Security
Draft: the reporting contact must be filled in before 1.0. Shellaro is published by Dvir Horev under the DvirLabs brand.
Reporting a vulnerability
Please report security problems privately, not in a public issue:
- Contact: to be set by the owner (a monitored address such as security@<domain>, or GitHub private vulnerability reporting once the repository is public).
Include the Shellaro version (Settings > Help & About > Copy diagnostics), what you did, and what happened. Do not include real passwords or keys.
Supported versions
| Version | Security fixes |
|---|---|
| Latest stable release | Yes |
| Latest release candidate (Preview channel) | Yes, until the stable release |
| Older versions | No; update to the latest release |
How Shellaro protects you
- Credentials stay in Windows Credential Manager; they are not written to disk by Shellaro, logged, exported or put in support bundles.
- Host keys are verified (OpenSSH
known_hostsformat); a changed key is refused until you decide. - Updates are verified before they are installed: each installer must carry a signature made with Shellaro's update key (Ed25519, minisign format); the public key is built into the app. A missing or wrong signature, or a non-https download address, is refused and logged. Release installers are additionally Authenticode-signed once the code signing certificate is in place.
- Extensions run in isolated workers with the permissions you approved at install time; network access is limited to the hosts they declared. Command safety checks run on commands from extensions, runbooks and packs as well.
- Command safety warns before dangerous commands, more strictly on production sessions. It is a best-effort local check, not a security boundary.
- Labs never run on sessions marked production, and show their setup script before it runs.
- No telemetry; the local log is redacted.
Scope notes
Shellaro runs commands you (or extensions and runbooks you approved) send to servers you choose; it cannot make an unsafe command safe. The local Kubernetes cluster is for practice: it listens on this computer only and uses a key generated for it.