Skip to content

Security: Metaphor-ReFantazio-Offline/metaphor-refantazio-offline-setup-assistant

Security

SECURITY.md

Security Policy

๐Ÿ›ก๏ธ Supported Versions

We actively support the following versions of Metaphor: ReFantazio Offline Setup Assistant:

Version Supported
2.1.x โœ… Yes
2.0.x โœ… Yes
1.9.x โš ๏ธ Limited support
< 1.9 โŒ No

๐Ÿšจ Reporting a Vulnerability

The security of our gaming community is important to us. If you discover a security vulnerability, please follow these steps:

๐Ÿ“ง Contact Information

Primary Contact: security@metaphor-offline.com GPG Key: Available here

๐Ÿ” What to Include

When reporting a vulnerability, please include:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact on users and the gaming experience
  • Steps to Reproduce: Detailed reproduction steps
  • Proof of Concept: Code or screenshots (if applicable)
  • Environment: OS, version, configuration details
  • Severity Assessment: Your assessment of severity level

โฑ๏ธ Response Timeline

  • Acknowledgment: Within 24 hours
  • Initial Assessment: Within 72 hours
  • Regular Updates: Every 7 days until resolution
  • Resolution: Varies by severity (see below)

๐ŸŽฏ Severity Levels

๐Ÿ”ด Critical (24-48 hours)

  • Remote code execution
  • Unauthorized access to game files
  • User data exposure
  • System compromise

๐ŸŸ  High (3-7 days)

  • Privilege escalation
  • Authentication bypass
  • Sensitive information disclosure
  • Denial of service

๐ŸŸก Medium (2-4 weeks)

  • Input validation issues
  • Information leakage
  • Configuration vulnerabilities
  • Limited DoS

๐ŸŸข Low (1-3 months)

  • Minor information disclosure
  • Low-impact configuration issues
  • Cosmetic security issues

๐Ÿ” Security Best Practices

For Users

Download Safety

  • โœ… Always download from official sources
  • โœ… Verify checksums/signatures
  • โœ… Use antivirus software
  • โŒ Don't download from unofficial sites

Installation Security

  • โœ… Run with minimal required permissions
  • โœ… Keep software updated
  • โœ… Use official configuration files
  • โŒ Don't run as administrator unless necessary

Configuration Security

  • โœ… Use strong, unique passwords
  • โœ… Enable available security features
  • โœ… Regular backup of configurations
  • โŒ Don't share configuration files with sensitive data

For Developers

Code Security

  • โœ… Input validation and sanitization
  • โœ… Secure coding practices
  • โœ… Regular dependency updates
  • โœ… Code review process

Build Security

  • โœ… Secure build pipeline
  • โœ… Signed releases
  • โœ… Vulnerability scanning
  • โœ… Secure storage of secrets

๐Ÿ† Responsible Disclosure

We believe in responsible disclosure and work with security researchers to protect our users.

๐ŸŽ Recognition Program

While we don't offer monetary rewards, we recognize security researchers who help us improve:

  • Hall of Fame: Recognition on our security page
  • Special Thanks: Acknowledgment in release notes
  • Community Status: Special role in our Discord
  • Early Access: Beta access to new features

๐Ÿ“‹ Disclosure Process

  1. Report: Submit vulnerability through secure channels
  2. Validate: We confirm and assess the issue
  3. Fix: Develop and test the fix
  4. Coordinate: Work with reporter on disclosure timing
  5. Release: Public disclosure after fix deployment
  6. Recognition: Credit reporter (if desired)

๐Ÿ› ๏ธ Security Measures

Current Protections

Application Security

  • Input validation on all user inputs
  • Secure file handling and permissions
  • Sandboxed execution environment
  • Regular security audits

Communication Security

  • HTTPS for all web communications
  • Certificate pinning where applicable
  • Secure update mechanisms
  • Encrypted configuration storage

Build Security

  • Automated security scanning
  • Dependency vulnerability checks
  • Signed releases with verification
  • Secure CI/CD pipeline

Planned Improvements

  • Enhanced encryption for sensitive data
  • Additional sandboxing mechanisms
  • Improved audit logging
  • Multi-factor authentication support

๐Ÿ“š Security Resources

Documentation

Tools & References

๐Ÿšซ Out of Scope

The following are typically not considered security vulnerabilities:

Expected Behavior

  • Features working as designed
  • Performance issues
  • UI/UX concerns
  • Compatibility problems

Third-Party Issues

  • Game-specific bugs or vulnerabilities
  • OS-level security issues
  • Hardware-related problems
  • Network configuration issues

Low-Impact Issues

  • Theoretical attacks without practical impact
  • Issues requiring physical access
  • Social engineering vectors
  • Cosmetic issues

๐Ÿ“ž Emergency Contact

For critical security issues requiring immediate attention:

๐Ÿ“„ Legal

Safe Harbor

We will not pursue legal action against security researchers who:

  • Make good faith efforts to avoid privacy violations
  • Don't access, modify, or delete user data
  • Don't perform attacks against our infrastructure
  • Don't violate any applicable laws

Confidentiality

All security reports are treated as confidential until public disclosure is agreed upon.


Thank you for helping keep the Metaphor: ReFantazio community safe! ๐ŸŽฎ๐Ÿ›ก๏ธ

There aren't any published security advisories