dotfiles

Security

How dotfiles handles security and system modifications.

Core Principles

Hardening

Feature Env Var Action (macOS) Action (Linux)
Firewall DOTFILES_FIREWALL Enables socketfilterfw + Stealth Mode Configures UFW
Telemetry DOTFILES_TELEMETRY Disables Diagnostic plists Disables whoopsie/apport
DNS-over-HTTPS DOTFILES_DOH Browser-level settings Configures resolvectl
Idle Security DOTFILES_LOCK Sets screensaver idle time Sets GNOME/KDE idle-delay

Secrets

The dotfiles use age for encryption.

SSH Certificates

Short-lived SSH certificates reduce the blast radius of key compromise.

Reporting a Vulnerability

If you discover a security vulnerability, don’t open a public issue. Follow the instructions in the Security Policy.