| Version | Supported |
|---|---|
| 0.3.1-beta.2 | Yes |
| Earlier public beta builds | No |
The supported runtime baseline is Minecraft 26.2, Java 25, Fabric Loader 0.19.3 or newer, Fabric API 0.155.0+26.2 or newer, Scanatous Atlas 0.3.1-beta.2 or newer, and Scanatous Encounter Director 0.2.1-beta.2 or newer.
Do not open a public issue for a suspected security vulnerability.
Use GitHub's private vulnerability reporting feature for this repository:
- Open the repository's Security tab.
- Select Report a vulnerability.
- Provide the affected version, runtime environment, reproduction steps, expected impact, and a minimal proof of concept.
Include only the minimum data required to reproduce the issue. Remove access tokens, account credentials, public server addresses, player personal information, and unrelated world data.
Private reporting is appropriate for issues such as:
- arbitrary command or code execution;
- unintended file access or path traversal in release tooling;
- privilege or permission bypass;
- unbounded resource consumption that can be triggered remotely;
- malicious data-pack input causing server compromise;
- exposure of secrets or private server data.
Ordinary crashes, structure placement defects, loot balance, localization defects, performance regressions, and compatibility problems should use the public bug-report template unless they create a credible security impact.
Reports will be reviewed, reproduced, and classified before public disclosure. A security advisory and corrected release will be published when a confirmed vulnerability requires coordinated disclosure.