The vast majority of security vulnerabilities will be handled via the Paradox Interactive with the game engine. We do use utilities that should be reported if there is a known vulnerability.
If you discover a security vulnerability in Millennium Dawn, please report it responsibly:
- Do not open a public issue or pull request
- Do not discuss the vulnerability in public channels
- Report the issue privately to the development team
To report a security vulnerability, please contact the development team at:
- Email: millenniumdawnmod@gmail.com
- GitHub: Create a draft security advisory on the Millennium Dawn repository
When reporting a vulnerability, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
This project uses Dependabot to automatically monitor and update dependencies for security vulnerabilities.
Our Dependabot configuration includes:
- GitHub Actions: Weekly updates for workflow dependencies
- Python Dependencies: Weekly updates for tools dependencies
- Documentation site (Bun / Astro): Weekly updates for
docs/dependencies (package.json/bun.lock)