If you believe you have found a security vulnerability in any repository belonging to the Perl-SDL3 organization, please report it privately rather than opening a public issue.
Preferred: use GitHub private vulnerability reporting on the affected repository (Settings → Security policy → Report a vulnerability), if enabled.
Alternatively, email Sanko Robinson sanko@cpan.org with:
- The repository and version affected
- A description of the vulnerability
- Steps to reproduce it (or a minimal proof of concept)
- The impact, if you can assess it
Please allow time for a response before disclosing publicly. We aim to acknowledge reports within a few days and will coordinate a fix and a public disclosure with you.
- The
SDL3Perl module and theAlien-SDL3*build distributions are the primary projects in scope. - Bugs in the underlying SDL C library itself should be reported upstream to the SDL bug tracker instead.
Security fixes are applied to the current release of the affected distribution and released to CPAN as soon as a fix is ready.