Overview
dsh-safe-workflow
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
This is a workflow guard, not a process sandbox. A plugin runs in the host process and has the host's permissions. The first version provides policy, evidence, and best-effort file snapshots; it does not promise atomic rollback of arbitrary shell side effects, network operations, databases, or files that were not included in a checkpoint. For production use, review the source, pin the plugin version or commit, keep `.dsh-safe-workflow` out of sensitive repositories if needed, and run it with DSH's normal sandbox and approval layers enabled.
