Skip to content

Security: MillenniumDawn/Millennium-Dawn

Security

SECURITY.md

Security Policy

The vast majority of security vulnerabilities will be handled via the Paradox Interactive with the game engine. We do use utilities that should be reported if there is a known vulnerability.

Reporting a Vulnerability

If you discover a security vulnerability in Millennium Dawn, please report it responsibly:

  1. Do not open a public issue or pull request
  2. Do not discuss the vulnerability in public channels
  3. Report the issue privately to the development team

How to Report

To report a security vulnerability, please contact the development team at:

When reporting a vulnerability, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment

Dependabot Security Updates

This project uses Dependabot to automatically monitor and update dependencies for security vulnerabilities.

Configuration

Our Dependabot configuration includes:

  • GitHub Actions: Weekly updates for workflow dependencies
  • Python Dependencies: Weekly updates for tools dependencies
  • Documentation site (Bun / Astro): Weekly updates for docs/ dependencies (package.json / bun.lock)

There aren't any published security advisories