Add standard open-source project files: - LICENSE.md — GNU GPL v3.0 or later (verbatim) - CONTRIBUTING.md — setup, workflow, and required AI-usage disclosure - CONTRIBUTORS.md — maintainers, contributors, AI-assistance policy - CODE_OF_CONDUCT.md — Contributor Covenant 2.1 - SECURITY.md — private vulnerability reporting - .gitea/ISSUE_TEMPLATE/* + PULL_REQUEST_TEMPLATE.md - README: License section (Copyright (C) 2026 Runic Gateway) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XmHdsbnLzDMAVQkAoTQSBe
2.0 KiB
Security Policy
Thank you for helping keep Runic Gateway and its users safe.
Reporting a vulnerability
Please do not report security vulnerabilities through public issues, pull requests, or the wiki. A public report tips off attackers before a fix is available.
Instead, report privately by email to:
Please include as much of the following as you can:
- The repository and component affected.
- The type of issue (e.g. authentication bypass, injection, secret exposure, remote code execution, denial of service).
- Step-by-step instructions to reproduce, and a proof-of-concept if you have one.
- The impact — what an attacker could do with it.
- Any suggested remediation.
You will receive an acknowledgement of your report, typically within a few days. We will keep you informed as we investigate and work toward a fix, and we are happy to credit you in the release notes once the issue is resolved (let us know if you would prefer to remain anonymous).
Scope
Runic Gateway is a self-hosted platform made up of several components:
| Component | Repo | Network exposure |
|---|---|---|
| Website (site + admin + API) | RunicGateway/website |
Internet-facing (behind a reverse proxy) |
| uo-link sidecar | RunicGateway/link |
The only network-facing part of the game bridge |
| ServUO plugin | RunicGateway/servuo-plugins |
Loopback only — dials the sidecar on 127.0.0.1 |
| Documentation | RunicGateway/docs |
Content only |
Because instances are self-hosted, the security of any given deployment also
depends on how it is configured and operated — strong secrets (JWT_SECRET,
SECRET_ENC_KEY, database and admin passwords), a correctly configured reverse
proxy and TRUST_PROXY, and keeping the shard itself unreachable from the
internet (only the sidecar should be exposed). See each repo's README for the
security model.
Supported versions
This project is developed continuously and does not maintain long-term release
branches. Security fixes land on main; please run a recent build.