Policy
Publisher policy
This policy applies to everyone who publishes plugins on the Runesmith hub. Registering a plugin means you accept it. Breaking it can lead to a plugin being frozen, blocked or deleted, and a publisher being suspended or blocked.
Your code
- No malware, and nothing that acts against the user: no stealing data, credentials or tokens, no hidden downloads of code, no mining.
- No collecting data about users unless your README says what you collect and why, and your plugin asks the user before it starts.
- No advertising inside the editor.
- No obfuscation. The hub builds from your source, and reviewers and users must be able to read what runs.
- Declare every capability your plugin uses, with an honest reason.
- Ship only what you have the right to distribute, under licenses that allow it.
Your accounts
- Protect the GitHub accounts that can release your plugin with two-factor authentication.
- Keep the list of maintainers current.
- If an account or a release is compromised, tell Runesmith at once through the security page.
Reports
- Answer security reports within 14 days.
- Answer reports of broken behaviour in your repository within 14 days.
- Cooperate with administrators while a report is investigated.
Changes
Runesmith may change this policy. Changes are made in the registry repository and announced there.