Do not post credentials, private room details or vulnerability exploits in public issues. Use GitHub's private vulnerability reporting for this repository:
https://github.com/fillbyte/ball2d/security/advisories/new
Include the affected SDK version, impact, a minimal reproduction and whether the official service is affected. Test only resources you control. Never include a live API key; revoke exposed credentials through your Ball2D account.
The 0.2.0 development candidate is under validation; earlier runtime versions are being withdrawn. No response-time SLA or bounty is offered by this document. The package does not contain private implementation source, but distributed executable code can be inspected. API authorization protects access to the official service and does not make client-side code confidential.