| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability within Hotbound-AI, please follow these steps:
- DO NOT disclose the vulnerability publicly
- Send a detailed report to evtran0209@gmail.com
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if possible)
You can expect:
- Initial response within 48 hours
- Regular updates on the progress
- Full credit for the discovery (if you wish)
- All API keys and sensitive credentials are stored in environment variables
- Dependencies are regularly updated via Dependabot
- Code scanning is enabled to detect potential security issues
- Secret scanning is enabled to prevent accidental commits of tokens