Before v1.0.0, security fixes are released from the latest minor version. Users should upgrade to the newest available release before reporting an issue that may already be fixed.
Use GitHub private vulnerability reporting for vulnerabilities that could expose bot tokens, bypass webhook authentication, corrupt update delivery, or otherwise affect users of this module.
Do not include bot tokens, private keys, webhook secrets, or production payloads in a public issue. A useful report includes:
- the affected tgbot version or commit;
- the relevant Telegram Bot API method or update type;
- a minimal reproduction using redacted credentials;
- the expected impact and any known workaround.
Use a public GitHub issue for ordinary correctness bugs that do not have a security impact.