# Security Policy

## Reporting a vulnerability

Please do not publish credentials, device codes, tokens, account identifiers, or
vulnerability details in a public issue.

Use the repository's private **Report a vulnerability** form when available. If
private reporting has not been enabled yet, open a public issue containing only
a request for a private maintainer contact; do not include exploit details.

Include the affected version, DSH version, operating system, reproduction steps,
and expected impact. Replace every credential and account identifier with a
clearly fake value before attaching logs or fixtures.

## Scope

Reports about credential disclosure, OAuth state handling, unsafe verification
links, cross-account usage data, installer path validation, and package supply
chain behavior are especially welcome.

OpenAI account eligibility, service availability, and upstream Codex behavior
are outside this project's control, but integration defects involving them are
still useful to report.
