Security fixes are currently provided for the latest 1.0.x release.
Please do not disclose suspected vulnerabilities in a public issue or discussion.
Use the repository's Security tab and choose Report a vulnerability to submit a private security advisory. Include:
- the affected version and component;
- clear reproduction steps or a proof of concept;
- the expected and observed behavior;
- the likely impact; and
- any suggested remediation, if available.
We aim to acknowledge a report within 7 days and provide an initial status within 14 days. These are response targets rather than guarantees.
Reports about the Studio application, its build process, or its published release assets are in scope. DualSPHysics itself and independently supplied DLC tools are separate upstream projects; report vulnerabilities in those projects to their maintainers. If an upstream issue creates a Studio-specific risk, please also notify this project privately.
Do not include secrets, personal data, or destructive payloads beyond what is necessary to demonstrate the issue.