Skip to content

Security: refringe/SPT-Check-Mods

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest

Reporting a Vulnerability

If you discover a security vulnerability in SPT Check Mods, please report it responsibly by following these steps:

  1. Do NOT create a public GitHub issue for security vulnerabilities
  2. Send an email to the project maintainer me@refringe.com with details about the vulnerability
  3. Include the following information:
    • Description of the vulnerability
    • Steps to reproduce the issue
    • Potential impact
    • Suggested fix (if available)

Security Considerations

SPT Check Mods handles:

  • API keys stored in %APPDATA%\SptCheckMods\apikey.txt
  • File system access for mod scanning
  • Network requests to forge.sp-tarkov.com API

Disclosure Policy

We will acknowledge receipt of your vulnerability report within 48 hours and provide regular updates on our progress. Once the vulnerability is resolved, we will coordinate with you on the disclosure timeline.

There aren’t any published security advisories