Skip to content

Security: mrbuilder1961/ChatPatches

SECURITY.md

Vulnerability Report Format

Please include the following details in your report with as much relevant information as possible:

  • Your contact info
    • Preferably an Discord username and/or email address
  • Summary of the vulnerability (with impact and severity as clear as possible)
  • Versions and info:
    • Chat Patches version affected
    • Minecraft version used
    • Relevant or recent latest.log upload on https://mclo.gs
    • Operating system
  • Steps to reproduce
  • Impact/severity of the vulnerability
  • Remediation suggestion
    • ex. "I think changing x to y and updating dependency z might fix the issue"

Disclosure Policy

The Chat Patches team (OBro1961) is dedicated to working closely with the open source community and with projects that are affected by a vulnerability, in order to protect users and ensure a coordinated disclosure. When we identify a vulnerability in a project, we will report it by contacting the publicly-listed security contact for the project if one exists; otherwise we will attempt to contact the project maintainers directly.

If the project team responds and agrees the issue poses a security risk, we will work with the project security team or maintainers to communicate the vulnerability in detail, and agree on the process for public disclosure. Responsibility for developing and releasing a patch lies firmly with the project team, though we aim to facilitate this by providing detailed information about the vulnerability.

Our disclosure deadline for publicly disclosing a vulnerability is: 90 days after the first report to the project team.

We appreciate the hard work maintainers put into fixing vulnerabilities and understand that sometimes more time is required to properly address an issue. We want project maintainers to succeed and because of that we are always open to discuss our disclosure policy to fit specific requirements, when warranted.

Adapted from the GitHub Security Lab report template

Learn more about advisories related to mrbuilder1961/ChatPatches in the GitHub Advisory Database