Security fixes are made against the latest released version of LibreMetaverse. Please
confirm an issue reproduces on the latest release (or current master) before reporting it.
Please do not open a public issue or pull request for a security problem.
Report it privately using GitHub's private vulnerability reporting:
- Go to the Security tab of this repository.
- Choose Report a vulnerability.
Helpful things to include:
- the affected version(s) and target framework
- a description of the issue and its impact
- steps to reproduce, ideally a failing test or a small proof of concept
- any suggested fix
LibreMetaverse is maintained by volunteers, so responses are best-effort. You can expect an acknowledgement of your report, and we will keep you updated as the issue is investigated and fixed. Please give us a reasonable chance to release a fix before disclosing publicly; we are happy to credit you in the release notes unless you prefer otherwise.
This policy covers the code in this repository and the packages published from it. Problems in third-party dependencies (for example CoreJ2K or SkiaSharp) should be reported to those projects, though please let us know if LibreMetaverse is affected so we can update.