Skip to content

Security: ecrindigital/carat

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x.x

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

How to Report

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Send an email to hello@ecrin.digital with:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

What to Expect

  • Acknowledgment: Within 48 hours of your report
  • Initial Assessment: Within 7 days
  • Resolution Timeline: Depends on severity
    • Critical: 24-72 hours
    • High: 1-2 weeks
    • Medium: 2-4 weeks
    • Low: Next release cycle

Disclosure Policy

  • We follow coordinated disclosure practices
  • Security advisories will be published after fixes are available
  • Credit will be given to reporters (unless anonymity is requested)

Security Best Practices

When using Carat Engine:

  • Keep dependencies updated
  • Validate all external input (assets, user data)
  • Use the latest stable release
  • Review shader code for potential issues

Scope

This security policy applies to:

  • Carat Engine core library
  • Official examples and tools
  • Build system configurations

Third-party dependencies have their own security policies.

There aren’t any published security advisories