1.0 KiB
Security policy
Reporting a vulnerability
Do not open a public issue for an exploitable vulnerability or include exploit details in Discord, logs, screenshots, or pull requests.
Use GitHub private vulnerability reporting. If that form is unavailable, use the private contact listed on the official Sky-Systems contact page.
Include the affected release tag or commit, framework and integration context, impact, minimal reproduction, and any proposed mitigation. Remove credentials, tokens, private server addresses, and player-identifying data.
We will acknowledge the report, reproduce and assess the impact, coordinate a fix, and publish details after affected users have a reasonable update path. Please do not disclose the issue publicly before that coordination is complete.
Supported versions
Security fixes target the latest published release and the current dev branch. Older releases may require upgrading before a fix can be applied.