Skip to content

Latest commit

 

History

History
29 lines (19 loc) · 745 Bytes

File metadata and controls

29 lines (19 loc) · 745 Bytes

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any EndstoneMC project, please report it responsibly.

Email: hello@endstone.dev

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • The affected repository and version

Response Timeline

  • Acknowledgement: within 48 hours
  • Initial assessment: within 7 days
  • Fix or mitigation: best effort, typically within 30 days

Scope

This policy covers all public repositories under the EndstoneMC organization.

Disclosure

We ask that you do not publicly disclose the vulnerability until we have had a chance to address it. We will coordinate with you on disclosure timing.