Skip to content

Security: VidTu/Ksyxis

docs/SECURITY.md

Security Policy

Vulnerabilities

Reporting

Ksyxis is a Minecraft mod. Proper security in this realm is a rare occasion. Additionally, the niche/role of Ksyxis isn't very prone to vulnerabilities. However, if you think the bug you have found is a vulnerability, you can report it privately via any of the following methods:

  • GitHub Private vulnerability reporting: Head over to the Security tab and click "Report a vulnerability".
  • Mail: imvidtu <at> proton <dot> me

Where possible, prefer GitHub Private vulnerability reporting.

Supported Versions

The only supported versions for vulnerability reporting are:

  • The latest release published to Modrinth, CurseForge, and/or GitHub.
  • The latest pre-release published to GitHub1.
  • The latest alpha and/or beta published to Modrinth and/or CurseForge1.
  • The latest Git commit build.

Artifacts (Binaries/JARs)

Reproducible Builds

Status of reproducible builds/binaries:

  • >=1.4.0: All builds should be fully reproducible.
  • >=1.3.3 <=1.3.4: All builds require umask to be 022 to be reproducible.
  • <=1.3.2: Builds are not reproducible, modification timestamps are stored in JARs.

For better results, every release should be compiled with:

./gradlew clean assemble --no-daemon --no-build-cache --no-configuration-cache --no-isolated-projects --rerun-tasks --refresh-dependencies

Supply Chain

Ksyxis has implemented supply chain validation where possible:

  • Gradle Wrapper (gradle/wrapper/gradle-wrapper.jar) is verified on GitHub CI on every commit by gradle/actions/setup-gradle action. Verify it locally too.
  • Gradle distribution is verified by the wrapper via distributionSha256Sum in gradle-wrapper.properties file after downloading.
  • All Gradle plugins and dependencies used are verified via hashes/checksums in verification-metadata.xml. To avoid fetching keys for signatures, the local PGP keystore is used from armored verification-keyring.keys. You can disable or replace the keyring if you want to use your own pubkey keystore.
  • All GitHub CI workflows are SHA-pinned.

However, Gradle Java Toolchains and Foojay Disco API Resolver are missing supply-chain verification. Therefore, you must install Java 8 and Java 25 from your preferred vendors and disable auto-provisioning. You can disable it per-repository (in ./gradle.properties file), per-build (by using ./gradlew -Dorg.gradle.java.installations.auto-download=false [...]), or system-wide (in $GRADLE_HOME/gradle.properties file), at your choice.

Footnotes

  1. Pre-release, alpha and beta versions are supported only if they were published after the latest stable release. ↩ ↩2

There aren't any published security advisories