Skip to content

Security: cvsz/zLinebot-automos

SECURITY.md

Security Policy

Supported Versions

This repository is actively maintained on the default branch.

Reporting a Vulnerability

Please do not open public issues for vulnerabilities.

Instead, report responsibly with:

  • Affected component(s)
  • Reproduction steps
  • Impact assessment
  • Proposed mitigation (if available)

Send reports to: security@zlinebot.example (replace with your actual security mailbox).

Response Targets

  • Initial acknowledgement: within 72 hours
  • Triage update: within 7 days
  • Remediation plan: as soon as severity is confirmed

Best Practices for Operators

  • Rotate generated secrets before production go-live.
  • Keep Docker base images and host OS patched.
  • Restrict exposed network surfaces to required ports only.
  • Enable HTTPS with trusted certificates.

Documentation Refresh — 2026-03-26 (UTC)

  • Revalidated the security reporting process and response expectations section.
  • Audit scope: repository-wide markdown and operational-documentation verification pass.

There aren't any published security advisories