Skip to content

Security: AsaTyr2018/AloftCompanionMap

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest published release. Older versions may be asked to upgrade before a report is investigated.

Reporting a vulnerability

Use GitHub private vulnerability reporting for the repository. Do not disclose the issue publicly until a fix is available. Include affected versions, reproduction steps, impact, and any suggested mitigation. Do not attach real savegames, access tokens, private keys, or proprietary Aloft assemblies.

If private vulnerability reporting is unavailable, contact the repository maintainer privately through the contact method listed on their GitHub profile.

Security boundaries

The application is designed for local use and binds its HTTP services to loopback addresses only. It must not be exposed through port forwarding, a reverse proxy, a public tunnel, or a non-loopback bind address. Runtime telemetry is read-only. Explicitly enabled waypoint and experimental teleport tools can modify game state through a session-authenticated command endpoint.

There aren't any published security advisories