Skip to content
This repository was archived by the owner on Jun 8, 2026. It is now read-only.

Security: SpineEventEngine/model-compiler

Security

SECURITY.md

Security policy

We take the security of the Spine Event Engine SDK seriously, and we appreciate the work of those who report vulnerabilities to us.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

Instead, please follow our Coordinated Vulnerability Disclosure Policy. It names the single point of contact for reports, and describes what to include in one.

Please report a vulnerability to us before making any information about it public.

What to expect

The Policy describes this in full. In short:

  • We confirm the receipt of your report within 3 business days.
  • Within the next 10 business days, we inform you of the results of our initial assessment.
  • After that, we provide status updates at least once every 30 business days until the matter is resolved or otherwise closed.
  • Once a fix is available, we publish an advisory on our website and reference it in the release notes.

We ask you to coordinate the timing of any public disclosure with us. As a general rule, this means waiting until we have released a fix, or until 90 days have passed since your report, whichever is earlier.

If you follow the Policy, we keep your report confidential, and will not take legal action against you or report your research to law enforcement.

Supported versions

We provide security fixes for the 2.x versions of the SDK.

The 1.x versions are no longer maintained. If you use one of them, please migrate to 2.x to receive security fixes.

Third-party components

Spine incorporates third-party components and other dependencies. Where a vulnerability in such a component affects Spine, we treat it as an issue affecting our product and address it accordingly. Please see the Policy for the details.

There aren't any published security advisories