Skip to content

Security: Asteroid0449/dsh-agent-plugin-research

Security

SECURITY.md

安全策略 / Security Policy

支持范围

当前只为最新 GitHub Release 和仓库默认分支提供安全修复。DeepSeek Harness 仍处于 developer preview;报告时请注明准确的 DSH、Node.js 和插件版本。

报告漏洞

不要在公开 Issue 中发布可用的利用代码、API key、token、凭据文件或未经脱敏的用户路径。

优先使用本仓库的 GitHub Private vulnerability reporting / Security advisory。如果该入口尚未启用,请建立一个不含利用细节的普通 Issue,请求维护者提供私下联络方式。收到确认前不要公开完整细节。

报告应包含影响范围、前置条件、最小复现、可能影响的安装来源,以及建议的缓解措施。第三方插件本身的恶意行为应同时报告给其维护者;本项目的边界是搜索、检查、安装协调和验证。


Only the latest GitHub Release and the default branch receive security fixes. Do not post exploits, credentials, tokens, or unredacted user paths publicly. Prefer GitHub private vulnerability reporting; if unavailable, open a detail-free issue asking for a private contact channel. Include affected versions, prerequisites, a minimal reproduction, impact, and mitigations.

There aren't any published security advisories