Thank you for helping keep Perastage safe.
Perastage is an open-source application used to work with stage, lighting, MVR and GDTF workflows. If you find a security issue, suspicious behavior, or anything that could put users, files or systems at risk, please report it responsibly.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, send an email to:
Please include as much relevant information as possible:
- A clear description of the issue.
- Steps to reproduce it, if possible.
- The Perastage version affected.
- Your operating system.
- Any related files, logs or screenshots that may help understand the problem.
- Whether the issue affects imported files, exported files, installation, updates, crashes, or another part of the application.
If you are not sure whether something is a security issue, feel free to report it anyway.
After receiving a report, I will try to:
- Confirm that the report has been received.
- Review the issue as soon as possible.
- Ask for more details if needed.
- Work on a fix when the issue is confirmed.
- Credit the reporter if appropriate and if they want to be credited.
Please keep in mind that Perastage is an independent open-source project, so response times may vary depending on availability and the complexity of the issue.
Security fixes will generally focus on the latest public release of Perastage.
Older versions may not receive security updates unless the issue is especially important or easy to patch.
For the best experience and safety, users are encouraged to use the latest available version.
Please give reasonable time to investigate and fix the issue before sharing details publicly.
This helps protect users while the problem is being reviewed and corrected.
Security reports may include, but are not limited to:
- Crashes caused by malformed files.
- Unsafe handling of imported MVR, GDTF, OBJ, GLB, 3DS or related files.
- Problems with file paths or extracted archives.
- Unexpected file creation, overwrite or deletion.
- Issues related to installers, releases or downloaded assets.
- Any behavior that could compromise a user's system or data.
General bugs, feature requests or usability issues should be reported using GitHub Issues instead.