| Version | Security support |
|---|---|
latest 2.x release |
Yes |
older 2.x releases |
Best effort; upgrade first |
< 2.0 |
No |
Do not open a public issue. Use GitHub's private Report a vulnerability flow:
https://github.com/Ayerdi/dedicated-server-save-sync/security/advisories/new
Private Vulnerability Reporting is enabled for this public repository.
Include the affected version, impact, minimal reproduction steps and known mitigations. Do not attach real saves, tokens or production configuration.
- real
.envfiles; pws_...tokens;- REST passwords or DPAPI exports;
- machine-specific
config.json; - saves, ZIP archives, SQLite databases and WAL/SHM sidecars;
- rendered Traefik runtime configuration;
- logs or screenshots that contain credentials;
- private domains, users, GUIDs or filesystem paths from a real deployment.
.gitignore is only a guardrail. Always review the diff and run the secret scanner.
- A stolen Bearer token has that user's privileges until it is revoked.
- The backend validates identity metadata and ZIP structure; it does not semantically parse
Level.sav. - DPAPI protects local secrets at rest, not against malware running as the same Windows user.
- The reverse proxy must strip client-supplied Authentik identity headers.
- SQLite and ZIP confidentiality still depend on correct host filesystem permissions.
- The Gitleaks and repository checks reduce accidental exposure; they do not replace secret rotation after a leak.
bash scripts/check-repository.sh
bash scripts/run-gitleaks.sh
git diff --cachedCI also runs dependency auditing, coverage, Docker E2E, crash/restart recovery tests and Pester. Automated tests do not replace an external backup or a controlled real-game acceptance test.