Donify is an early-stage local drone simulator. Security fixes target the latest default branch and latest published alpha; older snapshots do not have a separate maintenance commitment. There is no guaranteed response time.
If the repository's Security → Advisories → Report a vulnerability action is available, use that private GitHub reporting channel. If it is unavailable, use a contact method published by the maintainer on the w4coder GitHub profile to request a private channel. If no private contact is listed, open an issue containing only a request for a private security contact, without technical details or sensitive material.
Include the affected version or commit, a minimal reproduction, the likely impact and any proposed fix. Remove real credentials and personal data from examples. Do not publish an exploit or working secret in an issue while a private report is being arranged.
Relevant reports include unsafe asset extraction or paths, compromised download integrity, credential disclosure in publication tooling, and unsafe repository automation. Local setup files and optional generation/publishing credentials must remain outside source control. A public asset download must not require access to the maintainer's storage credentials.
Unreal Engine and external authoring tools are separately installed dependencies. Report vulnerabilities in those products to their respective maintainers; provide a private Donify report as well if project code exposes or worsens the issue.
The public workflow runs on GitHub-hosted runners with read-only repository permissions. It checks source, module boundaries and asset tooling without an Unreal install or publication secrets. These checks are not a security audit of the Engine, the repository's entire history or third-party assets.