Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security: EpicGames/lore-js

Security

SECURITY.md

Security policy

Do not open a public GitHub Issue, Discussion, or pull request to report a security vulnerability. Public disclosure before a fix is available puts all Lore users at risk.

Reporting a vulnerability

Report through Epic Games' security channels:

Use the subject line "Lore JS SDK security" when reporting by email.

Safe harbor

Epic doesn't pursue legal action against researchers acting in good faith under this policy.

What to include

  • A description of the vulnerability and how it can be exploited
  • Step-by-step reproduction, or a minimal reproduction program
  • The affected SDK version (check node_modules/@lore-vcs/sdk/package.json)
  • Your Node.js version, OS, and CPU architecture
  • Impact assessment — what can an attacker do?
  • Your name and affiliation for credit (or note if you prefer anonymity)

Scope

This file covers the @lore-vcs/sdk JavaScript/TypeScript package and its npm-published platform binaries. Vulnerabilities in the underlying Lore wire protocol, lore-capi, or loreserver are also in scope — mention which component is affected.

Response, disclosure, supported versions, and bug bounty

The full response timeline, embargo tracks, supported-version policy, CVE coordination, and bug bounty terms are governed by the Lore project security policy and apply uniformly to the SDK:

Lore SECURITY.md

If you do not receive an acknowledgement within 7 days, follow up at security@epicgames.com with "Lore JS SDK security" in the subject line.

There aren't any published security advisories

Morty Proxy This is a proxified and sanitized view of the page, visit original site.