# Security Policy The currently supported release line is `0.1.x`. Security fixes are provided on the latest published `0.1.x` release only. Do not commit credentials, user project data, SQLite runtime files or Session transcripts. Report suspected vulnerabilities privately through GitHub Security Advisories for `esonx/dsh-project-j4agent`; do not open a public issue until coordinated disclosure is complete. The v0.1.0 threat boundary assumes one local DSH user. DSH and installed plugins share a trusted Host process. Browser, Workspace, Session and Agent identifiers are not authentication identities by themselves. J4Agent does not store model provider credentials.