Skip to content

Security: RitoShark/Hematite

Security

SECURITY.md

Security

Security fixes target the latest release.

For a vulnerability, use GitHub's private reporting form if it is available. Otherwise, contact a maintainer privately through a contact listed on their GitHub profile. Do not post exploit details in a public issue.

Include the Hematite version, steps to reproduce, and the likely impact. Useful reports include a crafted mod writing outside the output folder, executing code, or an unsafe download being accepted.

Ordinary repair failures can go in issues. If a crash may be exploitable, report it privately first.

There aren't any published security advisories