| Version | Supported |
|---|---|
| 2.x | Yes |
| 1.x | No |
DopamineJS packages that handle data or external communication:
dopaminejs:RewardSystempersists player state tolocalStorageby default. Pass a customstorageto move it elsewhere. Synchronous and promise-returning storages both work.dopaminejs-react:RewardsProviderwrapsRewardSystem, so the same storage note applies. Pass astorageprop to override.dopaminejs-plugin-ecosystem:WebhookIntegrationandLeaderboardPluginPOST reward events to the endpoint you configure. Nothing is sent until you set awebhookUrl.
The other packages (dopaminejs-themes, plugin-debug-overlay, plugin-feedback-effects, plugin-howler-audio, plugin-sound-packs, plugin-webgl-particles) only render and do not handle user data.
These are properties of a client-side library, not vulnerabilities. Reports about them will be closed.
- Player state is editable by the player. XP, levels, streaks and achievements live in the browser. Anyone can change them in dev tools. Saved state is validated on load so a bad value cannot crash the app or reach
Object.prototype, but it is not trusted. If a number matters (prizes, rankings, payments), compute it on your server. achievement.iconis rendered as HTML. This is on purpose, so an icon can be an<img>or an SVG. Every other achievement field is rendered as text. Never buildiconfrom user input.- A webhook secret in browser code is visible to players. With a
secret,WebhookIntegrationsendsX-Dopamine-Signature: sha256=<hex>, the HMAC-SHA256 of the exact request body. That proves the body was not altered in transit. It does not prove the sender is honest, because the player holds the key. Verify the signature on the raw body, then treat the payload as a claim. Wherecrypto.subtleis missing (plain HTTP pages), requests go out unsigned with one console warning.
Do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities privately via GitHub's Security Advisory feature:
- Go to https://github.com/BaryoDev/dopaminejs/security/advisories/new
- Describe the vulnerability, affected package(s), version, and reproduction steps.
Alternatively, email security@baryo.dev with the subject line [SECURITY] dopaminejs: <short description>.
| Action | Target |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial triage | Within 5 business days |
| Fix or mitigation | Within 30 days for high/critical severity |
We will coordinate disclosure timing with you. We aim to publish a security advisory and release a patch before public disclosure.