Security fixes are applied to the latest released minor version while DSUI remains pre-1.0.
Do not open a public issue. Use GitHub private vulnerability reporting for northgraindata/dsui, including affected version, impact, reproduction steps, and any suggested mitigation. Northgrain Data will acknowledge a complete report within five business days and coordinate disclosure after a fix is available.
- Configure
DSUI_MASTER_KEYwhenever UI-managed credentials or enterprise authentication are enabled. - Put internet-facing deployments behind TLS and configure trusted proxy headers explicitly.
- Use authentication outside a private local environment.
- Run the container non-root with a read-only root filesystem and no Docker socket.
- Mount
dsui.yamlread-only and inject secrets through the environment or a secret manager. - Treat community adapters as trusted third-party server code. Integrity verifies identity, not safety.
- Adapters are built from their source on every start, which runs a package manager and a bundler over that source with lifecycle scripts disabled. The adapter build is not sandboxed.
- Verify an adapter's source, license, provenance, and network access before configuring it. Pin
refto a commit when you need a reproducible build.
Resolved credentials must never be included in bug reports, diagnostics, or logs.