# Security policy ## Scope `dsh-secure-remote` handles SSH connection profiles, remote paths and remote command transport. A security issue may expose local SSH metadata, credentials, remote files or command execution. ## Reporting a vulnerability Please do not open a public issue for an undisclosed vulnerability. Use a private GitHub Security Advisory for this repository, or contact the repository maintainers privately through GitHub. Include: - affected version and local operating system; - a minimal reproduction without private keys, passwords, hostnames or private source code; - impact and any known mitigation. We will acknowledge reports when possible and coordinate a fix before publishing details. ## Safe reporting rules - Never attach a private key, password, `known_hosts`, DSH profile database or complete SSH stderr. - Redact hostnames, usernames, IP addresses and remote paths from screenshots and logs. - Do not test against systems you do not own or have permission to assess.