Skip to content

Security: WindowsGSH/WindowsGSH.ProjectZomboid

Security

SECURITY.md

Security policy

Security and trust

WindowsGSH modules execute with the user's Windows permissions. WindowsGSH cannot guarantee arbitrary third-party modules, so run only code you trust.

Download modules safely

Use the official WindowsGSH.ProjectZomboid repository or another independently verified source. Review the manifest and C# source before importing it.

Protect credentials and server data

Join/admin passwords, databases, player data, saves, logs, and backups may be sensitive. Restrict directory access and never post secrets or private server data.

Report a vulnerability

Do not disclose an unpatched vulnerability publicly. Use GitHub private vulnerability reporting where available or contact the maintainers privately.

Include in a report

Include affected versions, reproduction steps, impact, and sanitized diagnostics. Remove credentials, addresses, personal paths, and server data.

Supported versions

Only the current module release receives security fixes unless stated otherwise.

There aren't any published security advisories