Skip to content

Security Policy

To ensure the integrity, safety, and reliability of the Dice Chess Engine, the repository employs a multi-tiered security and analysis strategy. This page documents our active security measures and outlines how to report vulnerabilities.


Our codebase is continuously monitored using industry-standard static analysis and security tools:

LayerTool / ServiceSecurity Focus
Local Pre-commitbetterleaksPrevents API keys, credentials, and secrets from entering git history.
CI Workflow Analysisactionlint + ShellCheckValidates workflow structure and checks embedded shell plus repository release/build scripts.
CI Static AnalysisCodeQLAnalyzes GitHub Actions and JavaScript/TypeScript sources. Scala is outside CodeQL’s supported languages.
CI Secret Scanbetterleaks (via CodeRabbit)Double-checks all PR changes for secrets before merging to main.
Vulnerability ScanningSonarCloudAutomatically flags code smells, logic errors, and security issues.
Dependency GraphSbt Dependency SubmissionSubmits the resolved Scala/JVM graph so GitHub can monitor transitive dependencies that are not statically visible in build.sbt.
Dependency AuditsDependabot + Dependency ReviewOpens version/security updates and blocks known high or critical dependency vulnerabilities in PR dependency changes GitHub can derive safely. See Dependency Updates.
Push ProtectionGitHub Secret ScanningRejects push events containing detected credentials.

If you discover a security vulnerability in the engine, please do not create a public issue or public pull request. Instead, submit a private report so we can resolve the issue before public disclosure.

Preferred Method: GitHub Private Vulnerability Report

Section titled “Preferred Method: GitHub Private Vulnerability Report”

GitHub provides a native, secure channel for vulnerability disclosure:

  1. Go to the main page of the dicechess-engine repository.
  2. Under the repository name, click Security.
  3. In the left sidebar under Vulnerability reporting, click Advisories.
  4. Click Report a vulnerability to fill out a secure form.

You can also contact the maintainer directly via email: jegors.cemisovs@gmail.com. Please use a descriptive subject line (e.g., [Security Vulnerability] Dice Chess Engine).

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours.
  2. Status Update: We will provide a fix timeline or status update within 7 days.
  3. Disclosure: A patched release and public security advisory will be published once the fix is deployed.