For general project information, see the README.md. For contribution rules, see CONTRIBUTING.md. For community conduct concerns, see CODE_OF_CONDUCT.md.
Security fixes are intended for the latest supported release. Older versions may not receive security fixes.
Do not report security vulnerabilities publicly. Do not post sensitive vulnerability details in GitHub Issues, Discussions, pull requests, comments, or public chat channels.
Please use GitHub Private Vulnerability Reporting to submit a private report directly to the maintainers.
When reporting a vulnerability, include enough information for the maintainers to reproduce or understand the issue, such as the affected version, affected files or workflow, reproduction steps, and potential impact.
Security reports may include, for example:
- malicious or unexpectedly modified project files;
- compromised GitHub Actions or release automation;
- accidentally committed credentials or other secrets;
- malicious third-party code or assets introduced into the repository; or
- release artifacts that appear to have been tampered with.
Normal gameplay bugs, pack compatibility problems, documentation issues, and feature requests are not security vulnerabilities. Report those through GitHub Issues or GitHub Discussions as appropriate.
Please allow the maintainers reasonable time to investigate and address a reported vulnerability before publicly disclosing technical details. Keep the investigation and any sensitive reproduction information private until a fix or other resolution is available.
For community conduct incidents, do not use this process; follow CODE_OF_CONDUCT.md and contact a repository collaborator privately.