  • Regularly review and rotate credentials
  • Monitor logs for suspicious activity
  • Follow PostgreSQL security best practices

There aren’t any published security advisories