Skip to content

Security: chowjiaming/wsl-dev-bootstrap

Security

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the default branch (main). Tagged releases are cut from main; there is no long-term support branch.

Reporting a vulnerability

These scripts run with sudo, install packages from the network, and configure SSH keys. Treat them as privileged bootstrap code.

Please do not open a public GitHub issue for security-sensitive findings.

Instead, report privately via GitHub Security Advisories:

  1. Open https://github.com/chowjiaming/wsl-dev-bootstrap/security/advisories/new
  2. Include steps to reproduce, impact, and (if known) a suggested fix

If advisories are unavailable, email the maintainer address on the GitHub profile associated with this repository.

You should receive an acknowledgement within 7 days. Please give a reasonable window for a fix before any public disclosure.

Scope

In scope:

  • Privilege escalation or unexpected root behaviour in install.sh / system.sh / user.sh
  • Unsafe handling of SSH keys, agent sockets, or git signing material
  • Supply-chain issues in how third-party apt keys or installers are fetched
  • Logic that could overwrite user data without the documented backup behaviour

Out of scope:

  • Vulnerabilities in upstream tools this repo installs (report those upstream)
  • Issues that require an already-compromised machine or malicious sudoers config

There aren't any published security advisories