Please report security vulnerabilities privately through GitHub's private vulnerability reporting:
Security → Report a vulnerability at https://github.com/PerryLink/dsh-auto-review/security/advisories/new
Do not open a public issue for security findings.
Before reporting, sanitize everything you paste: remove tokens, API keys, credentials, authorization headers, session contents, and personal data. Logs without secrets only.
- affected package version (and DeepSeek Harness runtime version)
- a minimal reproduction
- your impact assessment
- acknowledgement within 7 days
- status updates at least every 14 days until resolution
- coordinated disclosure: the fix and advisory are prepared first; the finding is disclosed publicly after the fix ships
- reporters are credited in the advisory and CHANGELOG unless they ask to stay anonymous
- advisories follow GitHub's advisory workflow and are published together with the fix