Cloudy-Canvas

Discord bot for integration with the Manebooru imageboard


Project maintained by romulus4444 Hosted on GitHub Pages — Theme by mattgraham

Security Policy

Reporting a vulnerability

Please do not open a public issue for a security problem. Use GitHub’s private reporting instead: open the Security tab of this repository and choose Report a vulnerability (direct link).

If that option is not available, use the Discord server linked in the README and ask for a private way to share the details before you post them anywhere.

A useful report says what you did, what you expected, what happened instead, and which version (the commit on mane) you tried it on. A way to reproduce it in a test server helps most.

This is a small volunteer project. Reports are read and handled as time allows, with no promised response time. There are no numbered releases: the supported version is the latest commit on mane.

What counts

Examples of things worth reporting:

Not in scope: flooding the bot with commands (each user has a short cooldown, and Discord rate-limits the rest), what is on Manebooru itself, problems in Discord, and the security of the machine you run your own copy on.

What protects the bot

For people running their own copy, and for reviewers:

Running your own copy safely