We take the security of software maintained by the evolution-gaming GitHub organization seriously and appreciate responsible disclosure of potential security vulnerabilities.
This policy supplements the Evolution Vulnerability Disclosure Policy.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use one of the following channels:
- For repositories where GitHub Private Vulnerability Reporting is enabled: Security → Advisories → Report a vulnerability
- Email cybersec@evolution.com, optionally encrypted with our PGP key
When submitting a report, please include, where possible:
- The affected repository, component, and version
- A description of the vulnerability
- The potential security impact
- Steps to reproduce the issue
- A proof of concept, if available
- Any suggested mitigation or fix
- Your preferred contact information
Please avoid accessing, modifying, or deleting data that does not belong to you while investigating a potential vulnerability.
Security fixes are generally provided for currently supported versions of our software.
Individual repositories may define more specific supported-version requirements in their own SECURITY.md.
Please allow reasonable time for us to investigate and address a reported vulnerability before publicly disclosing it.
Where appropriate, we will coordinate disclosure with the reporter after a fix or mitigation is available.
This policy applies to repositories maintained by the evolution-gaming GitHub organization unless a repository defines its own security policy.
A repository-specific SECURITY.md takes precedence over this organization-wide policy.