Skip to content

Security: steamtoolsapp/ManifestHub

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue with the data in this repository or the steamtoolsapp.com website, please do not open a public issue.

Instead, report it privately:

  1. Email the maintainer via the GitHub security advisory feature, or
  2. Join our Discord and message a moderator directly.

Please include:

  • A description of the issue and its potential impact.
  • Steps to reproduce (if applicable).
  • Any suggested fixes.

We aim to respond within 48 hours.

Scope

  • Malicious or corrupted files in the repository's branches.
  • Security issues in the steamtoolsapp.com website (hosted separately at /Users/qiang/project/steam-tools/steamtoolsapp.com or the live site).
  • Unauthorized access to repository content.

Out of scope

  • The legality of Steam manifest files, depot keys, or the SteamTools desktop client — these are community tools and are not maintained here.
  • Issues with the Steam platform itself.

There aren't any published security advisories