This is a personal, single-maintainer project.
- Security fixes are handled on a best-effort basis.
- Only the latest code on
mainis in scope. - Older tags/commits are not supported.
Preferred channel: report vulnerabilities privately through GitHub Security Advisories:
https://github.com/romantech/tic-tac-toe/security/advisories/new
Fallback (if you cannot use Security Advisories): open a public issue with only "Security report: private contact requested" in the title/body and no technical details. The maintainer will reply with a private channel for full disclosure.
Do not post exploit details in public issues before a fix is available.
Include the following when possible:
- Impact and affected area
- Reproduction steps (or PoC)
- Affected commit/tag and environment
Reports are triaged and addressed by one maintainer on a best-effort basis, with no guaranteed SLA.