1.1 KiB
1.1 KiB
Security Review
Scope
Project:
Warium NeoForge 1.21.1 Port
Reviewed version or commit:
Unreleased scaffold
Code Patterns Checked
- No secrets committed.
- Generated original assets are ignored.
- Decompiled source output is ignored.
- Original jar artifacts are ignored.
- Private integration jars are ignored.
- External network calls are documented.
Dependency Review
Command:
./gradlew --no-daemon build
Result:
Pending runner execution.
Runtime Review
- Gitea publishing uses
REGISTRY_TOKENsecret only. - Package download is private/internal pending rights clearance.
- Source Warium jar is downloaded from Modrinth and verified by SHA1.
- Required private integrations are shimmed until real NeoForge 1.21.1 jars exist.
Release Notes
Known residual risks:
The current scaffold preserves registry IDs and resources but does not yet fully port the original MCreator behavior procedures, block entities, GUI logic, entities, AI, weapons, ordnance, nuclear effects, or external integration APIs.