Skip to content

Security: sparrowapp-dev/sparrow-bot

Security

SECURITY.md

Security Policy

Supported Versions

We currently support the following versions with security updates:

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

We take the security of Sparrow Bot seriously. If you believe you've found a security vulnerability, please follow these steps:

  1. Do not disclose the vulnerability publicly
  2. Email us at [email protected] with details about the vulnerability
  3. Include the following information:
    • Type of vulnerability
    • Full path to the vulnerable file
    • Steps to reproduce
    • Potential impact

What to Expect

  • We will acknowledge receipt of your report within 48 hours
  • We will provide an initial assessment of the report within 7 days
  • We will work with you to understand and validate the issue
  • We will release a fix as soon as possible, depending on the complexity of the issue

Security Best Practices

When using Sparrow Bot, please follow these security best practices:

  1. Keep your GitHub tokens secure and never commit them to your repository
  2. Use the principle of least privilege when creating tokens for the bot
  3. Regularly review the permissions granted to the bot
  4. Monitor the bot's activity in your repositories
  5. Keep the bot updated to the latest version

Responsible Disclosure

We follow the practice of responsible disclosure. After a fix has been released, we encourage you to submit a detailed report about the vulnerability. This helps the community learn from the issue and improve security practices.

Thank you for helping keep Sparrow Bot and its users safe!

There aren’t any published security advisories