SilverElixir commited on
Commit
816060f
·
1 Parent(s): 4980a0b

Docs: SECURITY.md in English to match README and LICENSE

Browse files
Files changed (1) hide show
  1. SECURITY.md +6 -6
SECURITY.md CHANGED
@@ -1,10 +1,10 @@
1
  # Security Policy
2
 
3
- Нашли уязвимость — напишите владельцу через GitHub Issues (приватно, без деталей
4
- эксплуатации в публичном тексте) или в личных сообщениях Telegram-бота.
5
 
6
- Что полезно прислать: где (файл и строка), что может сделать атакующий,
7
- как воспроизвести на тестовом окружении. Не присылайте боевые ключи и токены.
8
 
9
- Секреты в `.env` и переменные окружения никогда не коммитятся (см. `.gitignore`).
10
- Если ключ утек — скажите об этом прямо, ключ будет перевыпущен.
 
1
  # Security Policy
2
 
3
+ Found a vulnerability? Please report it privately — open a GitHub issue
4
+ without exploit details in the public text, or message the bot owner directly.
5
 
6
+ Helpful reports include: where (file and line), what an attacker could do,
7
+ and how to reproduce it in a test environment. Never send live keys or tokens.
8
 
9
+ Secrets in `.env` and environment variables are never committed (see
10
+ `.gitignore`). If a key has leaked, say so directly and it will be rotated.