Skip to content

Security: Devputta/Battel-Game

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are generally applied to the latest version of the project. Support for older releases may be limited.

Reporting a Vulnerability

Please do not publish sensitive security details in a public GitHub issue.

Report security vulnerabilities privately through the repository owner's available GitHub security/contact mechanism.

Include:

  • a short description
  • affected file, endpoint, or feature
  • steps to reproduce
  • expected behavior
  • actual behavior
  • potential impact
  • a safe proof of concept, when necessary

Do not include API keys, passwords, tokens, personal data, or other secrets in a report.

Security Practices

The project should:

  • Store API keys and credentials in environment variables.
  • Never commit .env files containing real secrets.
  • Keep .env.example limited to variable names and safe placeholders.
  • Validate user-controlled input on the server.
  • Treat AI output as untrusted data.
  • Validate structured AI responses before using them.
  • Enforce round expiration on the server where applicable.
  • Prevent duplicate/replay submissions.
  • Apply appropriate rate limiting to public endpoints.
  • Avoid exposing internal stack traces or secrets to users.
  • Log diagnostics without logging credentials or sensitive data.
  • Keep dependencies reasonably up to date.
  • Run security and failure tests before deployment.

AI-Specific Considerations

User-provided text may be sent to an AI provider. AI-generated content must not be treated as trusted input.

The application should:

  • validate AI responses
  • handle malformed or empty responses
  • handle provider timeouts and rate limits
  • protect system instructions and internal configuration
  • constrain prompt-injection attempts where appropriate
  • keep API credentials on the server
  • avoid storing unnecessary user content

Responsible Testing

Only test the application and services you are authorized to test.

Resilience and audit features are intended for controlled testing of this application's own failure-handling behavior.

There aren't any published security advisories