Skip to content

Security: leonardoxr/dsh-plugin-manager

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest published release. Upgrade before reporting behavior that affects an older release.

Version Supported
0.2.x Yes
< 0.2.0 No

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and include:

  • affected version and platform;
  • a minimal reproduction;
  • expected and observed security boundaries;
  • impact and any known mitigations.

Please avoid accessing data that is not yours or testing against systems without permission.

Trust model

  • Loopback RPC authority limits network reachability; it is not user authentication.
  • Installed plugins execute inside the DSH host with the same operating-system user privileges as DSH. Disabling package lifecycle scripts does not sandbox runtime code.
  • Install only reviewed exact versions from trusted publishers.
  • The active profile and package-manager executable are trusted same-user resources. Supported DSH writers are expected to honor shared file locks; a malicious or non-cooperating local writer is outside this plugin's isolation boundary.

There aren't any published security advisories