Skip to content

Security: CubDen/cubden-game

Security

SECURITY.md

Security Policy

Reporting

  • If you find a security issue, report it privately to the maintainers instead of opening a public issue.
  • Include a short description, affected files or features, reproduction steps, and impact.

Scope

  • Unexpected obfuscated code in tracked source files
  • Browser game code importing Node-only modules
  • Supply-chain or build-script changes that introduce unsafe behavior
  • Client-side behaviors that expose users to script injection or malicious redirects

Local Verification

  • Run pnpm run security:scan before commit or release.
  • Run pnpm run verify before pushing.
  • This repository includes a versioned git hook in .githooks/pre-commit.

Review Guidance

  • Reject commits that introduce minified or obfuscated code into src/ unless it is a reviewed vendored asset.
  • Reject browser game code that imports Node-only modules.
  • Review unusual changes to build config, package scripts, and scene files with extra scrutiny.

Response Guidance

  • Remove suspicious code from the working tree first.
  • Identify the introducing commit with git blame and git log.
  • Rewrite history when needed so malicious commits are no longer reachable from active branch refs.

There aren't any published security advisories