BAD DECISION is a client-side browser game. The current implementation stores gameplay progress locally in the browser and does not use a project-owned backend for its core game state.
Security concerns can still involve:
- Dependency vulnerabilities
- Client-side injection issues
- Unsafe handling of browser storage
- Accidental secret exposure
- Malicious modifications to the deployed application
- Supply-chain risks in dependencies
Security fixes are generally applied to the active development version.
| Version | Security Support |
|---|---|
Current main |
Supported |
| Older revisions | Not guaranteed |
Please do not publish an unpatched vulnerability with reproduction details in a public issue.
Use the repository's available private security-reporting mechanism, such as GitHub Security Advisories, when enabled.
If private reporting is not enabled, open a general security contact request through the repository while avoiding sensitive exploit details. A private communication channel should be established before sharing proof-of-concept material.
A useful report should include:
- A short description
- Affected file or component
- Reproduction steps
- Expected behavior
- Actual behavior
- Impact assessment
- Relevant logs or screenshots
- A suggested mitigation, if known
Never commit:
.env
.env.local
.env.production
API keys
Access tokens
Private credentials
Private certificates
Service-account credentials
The repository's .gitignore excludes .env* files while allowing .env.example.
Use placeholder values in documentation and example configuration files.
Dependencies should be reviewed before upgrades.
Recommended checks:
npm auditFor Bun-based development, review dependency changes before committing the updated lockfile.
Do not blindly upgrade dependencies in production without checking:
- Breaking changes
- Build compatibility
- TypeScript compatibility
- Browser compatibility
- Known security advisories
Gameplay progress is stored in browser localStorage.
Do not store sensitive information in game progress or browser storage.
Browser storage should be treated as:
Client-controlled
Non-secret
Modifiable
Potentially removable
The application should never rely on local progress data as proof of identity, authorization, payment, or access control.
The project uses third-party packages for UI, build tooling, animation, icons, and effects.
Dependency versions are defined in package.json and resolved through the package manager lockfile.
Changes to dependencies should be reviewed for:
- Maintainer trust
- Package provenance
- Known vulnerabilities
- License compatibility
- Unnecessary permissions or functionality
Before release:
[ ] No secrets committed
[ ] .env files excluded
[ ] Dependencies reviewed
[ ] npm audit reviewed where applicable
[ ] TypeScript check passes
[ ] Production build passes
[ ] User-controlled values are validated
[ ] localStorage data is treated as untrusted
[ ] Error messages do not expose secrets
[ ] Deployment configuration is reviewed
Please allow reasonable time to investigate and address a reported issue before publicly disclosing technical exploit details.
Security reports should contain enough information to reproduce the issue without unnecessarily exposing credentials, personal data, or other sensitive information.