Skip to content

Security: javelin-anticheat/JavelinAC

SECURITY.md

Security Policy

Supported Versions

The following versions of JavelinAC are currently supported with security updates:

Version Supported
main (latest)
Older releases

If you are running an unsupported version, please update to the latest release to ensure you receive security fixes.


Reporting a Vulnerability

If you discover a security vulnerability in JavelinAC, we ask that you do not open a public issue.
Instead, please report it through one of the following channels:

When reporting, please include:

  • A clear description of the issue.
  • Affected version(s).
  • Steps to reproduce or a proof-of-concept.
  • Any information about potential impact.

We aim to respond to initial reports within 3 business days.


Disclosure Policy

We follow a coordinated disclosure approach:

  1. We confirm receipt of your report.
  2. We investigate the issue and determine severity.
  3. We prepare and test a fix in a private branch or advisory fork.
  4. Once the fix is ready, we release a patched version.
  5. We publish a public Security Advisory to inform users, and if needed, request a CVE ID.

If a fix cannot be provided quickly, we will communicate available mitigations.


Recognition

We value the security community and appreciate responsible disclosures.
Contributors who report valid vulnerabilities may be credited in the final advisory (with consent).


Contact


Notes

This project is part of the Javelin Anti-Cheat initiative, focused on building fair and secure multiplayer environments.
Security is critical, and your help is appreciated in keeping JavelinAC safe for all users.

There aren't any published security advisories