Skip to content

Security: Demeterio/Mod-Update-Checker

SECURITY.md

Security Policy

Reporting a Security Issue

Please do not report security vulnerabilities through a public GitHub Issue.

Use GitHub's private vulnerability reporting feature when available, or contact Demeterio privately through an official Mod Update Checker support channel.

Include:

  • the affected MUC version;
  • The Sims 4 game version;
  • a clear description of the issue;
  • reproduction steps;
  • relevant logs or screenshots;
  • any proof-of-concept code, if applicable.

Do not include passwords, access tokens, private keys, personal information, or private repository addresses.

Security Scope

Security reports may include issues involving:

  • registry signature verification;
  • registry validation and freshness checks;
  • network-request restrictions;
  • unsafe URL or file handling;
  • unintended data collection or transmission;
  • arbitrary code execution;
  • access to files outside MUC's intended folders;
  • bypasses of player consent or security checks.

General bugs, compatibility problems, and feature requests should be reported through the normal support channels instead.

Supported Versions

Only the latest public release of Mod Update Checker receives security updates.

Download the latest official release from:

https://github.com/Demeterio/Mod-Update-Checker/releases/latest

Disclosure

Please allow reasonable time for investigation and correction before publicly disclosing a vulnerability.

Confirmed security fixes will be published in a new official release. Existing releases will not be silently replaced.

No Security Bounty

Mod Update Checker is a free fan-made project and does not currently offer a paid security bounty program.

There aren't any published security advisories