Skip to content

Security: Ascendance3D/wrlforge

SECURITY.md

Security Policy

WRL Forge is an independent community project, currently in public beta. We take security issues seriously and appreciate reports that are made responsibly and privately.

Supported version

Version Supported
1.3.0-beta.3 (public beta) ✅ Yes — current public beta
1.3.0-beta.2 (public beta) ❌ No — update to beta.3
Earlier / private betas ❌ No

WRL Forge is prerelease, beta, and unsigned software. Only the current public beta listed above receives security attention.

Reporting a vulnerability

Please report vulnerabilities privately. Do not open a public issue for a security problem, and please do not disclose it publicly before it has been reviewed and addressed.

Use GitHub private vulnerability reporting:

  1. Go to the repository: https://github.com/Ascendance3D/wrlforge
  2. Open the Security tab.
  3. Click "Report a vulnerability" and fill out the private advisory form.

This keeps the report confidential between you and the project maintainer while it is being investigated.

What to include

To help us reproduce and assess the issue, please include as much of the following as you can:

  • The version affected (for example, 1.3.0-beta.3).
  • The download type you are running (Linux AppImage / tar.gz, or Windows Setup EXE / MSI / portable EXE / ZIP).
  • Your operating system and architecture (Linux x64 or Windows x64).
  • Clear steps to reproduce, including any sample .wrl file or world you have permission to share.
  • The impact — what an attacker could do, and why it matters.

Our commitment

We will make a best effort to acknowledge your report, investigate it, and keep you informed of progress. As a small community beta project, we cannot promise a specific response or fix deadline, but we will work in good faith to address confirmed issues and to credit reporters who wish to be credited.

Thank you for helping keep WRL Forge and its users safe.

There aren't any published security advisories