Skip to content

Security: Paraso42/dshan

Security

SECURITY.md

Security Policy

Supported versions

Only the latest release of dshan receives fixes. The plugin talks to a local DSH server on 127.0.0.1 and never accepts remote connections by itself; the security boundary for agent actions is your DSH configuration (sandbox policy, approval policy, skills), which dshan does not modify.

Reporting a vulnerability

If you discover a vulnerability, please report it privately instead of opening a public issue:

Please include the affected version, a description, and (when available) a minimal reproduction. We will acknowledge within 7 days and keep you informed as the report is triaged and fixed.

There aren't any published security advisories