Skip to content

Security: Cimaranton/Scanatous-Atlas

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the current public beta line only.

Version Supported
0.3.1-beta.2 Yes
0.3.0-beta.1 and older No
Unreleased development builds No guaranteed support

The supported runtime baseline is:

  • Minecraft 26.2
  • Java 25
  • Fabric Loader 0.19.3 or newer
  • Fabric API 0.155.0+26.2

Reports from unsupported versions may be closed after verification that the issue is already fixed or cannot be reproduced on the supported release.

Reporting a vulnerability

Use GitHub's private vulnerability reporting for this repository:

  1. Open the repository's Security tab.
  2. Select Advisories.
  3. Select Report a vulnerability.
  4. Submit the report privately.

Do not open a public GitHub issue for an unpatched security vulnerability.

Before publishing this repository, the repository owner must enable private vulnerability reporting under:

Settings → Security → Private vulnerability reporting

What to include

Provide the minimum information required to reproduce and assess the issue:

  • Scanatous Atlas version and JAR SHA-256
  • Minecraft, Java, Fabric Loader, and Fabric API versions
  • Server operating system
  • Affected command, data-pack resource, structure profile, or route profile
  • Exact reproduction steps
  • Expected and actual behavior
  • Relevant excerpts from latest.log
  • A minimized data pack or test world when required
  • Impact assessment and any known workaround

Do not include production credentials, authentication tokens, private server addresses, player IP addresses, or an unredacted production world.

Security-impacting issues

Examples include:

  • unintended access to operator-only Atlas commands;
  • crafted data causing world corruption or persistent server failure;
  • arbitrary file or path access;
  • exploitable denial-of-service behavior within normal supported use;
  • validation bypass that causes unsafe structure or route data to be accepted;
  • reward or progression duplication with meaningful server-economy impact;
  • malicious or unsafe content in official release archives;
  • dependency or build-chain compromise affecting official Atlas artifacts.

Usually not security issues

The following should normally be reported through the public issue tracker instead:

  • ordinary gameplay defects;
  • balance or progression feedback;
  • expected permission denials;
  • cosmetic or translation problems;
  • unsupported mod conflicts;
  • isolated crashes without a reproducible security impact;
  • performance problems caused only by deliberately extreme forced-chunk generation;
  • issues affecting unsupported Atlas versions.

When uncertain, use private vulnerability reporting.

Disclosure and remediation

Please allow the maintainers time to reproduce, assess, and remediate a confirmed vulnerability before public disclosure. The maintainers may request additional evidence, coordinate a release date, assign a severity, and credit the reporter unless anonymity is requested.

No fixed response-time or remediation-time guarantee is provided for the public beta.

There aren't any published security advisories