# Security `dsh-plugin-update-audit` is deliberately read-only. It does not spawn package-manager commands and does not modify Profile manifests, lockfiles, installed packages, or Git repositories. Online audits send only public npm package names to `registry.npmjs.org` and public GitHub owner/repository names to `api.github.com`. Local dependency paths are redacted from results. No API key is required or read. Treat every result as advisory. A version difference is not permission to update, and a matching version is not a security endorsement. Review upstream source and release notes before changing a Profile. Please report vulnerabilities privately through GitHub's security advisory feature after the repository is published. Do not include credentials, tokens, private package names, or private repository URLs in public reports.