Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 13 additions & 2 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,19 @@


name: "Bug Report"
description: "Report a reproducible problem in this repository. Incomplete reports make it hard to reproduce issues and may be closed."
title: "[Bug] <concise summary here>"
labels: [bug]

body:

- type: markdown
attributes:
value: |
> ⚠️ **Found a security issue? Do not file it here.**
> Do not open a public issue for security vulnerabilities. See our
> [Security Policy](https://github.com/carbonengine/.github/blob/main/SECURITY.md)
> for how to report privately.
- type: markdown
attributes:
value: |
Expand Down Expand Up @@ -32,6 +42,7 @@ body:
options:
- Windows 10/11
- macOS
- Other
default: 0
validations:
required: true
Expand All @@ -42,8 +53,8 @@ body:
label: "Tool-chain details"
description: |
Compiler / interpreter versions, build system, etc.
Example: MSVC 19.38 · CMake 3.28 · Python 3.11.3
placeholder: "clang 16, Ninja 1.11, Python 3.10.7"
Example: MSVC v141 · CMake 3.31 · Python 3.11.3
placeholder: "MSVC v141, CMake 3.31, Python 3.11.3"
validations:
required: true

Expand Down
38 changes: 23 additions & 15 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Security Policy
As CARBON, we take security seriously. This page explains **how to report vulnerabilities privately**, what’s **in scope** for the open-source code we publish on GitHub, and **what you can expect from us**.
Carbon Engine takes security seriously. This page explains **how to report vulnerabilities privately**, what’s **in scope** for the open-source code we publish on GitHub, and **what you can expect from us**.

---
## Scope
Expand All @@ -8,17 +8,25 @@ It does **not** cover FC’s production game services or player accounts (EVE On

---
## How to Report
- **Please DO NOT open a public issue for security problems.**
Email **security@fenris.com** with the subject line:
`Vulnerability Report: <brief description>`
Include as much detail as you can:
- Commit hash or release tag
- Steps to reproduce (from a clean clone)
- Technical details (logs, requests/responses, payloads)
- Impact (what an attacker could achieve)
- Environment (OS, compiler/interpreter, build system)
- Your contact info and whether you prefer to remain anonymous
If you’re unsure whether something qualifies as a security issue, **send it anyway** and we’ll help triage.
**Please DO NOT open a public issue for security problems.**

Report vulnerabilities through **GitHub private vulnerability reporting**:
- On the affected repository:
- Open the **Security** tab and click **Report a vulnerability**.
- This opens a private advisory only the maintainers can see, and keeps the report,
discussion, and fix coordination in one private place.
- For a step-by-step walkthrough of GitHub's private reporting flow, see [Privately reporting a security vulnerability](https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/report-privately).


In your advisory **Description**, please include as much detail as you can, e.g.:
- Commit hash or release tag
- Steps to reproduce (from a clean clone)
- Technical details (logs, requests/responses, payloads)
- Impact (what an attacker could achieve)
- Environment (OS, compiler/interpreter, build system)
- Your contact info and whether you prefer to remain anonymous

If you're unsure whether something qualifies as a security issue, **send it anyway** and we'll help triage.

### AI-generated reports.
We **do not** accept vulnerability reports that appear to be unverified AI output, generic "potential" issues without a working reproduction. AI tools are fine for analysis however, the report itself must come from a human who has verified the issue, can reproduce it from a clean clone, and can discuss it. Reports that fail this bar will be closed without detailed triage.
Expand Down Expand Up @@ -55,6 +63,6 @@ When a fix is ready, we will:
- Coordinate public disclosure timing with the reporter
---
## Contact
- **Primary:** security@fenris.com
- **Back-up (non-sensitive questions):** open an Issue in the relevant repo
Thank you for helping keep Carbon (and the developers who depend on it) safe.
- **Report a vulnerability:** GitHub **Security** tab → **Report a vulnerability** on the affected repo
- **Back-up contact (follow-up, coordination, off-platform comms):** security@fenris.com
- **Non-sensitive questions:** open an Issue in the relevant repo