Skip to content

Security: KayelC/Convergence

Security

SECURITY.md

Security Policy

Supported Scope

Convergence is currently a 0.1 pre-release source-distributed framework. Security fixes target the current main branch and the latest tagged 0.1.x release, when one exists. Older pre-release commits and all material under ArchiveDocs/ are unsupported historical evidence.

Report A Vulnerability

Use GitHub's Report a vulnerability feature for this repository so the report remains private. If private vulnerability reporting is unavailable, contact the repository owner through their GitHub profile without publishing exploit details in an issue or discussion.

Include the affected commit or version, reachable reproduction steps, expected impact, and any suggested mitigation. Do not include proprietary downstream game content unless it is essential to reproduce the framework defect.

Response And Disclosure

The maintainer will acknowledge a complete report when practical, assess whether the issue is inside the supported product boundary, and coordinate a correction. Please allow up to 90 days for coordinated disclosure unless active exploitation or another concrete risk requires a shorter timeline.

Security reports do not change the licensing terms in LICENSE.md. Godot, .NET, test tooling, and other third-party dependencies retain their own security and support policies.

There aren't any published security advisories