Please do not disclose a security vulnerability in a public issue. Use GitHub's private vulnerability reporting or open a private security advisory for this repository.
Useful reports include:
- affected ChoirLauncher version and build ID;
- a minimal reproduction using non-sensitive test files;
- whether the issue can write outside an intended root, execute mod code, alter official configuration without confirmation, bypass fingerprint checks, or leak private paths;
- expected versus observed behavior.
Do not attach real saves, profiles, launcher settings, access tokens, or private filesystem paths to public discussions.
Until the first stable release, only the newest published pre-release receives security fixes. Compatibility is limited to Songs of Syx 0.71.44.