Use GitHub's
private vulnerability reporting.
You can also contact matthias@lupinum.com.
Do not report a security issue in a public issue, discussion, or pull request.
Include:
- the affected version or commit;
- the security impact;
- the smallest reproduction; and
- only the evidence that is necessary.
Do not include real credentials, game packet captures, or unrelated private data.
We review security findings for:
- the latest published Stable release;
- the current public Beta or release candidate; and
mainwhen the finding affects the next release.
Older releases do not receive fixes.
Report crashes and non-security bugs with the public bug form. You can attach
the app's local diagnostics .zip export. Review the file before you attach
it.