We provide security updates for the following versions:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
Please report security vulnerabilities to contact@voxhash.dev with the following information:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and provide a detailed response within 7 days.
- Type of vulnerability (e.g., XSS, SQL injection, authentication bypass)
- Affected component or file
- Proof of concept or detailed steps
- Potential impact and severity
- We will acknowledge your report within 48 hours
- We will keep you informed of the progress
- We will credit you in the security advisory (unless you prefer to remain anonymous)
- We will not disclose the vulnerability publicly until a fix is available
When using this bot:
- Keep dependencies up to date
- Use strong API keys and tokens
- Enable webhook secret verification when using webhook mode
- Regularly review and rotate credentials
- Monitor logs for suspicious activity
- Follow PostgreSQL security best practices