Skip to content

Security: WindowsGSH/WindowsGSH.Windrose

Security

SECURITY.md

Security policy

Security and trust

The Windrose module executes C# with the current user's Windows permissions, launches the vendor server, and can invoke the separately installed WindrosePlus tooling. WindowsGSH cannot guarantee arbitrary third-party modules or addons. Review source, manifest, scripts, dependencies, and download origins before use.

Download modules safely

Use the official WindowsGSH repository or another source you trust. Obtain Windrose through Steam app 4129620. WindrosePlus is optional third-party code: review its repository and release contents independently before installing or enabling it.

Protect credentials and server data

Server passwords, invite codes, WindrosePlus RCON credentials, private addresses, world identifiers, saves, logs, and backups may be sensitive. Restrict file access, replace the default addon password, and redact configs, commands, screenshots, logs, and support bundles. Rotate exposed credentials or invite codes.

Report a vulnerability

Use the private repository advisory page. Report WindrosePlus vulnerabilities to its maintainer as well when the defect belongs to that addon. Do not publish exploits, credentials, private worlds, or unredacted diagnostics.

Include in a report

Include module/WindowsGSH versions, whether WindrosePlus is installed, package provenance, affected workflow, reproduction steps, impact, and the smallest sanitized diagnostic sample required.

Supported versions

Security fixes target the latest Windrose module release and current WindowsGSH module API unless stated otherwise. Third-party addon support follows that addon's own policy.

There aren't any published security advisories