| Version | Supported |
|---|---|
| v1.x (main) | ✅ |
Open a GitHub Security Advisory or issue with label security.
Do not post session files, config.json, api_hash or phone numbers in public issues.
config.jsonis git-ignored — copy fromconfig.example.json.- Never commit
session_DO_NOT_SHARE.json,*.session,TG_CODEor/tmp/tg_code.txtcontents. - If a session or api_hash leaked: revoke the session in Telegram (Settings → Devices → Terminate), regenerate API credentials at https://my.telegram.org, delete the file and rotate secrets.
- The code warns when the code-file is group/world-readable; keep it
chmod 600.