Skip to content

Security: WindowsGSH/WindowsGSH.Wreckfest2

Security

SECURITY.md

Security policy

Security and trust

The Wreckfest 2 module executes C# with the current user's Windows permissions and starts the vendor server executable. WindowsGSH cannot guarantee arbitrary third-party modules. Review this repository, its manifest, and download origins before use.

Download modules safely

Use the official WindowsGSH.Wreckfest2 repository or an independently verified source, and review its manifest and executable code before installing.

Protect credentials and server data

This module does not currently write a server password or admin secret into server-data/server_config.scnf. If you add credentials to that file manually, restrict access to the server-data directory and never post it, along with logs or backups, in issues or support requests.

Report a vulnerability

Use the private repository advisory page or contact maintainers privately. Do not publicly disclose an unpatched issue or credential.

Include in a report

Include the module and WindowsGSH versions, affected workflow, reproduction steps, impact, and the smallest redacted diagnostic sample needed to reproduce the issue.

Supported versions

Security fixes target the latest module release and current WindowsGSH module API unless stated otherwise.

There aren't any published security advisories