Security fixes are applied to the version named in the repository root
VERSION file and, when practical, to the latest published release. Older
release assets may not receive fixes.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting or Security Advisory feature for this repository. Include:
- affected version and component;
- reproduction steps or a proof of concept;
- expected impact and required privileges;
- suggested mitigation, if known;
- whether the issue has been disclosed elsewhere.
Maintainers should acknowledge a complete report within five business days, coordinate validation and remediation privately, and credit the reporter when requested and appropriate. Timelines depend on severity and on whether a fix also requires changes to separately maintained engine-source or release assets.
Reports concerning launch scripts, installers, release assets, configuration handling, dependency integrity, or repository automation are in scope. General support questions and feature requests should use the public issue templates.