Security Policy

August 28, 2026 ยท View on GitHub

Supported Versions

Security fixes are provided for the latest published minor release.

VersionSupported
0.4.xYes
0.3.xNo
0.2.xNo
0.1.xNo

Reporting A Vulnerability

Do not open a public issue for a suspected vulnerability. Use the repository's private security advisory form.

Include the affected Testkit and DSH versions, runner, subject source kind, impact, and a minimal reproduction when safe. Do not include credentials, proprietary plugin source, or unsanitized lifecycle logs.

Maintainers will acknowledge a report within seven days, keep the reporter informed while it is assessed, and coordinate disclosure after a fix is available. If the report is outside this project's boundary, the response will identify the responsible component when possible.

Security Boundary

Docker is the default isolation boundary, not a guarantee against malicious kernel-level behavior. --runner local --unsafe-local executes plugin install and runtime code directly on the host and is intended only for trusted sources.