Skip to content

Security: Stashpeak/SimLauncher

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities.

Use GitHub Security Advisories to report privately. Only you and the maintainer will be able to see the report.

Include as much detail as you can: steps to reproduce, affected version, and potential impact.

Response Time

Target
Acknowledgement Within 7 days
Fix or mitigation Within 90 days

For critical vulnerabilities a fix will be prioritized sooner.

Scope

Reports are welcome for vulnerabilities in SimLauncher itself — its Electron code, IPC handlers, and dependency chain.

Out of scope: vulnerabilities in the sim racing games or utilities that SimLauncher launches, and issues in the underlying OS or hardware.

Supported Versions

Only the latest release receives security fixes.

There aren't any published security advisories