This policy applies to every public repository of the MeshInspector organization, including MeshLib and our OpenCTM fork.
Please do not report security issues through public GitHub issues, discussions or pull requests. Use one of these private channels:
- GitHub private vulnerability reporting: open the Security tab of the affected repository and choose Report a vulnerability.
- Email: support@meshinspector.com with
[Security]at the start of the subject.
Include what you can of: the affected repository and commit or release, the file and function, a proof-of-concept input or program, the observed behaviour (sanitizer output, crash, stack trace), and your assessment of the impact.
- We acknowledge reports within three business days.
- We confirm the issue, tell you our planned fix and timeline, and keep you informed of progress.
- We fix the issue on the default branch and ship it in the next MeshLib release. If a fix needs time, we agree a disclosure date with you; otherwise the fix is public as soon as it is merged.
- We credit reporters by name in the fix and release notes unless you ask us not to.
We do not run a bug bounty programme.
Security fixes are made on the default branch and delivered in the next release. Older releases are not patched.