Skip to content

Security: ShugokiFable/RimWorldForge

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue that reveals a security problem.

For anything that could put users at risk — remote code execution, credential or data exposure, unsafe downloads, or supply-chain concerns — report it privately to the owner through GitHub's private vulnerability reporting (if enabled) or by opening a security advisory from the repo's Security tab.

If you are not sure whether something counts as a security issue, reporting it privately is always fine.

What happens next

This is a personal, hobby-maintained project, so response is best-effort. The owner aims to:

  1. acknowledge the report within a few days,
  2. assess severity and impact,
  3. ship a fix on the default branch (and a tagged release when one exists),
  4. credit the reporter (only with their consent).

Supported versions

Fixes land on the default branch and, where the project tags releases, in the newest release. Older tagged releases are not backported unless the issue is severe and the fix is trivial.

There aren't any published security advisories