Chess Material Studio does not currently publish a formal security-support matrix. Reports are evaluated against the current project code and version. This policy does not promise indefinite support for older releases, snapshots, or branches.
Do not open a public Issue for an undisclosed security vulnerability. Use GitHub Private Vulnerability Reporting through the repository's Security Advisories page and select Report a vulnerability.
Known dependency advisories and maintenance warnings that are currently accepted or awaiting upstream changes are tracked in DEPENDENCY_SECURITY.md.
Provide a concise summary, reproducible steps, expected impact, the affected version or commit if known, and the operating system when relevant. Include only the minimum files or log excerpts needed to investigate. A proposed mitigation or fix is welcome when available.
Remove personal data before submitting a report. Do not attach complete local databases or the complete Lichess puzzle corpus, and minimize other sensitive data.
Potential security issues may involve local file handling, SQLite, data import or download, interaction with external UCI engines, exports, or dependencies. This list is not exhaustive.
Use the public Issue Forms for ordinary functional bugs and feature requests.
Keep reports private while they are investigated. The maintainer may request additional information. Any publication or advisory will be coordinated after the issue is understood and, where possible, corrected.