We actively monitor and patch security vulnerabilities on the latest release of GhostBot.
| Version | Supported |
|---|---|
| v4.0.x | ✅ |
| < 4.0 | ❌ |
Do NOT open a public GitHub issue for security vulnerabilities or API key leaks.
If you discover a potential security issue (such as token exposure, insecure temporary URL handling, or API credential leaks), please report it privately:
- Email the maintainer directly at your contact email or via private GitHub Security Advisory.
- Include steps to reproduce the vulnerability and any relevant logs.
We aim to respond to security reports within 24 hours and patch critical secret/token vulnerabilities immediately.