Only the latest published DinoRand release receives security support.
Report vulnerabilities privately through GitHub private vulnerability reporting. Do not open a public issue or publish exploit details before maintainers have assessed the report. We target an acknowledgment within seven days; this is not a promise of a fix or disclosure date.
Do not submit credentials, private data, game files, game executables, or dumps containing copyrighted game bytes. Provide the smallest authored reproduction and redacted logs necessary. Steam/Enigma-protected builds are unsupported; reports must concern the GOG DRM-free releases.