DnDGem is preparing Public Alpha (0.x prereleases). Security fixes will target the default development branch until a stable release exists.
Please report security issues privately. Do not open public issues for undisclosed vulnerabilities.
Preferred contact: security@dndgem.dev
Product / Alpha support (non-security): support@dndgem.dev · https://dndgem.dev/support/
Include:
- description of the issue
- impact assessment if known
- reproduction steps or proof-of-concept if available
- affected commit/branch if known
You should receive an acknowledgement when the report is received. Timing may vary during early development.
- Use the committed
pnpm-lock.yaml - Prefer
pnpm install --frozen-lockfilein CI - Keep GitHub Actions pinned to major versions with least privilege (
contents: readby default) - Do not commit secrets (
.env, credentials, tokens)