Files
gregWiki/docs/contributors/plugin-submission-audit.md
Marvin e2839584f4 Merge Docusaurus site: all content under docs/, align with gregFramework split layout
- Move markdown and wiki-import tree into docs/; keep app shell at repo root
- Point docusaurus docs path to docs/; edit links to mleem97/gregWiki
- Sync and i18n scripts use gregWiki root and ../.wiki under gregFramework
- Sidebars: workspace layout from root docs ids; plugins under mods/extensions
- Fix redirects, module catalog URLs, release note paths, and wiki-import category keys
- Update repo inventory for split repos; Dockerfile for single-repo context

Made-with: Cursor
2026-04-09 23:39:32 +02:00

1.1 KiB

id, title, slug
id title slug
plugin-submission-audit Plugin Submission & Security Audit Workflow /contributors/plugin-submission-audit

Goal

Provide a repeatable workflow where community authors submit plugins through a Git repository URL, then pass an automated security/quality audit before publication in the wiki and release channels.

Submission Model

  1. Author opens a Plugin Submission issue.
  2. Author provides a public Git repository URL (https://...git).
  3. Maintainer triggers the security-audit workflow.

Automated Audit Steps

  • Clone submitted repository in CI.
  • Run static scan for suspicious calls and execution vectors.
  • Run secret and credential pattern checks.
  • Produce an auditable report artifact.

Release Gate Policy

  • If audit result is fail, publication is blocked.
  • If audit result is pass, maintainers can mark module as releaseReady and publish wiki/release visibility.

Multiplayer Clarification

Steamworks multiplayer remains a planned direction but is currently blocked by missing Steamworks implementation on the game developer side.