Skip to content

Security: worddevs/server-lavalink

Security

SECURITY.md

Security Policy

The WORD DEVS team takes the security of its infrastructure and Discord bot nodes seriously.


Supported Versions

Only the current production release receives security patches and plugin token mitigations.

Version Supported
1.0.x ✅
< 1.0.0 ❌

Reporting a Vulnerability

If you discover a security vulnerability, token leakage vector, or denial-of-service issue:

  1. Do NOT open a public issue.
  2. Report the vulnerability privately through GitHub Private Vulnerability Reporting via the Security tab of this repository.
  3. Include details of the vulnerability:
    • Reproduction steps or payload examples.
    • Potential impact on host or Discord bot consumers.
    • Proposed fixes (if available).

We will acknowledge receipt within 48 hours and work with you on patch coordination prior to public release disclosure.

There aren't any published security advisories