Skip to content

Security: WindowsGSH/WindowsGSH.7DaysToDie

Security

SECURITY.md

Security policy

Security and trust

The 7 Days to Die module executes C# and starts the 7 Days to Die dedicated server with the current user's Windows permissions. WindowsGSH cannot guarantee arbitrary third-party or modified modules. Review source, manifests, dependencies, and download origins before use.

Download modules safely

Obtain the module from the official repository or another trusted source and install server files/mods through legitimate Steam/vendor sources. Review mods and web tools independently.

Protect credentials and server data

Protect Telnet/web credentials, server XML, player data, save worlds, logs, mods, and backups. Keep Telnet/web administration private, use strong credentials, and redact diagnostics.

Report a vulnerability

Use the private repository advisory page. Do not publish exploits, credentials, private server data, or unredacted diagnostics.

Include in a report

Include module/WindowsGSH/server versions, mod provenance, reproduction steps, impact, and sanitized diagnostics.

Supported versions

Security fixes target the latest module release and current WindowsGSH module API unless stated otherwise.

There aren't any published security advisories