Skip to content

Security: Zaikonurami/RoShadeInfinity

Security

SECURITY.md

Security Policy

πŸ”’ Supported Versions

Currently supported versions for security updates:

Version Supported
2.0.x βœ… Yes
1.4.x ⚠️ Limited Support
< 1.4 ❌ No

🚨 Reporting a Vulnerability

If you discover a security vulnerability in RSInfinity, please follow these steps:

DO NOT open a public issue

Security vulnerabilities should be reported privately to protect users.

How to Report

  1. Email: Send details to security@rsinfinity.software (if available)
  2. Discord: Contact administrators directly on our Discord server
  3. GitHub: Use the private vulnerability reporting feature

What to Include

Please provide:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)
  • Your contact information

Response Time

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity (Critical: <7 days, High: <14 days, Medium: <30 days)

πŸ›‘οΈ Security Best Practices

When using RSInfinity:

  1. Download from Official Sources Only

  2. Verify File Integrity

    • Check SHA256 hashes (provided in releases)
    • Verify digital signatures when available
  3. Keep Updated

    • Always use the latest version
    • Enable auto-update notifications
  4. System Requirements

    • Use on legitimate Roblox installations only
    • Ensure Windows Defender/Antivirus is active
    • Run with appropriate user permissions

⚠️ Known Issues

Current known security considerations:

  • Admin Rights: The installer requires administrator privileges to modify Roblox files
  • Registry Access: Reads Roblox installation path from Windows Registry
  • File Modifications: Modifies Roblox directory to inject Reshade DLL

These are intended behaviors and necessary for the application to function.

πŸ“‹ Security Audit Log

Date Issue Severity Status
2025-12-18 Initial security review Info Complete

πŸ” Code Signing

  • Currently: Installers are not code-signed
  • Planned: Code signing certificate for future releases

πŸ“ž Contact

For security concerns:


Thank you for helping keep RSInfinity and its users safe!

There aren’t any published security advisories