Security fixes target the latest release commit on main.
Please report vulnerabilities through GitHub's vulnerability reporting page for
omdsh-dev/toybox. Do not open an issue with exploit details, credentials, local paths,
or non-public data. If that reporting channel is unavailable, contact an organization maintainer
through an established security channel and include only the minimum reproduction needed.
When runtime loading becomes available, toybox plugins will run with the permissions of the DSH process. Review plugin source before enabling it, pin Git sources to a full 40-character commit, and never place secrets directly in a repository source string. The planned distribution path is pinned Git source after the official Repository Plugin dependency is published; toybox packages are not published to a public npm registry.