Ksyxis is a Minecraft mod. Proper security in this realm is a rare occasion. Additionally, the niche/role of Ksyxis isn't very prone to vulnerabilities. However, if you think the bug you have found is a vulnerability, you can report it privately via any of the following methods:
- GitHub Private vulnerability reporting: Head over to the Security tab and click "Report a vulnerability".
- Mail:
imvidtu <at> proton <dot> me
Where possible, prefer GitHub Private vulnerability reporting.
The only supported versions for vulnerability reporting are:
- The latest release published to Modrinth, CurseForge, and/or GitHub.
- The latest pre-release published to GitHub1.
- The latest alpha and/or beta published to Modrinth and/or CurseForge1.
- The latest Git commit build.
Status of reproducible builds/binaries:
- >=1.4.0: All builds should be fully reproducible.
- >=1.3.3
<=1.3.4:
All builds require
umaskto be022to be reproducible. - <=1.3.2: Builds are not reproducible, modification timestamps are stored in JARs.
For better results, every release should be compiled with:
./gradlew clean assemble --no-daemon --no-build-cache --no-configuration-cache --no-isolated-projects --rerun-tasks --refresh-dependenciesKsyxis has implemented supply chain validation where possible:
- Gradle Wrapper (
gradle/wrapper/gradle-wrapper.jar) is verified on GitHub CI on every commit bygradle/actions/setup-gradleaction. Verify it locally too. - Gradle distribution is verified by the wrapper via
distributionSha256Sumin gradle-wrapper.properties file after downloading. - All Gradle plugins and dependencies used are verified via hashes/checksums in verification-metadata.xml. To avoid fetching keys for signatures, the local PGP keystore is used from armored verification-keyring.keys. You can disable or replace the keyring if you want to use your own pubkey keystore.
- All GitHub CI workflows are SHA-pinned.
However, Gradle Java Toolchains and Foojay Disco API Resolver
are missing supply-chain verification. Therefore, you must
install Java 8 and Java 25 from your preferred vendors and
disable auto-provisioning.
You can disable it per-repository (in ./gradle.properties file), per-build (by
using ./gradlew -Dorg.gradle.java.installations.auto-download=false [...]),
or system-wide (in $GRADLE_HOME/gradle.properties file), at your choice.