Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: dmwarenet/dscode

Security

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.xPre-release (active development)

DSCode is currently in pre-release development (0.x). Only the latest development version is supported.

Reporting a Vulnerability

If you discover a security vulnerability in DSCode, please report it responsibly:

Please do not file public issues for security vulnerabilities. Reports sent via email or GitHub Security Advisories will be acknowledged within 48 hours, and we aim to provide a substantive response within 7 days.

Disclosure SLAs

SeverityAcknowledgmentInitial ResponseFix Timeline
Critical24 hours3 days7 days
High48 hours7 days14 days
Medium48 hours7 days30 days
Low7 days14 daysNext release

Security Model

DSCode employs a multi-layered security architecture:

Tauri Application Sandbox

The main application runs in a Tauri 2.1 window with restricted capabilities. Tauri's permission system controls which commands the frontend can invoke, limiting the attack surface exposed to web content.

PathValidator

All filesystem IPC operations pass through PathValidator, which:

  • Validates paths against the workspace allowlist
  • Prevents directory traversal attacks (e.g., ../ sequences)
  • Blocks access outside the configured workspace roots

Extension Permissions

Extensions run in a separate Node.js process with a deny-by-default permission model:

  • Extensions start with zero permissions
  • Each permission must be explicitly requested and granted
  • Platform-specific sandboxing isolates extension processes:
    • macOS: sandbox-exec (seatbelt profiles)
    • Linux: bubblewrap (bwrap) namespaces
    • Windows: Job Objects API — memory limits, UI restrictions, kill-on-job-close

VSIX Extraction Safety

VSIX (extension package) extraction includes:

  • Zip Slip prevention — all extracted paths are validated against the target directory
  • Symlink validation to prevent path escape
  • VSIX manifest verificationextension.vsixmanifest is parsed and cross-validated against package.json:
    • Identity verification (extension ID, version, publisher)
    • SHA256 hash computation for integrity verification
    • Can be bypassed with DSCODE_SKIP_VSX_VERIFY env var for development

Secret Storage

Extension secrets use the OS-native keyring via the keyring crate, never stored in plaintext configuration files.

Node.js Binary Verification

The bundled Node.js binary is verified on startup:

  • SHA256 hashes are bundled in allowed-hashes.json
  • Resolved binary hash is verified before execution
  • Application refuses to start on hash mismatch

IPC Cleanup

  • Stale socket cleanup: Orphaned Unix domain socket files from previous sessions are removed on startup
  • Pending request timeout: Stale pending IPC requests (>5 minutes) are cleaned up periodically to prevent memory leaks
  • Session guard: IPC requests are rejected when the session is not in Ready or Initializing state

Extension Sandbox Model for Authors

Extension authors should understand the deny-by-default security model:

  1. No permissions by default — Your extension cannot read files, make network requests, access the clipboard, or use the terminal unless explicitly declared in package.json under dscode.permissions.

  2. Path validation — All filesystem paths are canonicalized and checked against the workspace allowlist. Attempts to access files outside the workspace, extension directory, or system temp folders are rejected.

  3. Rate limiting — Extensions are limited to 100 IPC requests/second by default. Batch operations instead of sending many individual requests.

  4. Sandbox per platform:

    • macOS: sandbox-exec (seatbelt) restricts filesystem and network access.
    • Linux: bubblewrap (bwrap) creates namespace isolation for mount, PID, and network.
    • Windows: Job Objects enforce memory limits and UI restrictions.
  5. Secrets only via keyring — Do not store credentials in globalState or settings. Use the provided SecretStorage API backed by the OS keychain.

  6. Crash recovery — If your extension crashes the host process, it will be restarted up to 3 times with exponential backoff. Persistent crashes will mark the extension as disabled.

Audit Schedule

ComponentFrequencyScope
Dependency audit (cargo audit)Every CI runAll Rust dependencies
VSIX verificationEvery extension installPackage integrity
Path validationEvery filesystem IPCPath traversal prevention
Permission checkEvery extension API callPermission enforcement

Known Limitations

  • Extension sandbox effectiveness varies by platform: The macOS sandbox-exec provides strong isolation, while the Linux bubblewrap sandbox depends on system configuration. The Windows Job Objects sandbox provides process-level limits but is less comprehensive than Unix sandboxes.
  • Extension host process isolation: Extensions share a single Node.js process. A malicious or buggy extension can affect other extensions within the same host (though it cannot escape to the main application).
  • Terminal PTY processes: Spawned terminal processes run outside the sandbox by necessity, as they require full system access.
  • Pre-release software: As 0.x software, security hardening is ongoing and the security model is not yet complete.

Disclosure Policy

When a vulnerability is reported, we will:

  1. Confirm the vulnerability and determine its scope and severity
  2. Acknowledge receipt within the SLA timeline above
  3. Develop a fix in a private branch
  4. Prepare a release with the fix
  5. Request a CVE if appropriate
  6. Publish a security advisory on GitHub with proper attribution
  7. Release the fix simultaneously with the advisory

There aren't any published security advisories