Thank you for helping keep the ecks RPG Framework secure.
This document explains how to responsibly report potential security vulnerabilities.
If you discover a potential security vulnerability, please do not create a public GitHub Issue or Discussion.
Instead, submit a private vulnerability report using the repository Private Vulnerability Reporting feature.
Please include, if possible:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The affected ecks version
- The potential security impact
- Any relevant screenshots, logs, or proof-of-concept examples
Examples include:
- Vulnerabilities affecting user or developer data
- Unsafe file handling
- Arbitrary code execution
- Privilege escalation or permission bypass
- Distribution or packaging vulnerabilities
- Security issues affecting projects built with or distributed alongside the framework
The following should be reported through the normal GitHub issue tracker or community support channels:
- Gameplay bugs
- UI issues
- Missing features
- Balance concerns
- Documentation errors
- General framework bugs
- Feature requests
Every report will be reviewed privately.
If a valid security issue is confirmed:
- The issue will be investigated and prioritized.
- A fix will be developed and tested.
- A security advisory may be published after a fix is available.
- Acknowledgment may be given to the reporter unless they request to remain anonymous.
This policy applies to:
- The ecks RPG Framework
- Official development tools
- Official documentation
- Official distribution packages
Third-party plugins, assets, libraries, and dependencies remain subject to their respective maintainers and security policies.
Thank you for helping keep the ecks ecosystem secure.