请不要在公开 Issue 中披露安全漏洞。
请打开 GitHub 仓库的 Security 页面,选择 Report a vulnerability,向维护者发送私密报告。报告中请注明受影响版本、复现步骤、影响范围以及建议的缓解方案。
dsh-plain-plugin-menu 可以调用本地 DSH CLI 安装或卸载第三方插件。GitHub 活跃度、Star、License 和仓库元数据只能帮助用户判断,不代表安全审计结果,也不能保证插件安全。
Please do not disclose security vulnerabilities in public issues.
Open the repository's Security tab and choose Report a vulnerability to send a private report to the maintainer. Include the affected version, reproduction steps, impact, and any suggested mitigation.
dsh-plain-plugin-menu can ask the local DSH CLI to install or remove third-party plugins. GitHub activity, stars, licenses, and repository metadata are informational signals only; they are not a security audit or a guarantee that a plugin is safe.