Skip to content

Security: mcj-coder-org/fantasy-rpg-world

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Contact

  • Email: [security contact TBD]
  • GitHub: Open a private security advisory

What to Include

  1. Description of the vulnerability
  2. Steps to reproduce
  3. Potential impact
  4. Any suggested fixes

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Resolution target: Depends on severity

Supported Versions

Version Supported
Development Yes

Security Practices

Code Review

All code changes require:

  • PR review by .NET Specialist persona
  • Security-focused review for sensitive areas
  • No merge without approval

Dependencies

  • Regular dependency updates
  • Vulnerability scanning enabled
  • No unmaintained packages

Secrets Management

  • No secrets in code or commits
  • Use environment variables
  • Secrets detected in commits will be rotated

Data Protection

  • Minimize data collection
  • Encrypt sensitive data
  • Follow platform security guidelines

Scope

This security policy covers:

  • Source code in this repository
  • Build and deployment configurations
  • Documentation with security implications

Out of scope:

  • Third-party dependencies (report to maintainers)
  • Platform-specific issues (Unity, .NET)

There aren’t any published security advisories