Skip to content

Security: swax/OpenSlope

Security

SECURITY.md

Security policy

This file covers vulnerabilities only. If you hold rights in material you believe this repository carries — copyright, trademark, or anything else — that is a different channel: write to contact@transparentsource.org, as LEGAL.md says. Please do not use the vulnerability flow for it; the two go to different places and a rights enquiry sent through GitHub's security reporting will be slower to reach a human who can act on it.

Reporting a vulnerability

Please do not open a public issue for an exploitable vulnerability, credential exposure, path traversal, malicious-file handling flaw, or other report that would put users at risk before a fix is available.

Use GitHub's Security → Report a vulnerability flow for this repository. Include the affected component, version or commit, reproduction steps, impact, and any suggested mitigation. If private vulnerability reporting is unavailable, open a minimal issue asking the maintainer to enable a private contact channel; do not include exploit details in that issue.

The project will acknowledge a report when it is seen, investigate it, and coordinate disclosure after a fix or mitigation is ready. This volunteer project does not promise a fixed response SLA.

Supported versions

The current main branch receives security fixes. Once tagged releases exist, the latest tagged release is also supported; older tags are supported only when an advisory says otherwise. Disc images, extracted assets, local Maps/, discs/, credentials, and generated Unity projects must never be attached to reports.

There aren't any published security advisories