Security fixes are applied to the latest release on main.
| Version | Supported |
|---|---|
| 1.x | Yes |
| Earlier versions | No |
Do not report a vulnerability in a public issue, discussion, or pull request.
Use the repository's Security tab to submit a private vulnerability report or draft security advisory. If private reporting is unavailable, contact the repository owner privately using the contact method on their GitHub profile.
Include as much of the following as possible:
- A description of the vulnerability and its potential impact
- Reproduction steps or a minimal proof of concept
- Affected browsers, versions, and configurations
- Any known mitigations or suggested fixes
- Whether the issue has been disclosed elsewhere
You should receive an acknowledgment within seven days and a status update within fourteen days. Resolution time depends on severity and complexity. Please allow maintainers a reasonable opportunity to investigate and release a fix before public disclosure.
Gameplay defects, rendering issues, and performance regressions without a security impact should use the public bug report form instead.