Skip to content

Security: HoleInWater/Mistborn

Security

SECURITY.md

Security Policy

Supported Versions

We take security seriously. The following versions of this project are currently being supported with security updates:

Version Supported
1.0.x
0.9.x

Reporting a Vulnerability

If you discover a security vulnerability within this project, please follow responsible disclosure practices:

How to Report

  1. DO NOT create a public GitHub issue for security vulnerabilities
  2. Send a detailed report to the project maintainers via their preferred contact method
  3. Include the following information:
    • Type of vulnerability
    • Full paths of source file(s) related to the vulnerability
    • Location of the affected source code (tag/branch/commit or direct URL)
    • Step-by-step instructions to reproduce the issue
    • Proof-of-concept or exploit code (if possible)
    • Impact assessment and potential attack scenarios

What to Expect

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours
  • Initial Response: A member of the security team will respond within 7 days
  • Status Updates: We will provide updates on the vulnerability status at least every 7 days until resolution
  • Resolution: We will work to develop and release a fix as quickly as possible, depending on complexity

Scope

Security concerns related to:

  • Authentication and authorization bypasses
  • Data exposure or leakage
  • Remote code execution vulnerabilities
  • Injection attacks (SQL, XSS, Command Injection, etc.)
  • Cryptographic weaknesses
  • Dependency vulnerabilities
  • Unity-specific security concerns

Out of Scope

  • Denial of Service attacks that require significant resources
  • Social engineering attacks
  • Physical security issues
  • Vulnerabilities in third-party services or dependencies not maintained by this project

Security Updates

Security updates will be released as patch versions and announced through the project's release notes. We encourage all users to keep their installations up to date.

Acknowledgments

We would like to thank all security researchers and community members who help keep this project safe. Contributors who report valid security issues will be acknowledged (unless anonymity is requested) in our security advisory and release notes.

There aren’t any published security advisories