Skip to content

Security: Cimaranton/Scanatous-Wayfarer-Structures

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
0.3.1-beta.2 Yes
Earlier public beta builds No

The supported runtime baseline is Minecraft 26.2, Java 25, Fabric Loader 0.19.3 or newer, Fabric API 0.155.0+26.2 or newer, Scanatous Atlas 0.3.1-beta.2 or newer, and Scanatous Encounter Director 0.2.1-beta.2 or newer.

Reporting a security vulnerability

Do not open a public issue for a suspected security vulnerability.

Use GitHub's private vulnerability reporting feature for this repository:

  1. Open the repository's Security tab.
  2. Select Report a vulnerability.
  3. Provide the affected version, runtime environment, reproduction steps, expected impact, and a minimal proof of concept.

Include only the minimum data required to reproduce the issue. Remove access tokens, account credentials, public server addresses, player personal information, and unrelated world data.

Security-relevant reports

Private reporting is appropriate for issues such as:

  • arbitrary command or code execution;
  • unintended file access or path traversal in release tooling;
  • privilege or permission bypass;
  • unbounded resource consumption that can be triggered remotely;
  • malicious data-pack input causing server compromise;
  • exposure of secrets or private server data.

Ordinary crashes, structure placement defects, loot balance, localization defects, performance regressions, and compatibility problems should use the public bug-report template unless they create a credible security impact.

Disclosure process

Reports will be reviewed, reproduced, and classified before public disclosure. A security advisory and corrected release will be published when a confirmed vulnerability requires coordinated disclosure.

There aren't any published security advisories