Skip to content

Security: JDProfresh/stationeers-dedicated

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x Yes
< 1.0 No

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

Do not open a public issue for security vulnerabilities.

Instead, please use GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Provide a detailed description of the vulnerability

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Resolution: Depends on severity and complexity

Security Considerations

This utility:

  • Runs with elevated privileges during installation (sudo required)
  • Manages server configuration files with sensitive data (admin secrets)
  • Executes shell commands based on user input

Built-in Protections

  • Configuration file permissions enforced (mode 600)
  • Config key validation prevents injection attacks
  • Installation directory validated before destructive operations
  • Warnings displayed for world-readable config files
  • Default admin secret must be changed before use

Disclosure Policy

We follow responsible disclosure practices. Once a fix is available, we will:

  1. Release the patched version
  2. Update the changelog with security notes
  3. Credit the reporter (unless they prefer anonymity)

There aren't any published security advisories