Skip to content

Security: ReallocAll/endkeep

Security

SECURITY.md

Security policy

Do not disclose exploitable data-loss, path traversal, privilege bypass or world-data exposure vulnerabilities in a public issue before maintainers can assess them.

Report privately via GitHub private vulnerability reporting when enabled, or contact the maintainer using the ReallocAll GitHub profile.

Provide the affected version, operating system, minimal reproduction and potential impact. Redact player information, credentials and private world contents. As a community project, EndKeep does not currently provide a guaranteed response SLA.

There aren't any published security advisories