Security fixes are applied to the latest released Core version. Before
v1.0.0, upgrading to the newest pre-release or stable tag may be required.
Please do not open a public issue for a suspected vulnerability or include credentials, database dumps, Telegram identifiers, source URLs, tokens, or production logs in an issue.
Use GitHub's private vulnerability reporting for FreshLabDev/core when it is
available. If it is not available, contact an Asterfield maintainer privately
through an existing trusted channel and include only the minimum reproduction
details needed to investigate.
We will acknowledge a report, assess affected versions, coordinate a fix, and publish an advisory when disclosure is safe.
- Keep
.env, PostgreSQL dumps, Telegram Bot API state, and media-cache files outside Git. - Use unique strong passwords for the owner and every bot role.
- Do not publish the PostgreSQL or local Bot API ports directly to the internet.
- Back up the database before applying a release with new migrations.
- Review migration grants,
SECURITY DEFINERownership, andsearch_pathwhenever a database API changes.