Creative Commons asks for attribution "in a manner reasonable to the medium." That is deliberately flexible, and flexibility is uncomfortable when you are the one who has to decide whether what you wrote is enough.
Here is the practical version.
#The four things
For a CC BY or CC BY-SA asset, a complete credit names:
- The creator, by whatever name they asked to be called.
- The work, by its title, if it has one.
- The license, by name, ideally linked.
- Whether you changed it, if you did.
So: "Forest Kit by Quaternius, CC BY 4.0, recolored." That is a complete credit. Most of what people write is missing the license and the modification note, which are the two parts that are actually load bearing.
#Where it goes
Anywhere a reasonable person would look for it. In practice that means one of:
- A credits screen in the game, reachable from the main menu.
- A
CREDITS.txtorTHIRD-PARTY.mdshipped alongside the executable. - The store page, for a small game where a credits screen would be the only screen.
A credits screen buried three menus deep is accepted practice. A credit that exists nowhere in the shipped product, only in your repository, is not.
#What is courtesy rather than obligation
CC0 needs nothing. Crediting anyway is generous and good for the ecosystem, and many people group these under a "thanks" heading separate from the required credits. That distinction is worth keeping, because it tells a future you which lines you may not remove.
Linking back is required only where practical. In a game, a clickable link often is not, and naming the source is enough.
Store-bought assets usually do not require credit at all. Check, because some sellers do ask.
#The reason it goes wrong
Nobody gets attribution wrong because they misread the license. They get it wrong because the credits file is written in the last week of a project, from memory, about four hundred files downloaded over eighteen months.
At that point the honest outcomes are: a credit that names the wrong person, a credit that omits the license, or an asset that gets quietly dropped because nobody can establish what it was.
#Write it continuously, not at the end
The fix is structural. If the license and the creator are recorded when an asset arrives, the credits file is a report rather than an act of recall.

That is what Tessera does. Copy assets into a game and a CREDITS.md is written next to them,
listing every pack with its creator, its license and its source, with the ones that require credit
first and the CC0 ones listed as thanks. It is rebuilt from the record every time, so it is never
out of date and you never write it.
Install Tessera, or read licenses and games and projects.