Skip to content

Security: TimMasalme/ForgeMapToolkit-Assets

Security

SECURITY.md

Security Policy

Scope

This repository contains static asset files only (JSON, PNG, DDS, Lua blueprints).
There is no server-side code, authentication, or user data processing.

Security vulnerabilities are unlikely, but if you discover one, please follow the process below.

Supported Versions

Asset Type Status
Skybox presets ✅ Active
Unit blueprints ✅ Active
Preview images ✅ Active

Reporting a Vulnerability

If you find a security issue (e.g. a malformed file that could cause a crash or exploit in ForgeMapToolkit):

  1. Do not open a public issue.
  2. Open a GitHub Security Advisory in this repository.
  3. Describe the issue clearly, including steps to reproduce if applicable.

You can expect an acknowledgment within 7 days and a resolution or update within 30 days depending on severity.

Out of Scope

  • Reports about third-party tools that consume these assets
  • Reports about the ForgeMapToolkit application itself (report those in the toolkit's own repository)

There aren't any published security advisories