If you discover a security vulnerability in phase.rs, please report it responsibly.
Do not open a public issue. Instead, please use one of the following:
- GitHub Security Advisories: Report a vulnerability (preferred)
- Email: matt@phase-rs.dev
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment within 72 hours
- We'll work with you to understand and address the issue before any public disclosure
- Credit in the fix commit unless you prefer to remain anonymous
This policy covers the phase.rs game engine, frontend client, and multiplayer server. Third-party dependencies are out of scope but we appreciate being notified if you find an issue in one of our dependencies that affects this project.