Report vulnerabilities through GitHub Security Advisories. Do not publish token leaks, pairing bypasses, callback forgery, or terminal-injection paths.
Development branch only is supported. Telegram bot traffic is not end-to-end encrypted; do not send secrets through Onibi.