Do not open a public issue for a suspected vulnerability.
Use Security > Report a vulnerability in the affected Lindforge Studios repository. If private
vulnerability reporting is unavailable, email inbox@lindforge.com
with the subject Security report: <repository>.
Include:
- the affected repository, version, tag, or commit;
- the expected and observed security boundary;
- minimal reproduction steps;
- the potential impact;
- a suggested remediation, if known.
Do not include API keys, OAuth tokens, private keys, credentials, personal data, or private project archives. Redact logs and screenshots before attaching them.
Please allow maintainers reasonable time to reproduce and fix the issue before public disclosure. Lindforge Studios will coordinate acknowledgement, remediation, and release notes with the reporter when appropriate.
Unless a repository documents a different policy, only its latest release and current default branch receive security fixes.