| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability in Lsport, please report it responsibly:
- Do NOT open a public issue
- Email the maintainers directly or use GitHub's private vulnerability reporting
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Lsport uses the
ssh2crate for remote connections - Credentials are never stored - authentication uses SSH agent or key files
- Host key verification follows system SSH configuration
- Killing processes requires appropriate system permissions
- The tool does not elevate privileges automatically
- Users should run with
sudoonly when necessary
- Port scanning only reads system information
- No network packets are sent for local scanning
- Process information is read via the
sysinfocrate
- Only connect to trusted remote hosts
- Use SSH keys instead of passwords
- Run without
sudowhen possible - Keep the tool updated to receive security fixes