This policy explains how security support and vulnerability reporting are handled for this repository.
Amulet Utility Plugins and its optional companion tools are maintained from the current public repository and the latest available releases.
Security fixes, when needed, are normally applied to the current code and the latest practical release. Older releases, archived files, previous plugin versions, experimental builds, forks, redistributed copies, and modified copies are not guaranteed to receive security updates unless stated otherwise.
Users should download plugins and companion tools from the official repository or the repository's Releases page when possible.
Please do not report security vulnerabilities through public issues, discussions, pull requests, screenshots, videos, or comments.
If you believe you found a security vulnerability, please report it privately using GitHub's private vulnerability reporting feature for this repository when available.
You may also contact the maintainer privately by email at:
ZeroTraceAPI@proton.me
GitHub may provide its own vulnerability report form. This security policy is meant to give additional guidance for what to report, what information to include, and what information should not be shared publicly.
When reporting a vulnerability, include as much relevant information as you safely can, such as:
- The affected plugin, companion tool, file, or repository area.
- The version, release, commit, or file name involved.
- The operating system, Amulet version, Minecraft edition, and Minecraft version, when relevant.
- A clear description of the issue.
- Steps to reproduce the issue, if they can be shared safely.
- Any known impact, workaround, or mitigation.
- Whether the issue appears to affect the official release, a modified copy, a fork, or a redistributed copy.
Do not include private worlds, private data, account credentials, access tokens, API keys, recovery codes, personal files, or anything you do not have permission to share.
A security issue may include, but is not limited to:
- Unsafe handling of files, paths, logs, reports, settings, or exported data.
- A way for a crafted file, world, report, setting, or plugin input to run unintended code.
- Code that can unexpectedly execute commands or unsafe system actions.
- Exposure of private user data.
- A serious issue that could damage files outside the intended world-editing scope.
- A suspicious official download, release asset, or repository file.
- A dependency, packaging, or distribution concern that could affect users.
Normal bugs, feature requests, compatibility issues, incorrect world output, unclear documentation, crashes, performance problems, or expected behavior concerns should usually be reported through GitHub Issues instead.
The maintainer will review reasonable security reports and may ask for more information if needed.
If a report is accepted, the maintainer may fix the issue, prepare a release, publish a note, credit the reporter when appropriate, or take other action based on the severity and practical impact.
If a report is declined, it may be redirected to a normal issue, discussion, documentation update, compatibility note, or closed with an explanation when practical.
There is no guaranteed response time, fix time, release schedule, or support period. Security reports are handled on a best-effort basis.
Please give the maintainer a reasonable chance to review and address a confirmed security issue before publicly disclosing details.
Avoid sharing exploit steps, proof-of-concept files, private data, or instructions that could harm users before a fix or mitigation is available.