dsh-vet is a security tool; it must hold itself to the standard it applies to others.
Use GitHub's private vulnerability reporting for this repository. Please do not open a public issue for vulnerabilities in dsh-vet itself. Reports are acknowledged within 7 days.
- dsh-vet source code, its CLI, and future GitHub Action
- The
dsh-vet/v1contract (ambiguities that lead consumers to mis-render severity or grade)
Out of scope: findings dsh-vet reports about other plugins. Those belong in the false-positive dispute template, not in vulnerability disclosure.
- dsh-vet runs locally. It reads the npm registry for dependency metadata and nothing else over the network.
- It never transmits audited code, audit results, or telemetry anywhere.
- Secrets found in evidence are redacted, never included in reports.
See the false-positive issue template. Disputes are handled in public: if a rule is wrong, the rule changes and the changelog says so.