Skip to content

Security: junwei529/session-coordinator-dsh

SECURITY.md

Security status

session-coordinator-dsh@0.1.1-alpha.1 is an unsigned, source-bound GitHub Pre-release. Its npm package metadata remains private: true; no npm distribution or public support SLA is promised. The prior 0.1.0-rc.1 release evidence does not qualify this release on DSH alpha.1.

The immutable published tarball contains the packaging-time copy of this file, which still calls alpha.1 a candidate. For current release status and vulnerability-reporting guidance, use this repository document together with the GitHub Release page; the accepted archive bytes and hashes remain unchanged.

Report vulnerabilities through GitHub private vulnerability reporting for junwei529/session-coordinator-dsh. Do not file a public issue or include secrets, credentials, private Session data, or production artifacts in a report. If the private-reporting interface is unavailable, no alternate public contact or response SLA is designated.

Runtime compatibility qualification remains limited to JSON coordination storage and JSONL Session persistence. The 0.1.1-alpha.1 release has accepted source-bound build, packed-artifact, real Loader/Remote/JSON restart, Chromium, and downstream work-charter-dsh evidence on exact official DSH dsh-v0.1.2-alpha.1@cd5ef8148158c3a752a658978873241fdf8e2bbc; its corrected producer checkpoint received final review, independent acceptance, and a faithful local commit before GitHub publication. Public-registry installation, SQLite and other providers, multi-process/cross-host operation, and broader downstream integration remain unverified.

There aren't any published security advisories