# Security Policy ## Supported code Security fixes target the current `master` release-candidate line. ## Reporting vulnerabilities Report suspected vulnerabilities privately to `security@itworx.tech`. This monitored mailbox is the permanent private reporting channel for the project. Do not publish credentials, private library paths or inventories, emulator firmware or keys, ROM/game contents, account data, provider tokens, production databases, private infrastructure, copyrighted archives, or exploit-sensitive evidence in a public issue. Include the affected version or commit, component, minimal reproduction using synthetic metadata and legally redistributable fixtures, expected and observed behaviour, and impact. State whether the issue affects archive parsing, path containment, read-only source mounts, browser emulation, metadata acquisition, authentication, imports, storage, player isolation, deployment, or third-party artifact provenance. ## Security and content boundary Ludarium coordinates untrusted filenames, metadata, archives, emulator components, and isolated players. Preserve path confinement, process isolation, explicit player origins, least-privilege filesystem access, and read-only source libraries. Contributions must not silently rename, move, delete, patch, extract into, or otherwise mutate source game archives. Unsupported or uncertain content must fail closed or become an explicit review item; runtime emulation must remain allowlisted and user-initiated. Never commit live `.env` files, firmware or keys, ROMs, copyrighted game assets, account data, private library databases, deployment credentials, private production exports, or unredacted production evidence.