Skip to content

Security: haterade22/LOTRAOM

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest release Yes
Previous release Security fixes only
Older versions No

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

Email: support@lotraom.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

What to Expect

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 7 days
  • Resolution Timeline: Depends on severity, typically 30-90 days

Disclosure Policy

  • Please give us reasonable time to address the issue before public disclosure
  • We will credit reporters in release notes (unless you prefer anonymity)
  • We do not offer bug bounties at this time

Security Best Practices

For Users

  • Download LOTRAOM only from official sources (GitHub releases, official launcher)
  • Keep your game and mod updated to the latest version
  • Report suspicious behavior or files

For Contributors

  • Never commit secrets, API keys, or credentials
  • Use environment variables or secure configuration for sensitive data
  • Follow the security guidelines in security.md

Scope

This policy covers:

  • LOTRAOM mod (/Main/, /ModuleData/)
  • LOTRAOM Launcher (/launcher/)
  • Update Server (/launcher/server/)
  • Analytics infrastructure (/devops/analytics/)

Contact

For security concerns: support@lotraom.com

For general questions: Use GitHub Issues or Discord

There aren't any published security advisories