All checks were successful
PR Checks / plugin-checks (pull_request) Successful in -1m44s
The repository RunicNPC is built in (docs/runicnpc/PLAN.md §9, stage 0): - plugin/RunicNPC.cs: `// Requires: Kits` (D217), `[Info]` with the 0.0.0 placeholder the release stamps, `RunicNpc_ApiVersion()` (API 1), and `rnpc.status`, which reports the version and which hooks have fired. It spawns nothing. - plugin.toml: the API version, the framework floors it was loaded on (Oxide 2.0.7726, Carbon 2.0.259) and requires_plugins = ["Kits"]. - scripts/checkPlugin.js, adapted from Rust-Plugins': every hook listed and void unless written down; chat-command signatures; every RunicNpc_ call reachable by Call (the HumanNPC trap, PLAN.md §1.2); ApiVersion, `// Requires:` and [Info] agreeing with plugin.toml. 23 self-tests, including the real plugin and a CRLF checkout. - PR Checks on PRs into main and edge; the release workflow on main, with Rust-Plugins' release engine unchanged and an adapter that ships runicnpc-<ver>.tar.gz (runicnpc/RunicNPC.cs + manifest.json) and SHA256SUMS. No bundle dispatch until stage 4. - tools/: the rig panel scripts, with the panel and server ids moved into a git-ignored tools/rigs.json. `con.js` became `console.js`: CON is a reserved device name on Windows, and git there cannot open the file. - README, CONTRIBUTING (edge-based flow, AI disclosure, borrow-not-copy), SECURITY, the code of conduct, issue and PR templates. `feat:` so the cutover to main cuts the first release, 0.1.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
52 lines
2.2 KiB
Markdown
52 lines
2.2 KiB
Markdown
# Security Policy
|
|
|
|
Thank you for helping keep Runic Gateway and its users safe.
|
|
|
|
## Reporting a vulnerability
|
|
|
|
**Please do not report security vulnerabilities through public issues, pull
|
|
requests, or the wiki.** A public report tips off attackers before a fix is
|
|
available.
|
|
|
|
Instead, report privately by email to:
|
|
|
|
**whitlocktech@gmail.com**
|
|
|
|
Please include as much of the following as you can:
|
|
|
|
- The repository and component affected.
|
|
- The type of issue (e.g. authentication bypass, injection, secret exposure,
|
|
remote code execution, denial of service).
|
|
- Step-by-step instructions to reproduce, and a proof-of-concept if you have one.
|
|
- The impact — what an attacker could do with it.
|
|
- Any suggested remediation.
|
|
|
|
You will receive an acknowledgement of your report, typically within a few days.
|
|
We will keep you informed as we investigate and work toward a fix, and we are
|
|
happy to credit you in the release notes once the issue is resolved (let us know
|
|
if you would prefer to remain anonymous).
|
|
|
|
## Scope
|
|
|
|
Runic Gateway is a self-hosted platform made up of several components:
|
|
|
|
| Component | Repo | Network exposure |
|
|
|---|---|---|
|
|
| Website (site + admin + API) | `RunicGateway/website` | Internet-facing (behind a reverse proxy) |
|
|
| rust-link sidecar | `RunicGateway/Rust-Link` | The only network-facing part of the game bridge |
|
|
| Oxide bridge plugin | `RunicGateway/Rust-Plugins` | Loopback only — dials the sidecar on `127.0.0.1` |
|
|
| RunicNPC | `RunicGateway/runicnpc-rust` | None — an in-process plugin; talks to no network, and reaches the site only through the bridge |
|
|
| Documentation | `RunicGateway/docs` | Content only |
|
|
|
|
Because instances are self-hosted, the security of any given deployment also
|
|
depends on how it is configured and operated — strong secrets (`JWT_SECRET`,
|
|
`SECRET_ENC_KEY`, database and admin passwords), a correctly configured reverse
|
|
proxy and `TRUST_PROXY`, and keeping the shard itself unreachable from the
|
|
internet (only the sidecar should be exposed). See each repo's README for the
|
|
security model.
|
|
|
|
## Supported versions
|
|
|
|
This project is developed continuously and does not maintain long-term release
|
|
branches. Security fixes land on `main`; please run a recent build.
|