If you discover a security vulnerability, please report it privately:
- Do NOT open a public issue
- Email: create an issue with "Security" label
- Include steps to reproduce
I'll respond as soon as possible.
| Version | Supported |
|---|---|
| latest | ✅ |
When deploying this bot:
- Keep your
.envfile secure and never commit it - Use strong passwords for the web dashboard
- Restrict
LAPLACED_ALLOWED_USER_IDSto trusted users only - Run behind a reverse proxy with HTTPS for webhooks