- Overview
- Quick Start
- Introduction
- Guides
- Client Libraries
- API Reference
- Examples
- DDD Resources
- Validation user guide
- Validation developer guide
- Security
Security policy
We take the security of the Spine Event Engine SDK seriously, and we appreciate the work of those who report vulnerabilities to us.
Reporting a vulnerability
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Instead, please follow our Coordinated Vulnerability Disclosure Policy. It names the single point of contact for reports, and describes what to include in one.
Please report a vulnerability to us before making any information about it public.
What to expect
The Policy describes this in full. In short:
- We confirm the receipt of your report within 3 business days.
- Within the next 10 business days, we inform you of the results of our initial assessment.
- After that, we provide status updates at least once every 30 business days until the matter is resolved or otherwise closed.
- Once a fix is available, we publish an advisory on our website and reference it in the release notes.
We ask you to coordinate the timing of any public disclosure with us. As a general rule, this means waiting until we have released a fix, or until 90 days have passed since your report, whichever is earlier.
If you follow the Policy, we keep your report confidential, and will not take legal action against you or report your research to law enforcement.
Supported versions
We provide security fixes for the 2.x versions of the SDK.
The 1.x versions are no longer maintained. If you use one of them, please migrate to 2.x to receive security fixes.
Third-party components
Spine incorporates third-party components and other dependencies. Where a vulnerability in such a component affects Spine, we treat it as an issue affecting our product and address it accordingly. Please see the Policy for the details.
The source of this page is SECURITY.md in the
SpineEventEngine/.github repository.