Skip to content

DDS Plugin SDK 0.3.2 — Developer Preview security update

Pre-release
Pre-release

Choose a tag to compare

@hkimw hkimw released this 03 Oct 12:04
· 22 commits to main since this release
b983dcd

This Developer Preview security update strengthens the public SDK's user workspace host, HTTP client, and publication checks.

  • Block hardlink aliases of protected or outside files across workspace reads, writes, rename, removal, and listings.
  • Align credential-file exclusions across workspace access, packaging, verification, and public-package checks; reject Windows device aliases and malformed Unicode paths.
  • Limit concurrent incoming bodies to 16, connections to 128, and requests per socket to 128. Preserve separate execution and cancellation limits.
  • Cancel unread error responses and stalled response streams on timeout or cancellation.

Upgrade both the workspace server and client. A new client cannot enforce the updated server policy on an older host. Copy intentionally shared hardlinks into ordinary files. If a plugin archive contains newly excluded files, remove those files and publish a new plugin version. Manifest contracts, workspace protocol 1, and the >=0.3.0 <0.4.0 plugin peer range remain unchanged.

Validation: 133 runtime tests, nine schemas, TypeScript declarations, the 90-file package inventory and independent installed consumers pass on Windows/Linux with Node 22/24. Six negative regressions reproduce on the released 0.3.1 package and pass after the fixes; oversized-header rejection was already present. No known dependency vulnerabilities were reported by npm audit at release validation.

This release is distributed through GitHub Releases, not the npm registry. Use the attached SHA256SUMS.txt to check the SDK tarball. Archive verification does not authenticate a publisher, scan malware, grant consent, or isolate in-process plugin code. See Security for upgrade guidance and remaining boundaries.