Skip to content

Security: jaime-gaming/dopamina

Security

SECURITY.md

Dopamina Security Policy

  1. Preamble

This Security Policy establishes the rules and guidelines governing the secure use of the interactive web application “Dopamina” (hereinafter, the “Application” or the “Platform”). The Application is an independent entertainment project developed by a student collective. Compliance with this policy is mandatory for all users.

  1. Nature of Service and Security Limitations

2.1. Non-Academic Entertainment Project: Dopamina is intended purely for entertainment and is not affiliated with any educational institution, academic staff, or government entity. 2.2. “As Is” Security: The Platform is provided “as is” and “as available,” without any guarantees of complete security. While efforts are made to minimize risks, the Developers do not guarantee the absence of errors, vulnerabilities, or security breaches. 2.3. User Responsibility: Users are responsible for ensuring that their devices are secure and for managing the environment in which they access the Platform.

  1. Acceptable Use and Restrictions

3.1. Users must access and interact with the Platform ethically, responsibly, and legally. 3.2. Prohibited Environments: The Platform must not be used within educational institutions during lessons, supervised activities, or in violation of internal rules regarding device usage. Misuse in these environments may result in disciplinary actions unrelated to the Developers.

  1. Data Handling and Storage

4.1. Local Storage: Game progress is stored locally (using localStorage or .dopamina files) and contains no personally identifiable information. 4.2. No Personal Data Collection: The Platform does not collect or transmit personal user data. 4.3. User Backup Responsibility: Users are solely responsible for backing up their game data and ensuring its integrity.

  1. Integrity and Anti-Tampering

5.1. Client-Side Limitations: Some measures are implemented to prevent simple manipulation of game data, but users may modify local files at their own risk. 5.2. Prohibition of Unauthorized Modifications: Users must not attempt to reverse engineer, decompile, or otherwise tamper with the Application’s code or algorithms. 5.3. Error Reporting: Errors or crashes are displayed in-game and logged in the console; users are encouraged to report issues through official channels.

  1. Device Safety

6.1. The Application requests no additional device permissions. 6.2. It does not access sensitive system files or data. 6.3. All resources are stored and executed locally unless otherwise specified.

  1. Updates and Security Improvements

7.1. Updates may be applied to improve security, fix bugs, or enhance gameplay. 7.2. Updates do not affect user privacy or personal data. 7.3. Users should always apply the latest version of the Platform to maintain optimal security.

  1. Contact and Reporting

8.1. Security concerns, bugs, or potential vulnerabilities can be reported through official channels on the Platform’s page. 8.2. Developers will review reports promptly but are not liable for consequences arising from unreported issues.

Supported Versions

This are the versions that already have security updates and are supported for any bugs

Version Supported
<b0.42 🟥
b0.42 🟨
b0.43 🟩
b0.44 🟥

Reporting a Vulnerability

If you discover a security vulnerability in the Dopamina Platform, we encourage you to report it responsibly so we can address it promptly.

How to Report:

Send an email describing the issue in detail to jaimegamingpro@gmail.com or jaimeferrerasg@safa-grial.es .

Include information such as:

Steps to reproduce the issue, expected behavior vs. observed behavior, screenshots or logs if available, any suggestions for mitigating the problem...

Acknowledgment and Updates:

We will acknowledge receipt of your report within 3 business days and we will provide periodic updates if necessary, depending on the complexity and impact of the issue.

Resolution:

If the vulnerability is confirmed, we will work to fix it as soon as possible, but if a report is not considered a vulnerability (e.g., user error or intended behavior), we will explain our reasoning clearly.

Good Faith and Responsible Disclosure:

Please avoid publicly disclosing the vulnerability until it has been resolved, to protect other users and reports submitted in good faith will be treated respectfully, and the reporter will not face legal or disciplinary actions.

There aren't any published security advisories