Synix is maintained by one independent developer. Security fixes are applied to the latest stable release and the current development branch.
| Version | Security support |
|---|---|
| Latest stable release | Supported |
| Current development branch | Supported while in development |
| Older releases | Update to the latest stable release first |
Please do not open a public issue containing an exploit, password, webhook, token, public IP address, private configuration, or complete launch command.
Use one of these private routes:
- Use GitHub private vulnerability reporting when the Report a vulnerability option is available.
- Join the official Synix Discord and privately contact the project owner, ubidzz.
- If neither private route is available, open a public issue containing only the words Private security contact requested. Do not include vulnerability details in that issue.
Include the following information privately when possible:
- The affected Synix version and installation type.
- The Windows version.
- A clear description of the problem and its possible impact.
- Reproduction steps that do not expose real credentials or private server data.
- Any suggested fix or mitigation.
Reports are reviewed on a best-effort basis. You may be asked for more information or a safe proof of concept. Please allow time for a fix and release before publicly disclosing a confirmed vulnerability.
This policy covers code and official release packages published by the Synix Control Panel repository. Vulnerabilities in Windows, SteamCMD, game servers, Discord, GitHub, or other third-party software should also be reported to the owner of that software.