Security
Draft, not yet professionally reviewed. Shellaro is published by Dvir Horev under the DvirLabs brand.
Reporting a vulnerability
Please report suspected security vulnerabilities privately by email:
- Contact: [email protected]
Include the Shellaro version (Settings > Help & About > Copy diagnostics), what you did, and what happened. Do not include real passwords, keys or other people's data.
Please do not publish a suspected vulnerability, or share it in public issue trackers, forums or social media, before it has been reported privately and there has been a reasonable opportunity to investigate it and coordinate a fix and its disclosure.
There is no bug bounty program.
Supported versions
| Version | Security fixes |
|---|---|
| Latest stable release | Yes |
| Latest release candidate (Preview channel) | Yes, until the stable release |
| Older versions | No; update to the latest release |
How Shellaro protects you
- Credentials stay in Windows Credential Manager; they are not written to disk by Shellaro, logged, exported or put in support bundles.
- Host keys are verified (OpenSSH
known_hostsformat); a changed key is refused until you decide. - Updates are verified before they are installed: each installer must carry a signature made with Shellaro's update key (Ed25519, minisign format); the public key is built into the app. A missing or wrong signature, or a non-https download address, is refused and logged. Release installers are additionally Authenticode-signed once the code signing certificate is in place.
- Extensions run in isolated workers with the permissions you approved at install time; network access is limited to the hosts they declared. Command safety checks run on commands from extensions, runbooks and packs as well.
- Command safety warns before dangerous commands, more strictly on production sessions. It is a best-effort local check, not a security boundary.
- Labs never run on sessions marked production, and show their setup script before it runs.
- No telemetry; the local log is redacted.
Scope notes
Shellaro runs commands you (or extensions and runbooks you approved) send to servers you choose; it cannot make an unsafe command safe. The local Kubernetes cluster is for practice: it listens on this computer only and uses a key generated for it.