Files
Warium-NeoForge-1.21.1/docs/security-review.md
Codex 6ef5fdd378
Some checks failed
Build / build (push) Failing after 13m38s
Release Dry Run / release-dry-run (push) Successful in 5s
Codex Template Compliance / template-compliance (push) Successful in 5s
Bootstrap Warium NeoForge port scaffold
2026-05-09 20:59:05 +02:00

1.1 KiB

Security Review

Scope

Project:

Warium NeoForge 1.21.1 Port

Reviewed version or commit:

Unreleased scaffold

Code Patterns Checked

  • No secrets committed.
  • Generated original assets are ignored.
  • Decompiled source output is ignored.
  • Original jar artifacts are ignored.
  • Private integration jars are ignored.
  • External network calls are documented.

Dependency Review

Command:

./gradlew --no-daemon build

Result:

Pending runner execution.

Runtime Review

  • Gitea publishing uses REGISTRY_TOKEN secret only.
  • Package download is private/internal pending rights clearance.
  • Source Warium jar is downloaded from Modrinth and verified by SHA1.
  • Required private integrations are shimmed until real NeoForge 1.21.1 jars exist.

Release Notes

Known residual risks:

The current scaffold preserves registry IDs and resources but does not yet fully port the original MCreator behavior procedures, block entities, GUI logic, entities, AI, weapons, ordnance, nuclear effects, or external integration APIs.