Files
runicnpc-rust/SECURITY.md
wtclaude 249f2e513f
All checks were successful
PR Checks / plugin-checks (pull_request) Successful in -1m44s
feat: stage 0, an empty RunicNPC that releases through CI
The repository RunicNPC is built in (docs/runicnpc/PLAN.md §9, stage 0):

- plugin/RunicNPC.cs: `// Requires: Kits` (D217), `[Info]` with the 0.0.0
  placeholder the release stamps, `RunicNpc_ApiVersion()` (API 1), and
  `rnpc.status`, which reports the version and which hooks have fired. It
  spawns nothing.
- plugin.toml: the API version, the framework floors it was loaded on
  (Oxide 2.0.7726, Carbon 2.0.259) and requires_plugins = ["Kits"].
- scripts/checkPlugin.js, adapted from Rust-Plugins': every hook listed and
  void unless written down; chat-command signatures; every RunicNpc_ call
  reachable by Call (the HumanNPC trap, PLAN.md §1.2); ApiVersion,
  `// Requires:` and [Info] agreeing with plugin.toml. 23 self-tests, including
  the real plugin and a CRLF checkout.
- PR Checks on PRs into main and edge; the release workflow on main, with
  Rust-Plugins' release engine unchanged and an adapter that ships
  runicnpc-<ver>.tar.gz (runicnpc/RunicNPC.cs + manifest.json) and SHA256SUMS.
  No bundle dispatch until stage 4.
- tools/: the rig panel scripts, with the panel and server ids moved into a
  git-ignored tools/rigs.json. `con.js` became `console.js`: CON is a reserved
  device name on Windows, and git there cannot open the file.
- README, CONTRIBUTING (edge-based flow, AI disclosure, borrow-not-copy),
  SECURITY, the code of conduct, issue and PR templates.

`feat:` so the cutover to main cuts the first release, 0.1.0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
2026-09-29 21:01:49 -05:00

2.2 KiB

Security Policy

Thank you for helping keep Runic Gateway and its users safe.

Reporting a vulnerability

Please do not report security vulnerabilities through public issues, pull requests, or the wiki. A public report tips off attackers before a fix is available.

Instead, report privately by email to:

whitlocktech@gmail.com

Please include as much of the following as you can:

  • The repository and component affected.
  • The type of issue (e.g. authentication bypass, injection, secret exposure, remote code execution, denial of service).
  • Step-by-step instructions to reproduce, and a proof-of-concept if you have one.
  • The impact — what an attacker could do with it.
  • Any suggested remediation.

You will receive an acknowledgement of your report, typically within a few days. We will keep you informed as we investigate and work toward a fix, and we are happy to credit you in the release notes once the issue is resolved (let us know if you would prefer to remain anonymous).

Scope

Runic Gateway is a self-hosted platform made up of several components:

Component Repo Network exposure
Website (site + admin + API) RunicGateway/website Internet-facing (behind a reverse proxy)
rust-link sidecar RunicGateway/Rust-Link The only network-facing part of the game bridge
Oxide bridge plugin RunicGateway/Rust-Plugins Loopback only — dials the sidecar on 127.0.0.1
RunicNPC RunicGateway/runicnpc-rust None — an in-process plugin; talks to no network, and reaches the site only through the bridge
Documentation RunicGateway/docs Content only

Because instances are self-hosted, the security of any given deployment also depends on how it is configured and operated — strong secrets (JWT_SECRET, SECRET_ENC_KEY, database and admin passwords), a correctly configured reverse proxy and TRUST_PROXY, and keeping the shard itself unreachable from the internet (only the sidecar should be exposed). See each repo's README for the security model.

Supported versions

This project is developed continuously and does not maintain long-term release branches. Security fixes land on main; please run a recent build.