Security
Report a security problem
If you find a plugin that is malicious or a security risk, or a security problem in the hub itself, report it privately.
How to report
- On GitHub: use private vulnerability reporting in the registry repository.
- By email: security@runesmith.dev
Include the plugin ID and version, what you found, and how to reproduce it if you can. Do not open a public issue for security problems.
What happens next
- Runesmith acknowledges your report within one day.
- If the report is credible, new installs of the plugin are paused while it is investigated. People who have it installed keep it and see a notice.
- If the problem is confirmed, affected versions are blocked. Runesmith disables blocked plugins on users' machines at its next check, and an advisory is published. You are credited if you want to be.
Advisories
Every active block and freeze is listed on the advisories page. Security advisories are also published in the registry repository.
Other reports
Broken plugins and policy problems are not security issues. Use the Report menu on the plugin's page.