If you discover a security vulnerability in this project, please report it responsibly.
Do not open a public issue for security vulnerabilities. Public disclosure before a fix is available can put users at risk.
Instead, please report the issue privately by contacting the maintainers.
Send a report that includes the following information:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The potential impact of the vulnerability
- Any proof-of-concept code, screenshots, or logs (if available)
- Possible mitigation suggestions (optional)
Please report vulnerabilities via email:
jacomalan314@proton.me
If email is not available, you may alternatively contact the maintainers through a private message or other listed project contact methods.
We ask that you follow responsible disclosure practices:
- Allow the maintainers reasonable time to investigate and fix the issue.
- Avoid publicly disclosing the vulnerability until a fix or mitigation is released.
- Coordinate disclosure timing with the maintainers when possible.
When a vulnerability is reported, maintainers will:
- Acknowledge receipt of the report.
- Investigate and confirm the issue.
- Develop and test a fix.
- Release a patch and publish a security advisory if necessary.
Security fixes are typically applied to the most recent stable version of the project. Older versions may not receive patches.
Users of the project are encouraged to:
- Keep dependencies up to date
- Use the latest version of the engine when possible
- Avoid running untrusted scripts or assets without sandboxing
Thank you for helping keep the project and its users safe.