Skip to content

Security: unauthorizedlogin/ecks

SECURITY.md

Security Policy

Thank you for helping keep the ecks RPG Framework secure.

This document explains how to responsibly report potential security vulnerabilities.


Reporting a Security Issue

If you discover a potential security vulnerability, please do not create a public GitHub Issue or Discussion.

Instead, submit a private vulnerability report using the repository Private Vulnerability Reporting feature.

Please include, if possible:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • The affected ecks version
  • The potential security impact
  • Any relevant screenshots, logs, or proof-of-concept examples

What Counts as a Security Issue?

Examples include:

  • Vulnerabilities affecting user or developer data
  • Unsafe file handling
  • Arbitrary code execution
  • Privilege escalation or permission bypass
  • Distribution or packaging vulnerabilities
  • Security issues affecting projects built with or distributed alongside the framework

What Is Not a Security Issue?

The following should be reported through the normal GitHub issue tracker or community support channels:

  • Gameplay bugs
  • UI issues
  • Missing features
  • Balance concerns
  • Documentation errors
  • General framework bugs
  • Feature requests

Response Process

Every report will be reviewed privately.

If a valid security issue is confirmed:

  • The issue will be investigated and prioritized.
  • A fix will be developed and tested.
  • A security advisory may be published after a fix is available.
  • Acknowledgment may be given to the reporter unless they request to remain anonymous.

Scope

This policy applies to:

  • The ecks RPG Framework
  • Official development tools
  • Official documentation
  • Official distribution packages

Third-party plugins, assets, libraries, and dependencies remain subject to their respective maintainers and security policies.


Thank you for helping keep the ecks ecosystem secure.

There aren't any published security advisories