Security fixes are provided on a best-effort basis for the latest published Mactician release. Older releases may be asked to upgrade before a report is investigated.
Use GitHub Private Vulnerability Reporting or open a private Security Advisory
for this repository. Do not disclose an unpatched vulnerability in a normal
public issue. If private reporting is not available, email
tweet9ra@gmail.com with Mactician security in the subject.
Include the affected version, macOS version and architecture, impact, reproduction steps, and the smallest proof needed to demonstrate the issue. Explain whether the issue affects the launcher, installer, local runtime, Sparkle update chain, or diagnostic tooling.
Sanitize logs before attaching them: keep only the lines needed to show the failure and remove usernames, home paths, tokens, cookies, credentials, device identifiers, Riot session data, and unrelated process output. Never attach a full AVD, raw game log, Keychain export, crash-memory dump, or private key.
Receipt and remediation times depend on maintainer availability and issue complexity; this policy does not promise a fixed response SLA.