Skip to content

Security: DrapNard/CrystalSpace

Security

SECURITY.md

Security Policy

Supported versions

CrystalSpace is under active development. Security fixes are applied to the latest revision of the default branch.

Reporting a vulnerability

Do not open a public issue for a vulnerability, leaked credential, access control problem, or report containing private user data.

Use the repository's Security tab and select Report a vulnerability to open a private GitHub Security Advisory. Include:

  • affected revision or release;
  • macOS version and hardware architecture;
  • reproduction steps;
  • expected and observed behavior;
  • impact;
  • a minimal proof of concept with secrets removed.

Do not include credentials, private signed URLs, personal wallpaper files, or unredacted logs. Please allow maintainers time to reproduce and address the report before public disclosure.

Scope

High-priority reports include:

  • arbitrary file read or write;
  • unsafe handling of security-scoped bookmarks;
  • credential or private URL exposure;
  • download validation bypass;
  • code execution through downloaded media or provider metadata;
  • authorization or entitlement bypass;
  • insecure update or distribution behavior;
  • privilege escalation.

Wallspace Pro or authentication bypass instructions are not accepted as features and should not be publicly disclosed through this project.

There aren't any published security advisories