Security fixes are applied to the default branch (main). Tagged releases are
cut from main; there is no long-term support branch.
These scripts run with sudo, install packages from the network, and configure
SSH keys. Treat them as privileged bootstrap code.
Please do not open a public GitHub issue for security-sensitive findings.
Instead, report privately via GitHub Security Advisories:
- Open https://github.com/chowjiaming/wsl-dev-bootstrap/security/advisories/new
- Include steps to reproduce, impact, and (if known) a suggested fix
If advisories are unavailable, email the maintainer address on the GitHub profile associated with this repository.
You should receive an acknowledgement within 7 days. Please give a reasonable window for a fix before any public disclosure.
In scope:
- Privilege escalation or unexpected root behaviour in
install.sh/system.sh/user.sh - Unsafe handling of SSH keys, agent sockets, or git signing material
- Supply-chain issues in how third-party apt keys or installers are fetched
- Logic that could overwrite user data without the documented backup behaviour
Out of scope:
- Vulnerabilities in upstream tools this repo installs (report those upstream)
- Issues that require an already-compromised machine or malicious
sudoersconfig