Shellaro Download

Security

Draft, not yet professionally reviewed. Shellaro is published by Dvir Horev under the DvirLabs brand.

Reporting a vulnerability

Please report suspected security vulnerabilities privately by email:

Include the Shellaro version (Settings > Help & About > Copy diagnostics), what you did, and what happened. Do not include real passwords, keys or other people's data.

Please do not publish a suspected vulnerability, or share it in public issue trackers, forums or social media, before it has been reported privately and there has been a reasonable opportunity to investigate it and coordinate a fix and its disclosure.

There is no bug bounty program.

Supported versions

VersionSecurity fixes
Latest stable releaseYes
Latest release candidate (Preview channel)Yes, until the stable release
Older versionsNo; update to the latest release

How Shellaro protects you

Scope notes

Shellaro runs commands you (or extensions and runbooks you approved) send to servers you choose; it cannot make an unsafe command safe. The local Kubernetes cluster is for practice: it listens on this computer only and uses a key generated for it.