Skip to content

Security: dipeshwalia/dev-clean

Security

SECURITY.md

Security

DevClean moves developer caches and build artifacts to Trash. It is fail-closed: if a check is unknown, it keeps the file.

Do not run it as root. Auto Clean never prompts for sudo and skips privileged work.

Report vulnerabilities privately. Do not open a public issue with a working exploit against path validation, symlink races, or trash handling.

Expected reports:

  • A path that Auto Clean or One-Click would move despite being source, credentials, or a Git worktree
  • A symlink or inode swap that bypasses revalidation
  • Trash placement outside ~/.Trash

Include OS version, DevClean version, and the candidate path. Do not include secrets.

There aren't any published security advisories