Verifiable updates
Release metadata binds version, package name and cryptographic digest to a pinned signing key.
A production-ready, CSF/LFD-compatible firewall distribution with 51 verified security fixes for cPanel, DirectAdmin, CyberPanel, CWP, InterWorx, VestaCP, Webmin and panel-free Linux.
DCSF preserves the familiar CSF and LFD workflow while closing exploit classes around root execution, untrusted parsers, remote updates, panel authorisation and firewall state.
Release metadata binds version, package name and cryptographic digest to a pinned signing key.
Shell-free execution and explicit validation reduce ambiguity where firewall administration crosses privilege boundaries.
Network, file and log inputs are processed with size, time and structure limits.
Changes are designed for staged validation, deterministic failure and recoverable firewall state.

Administrators retain the recognisable CSF/LFD interface and operational model. DCSF adds signed distribution, strict validation, bounded processing and transactional recovery underneath it.
DCSF targets the panel adapters already present in the CSF/LFD codebase, plus a generic Linux mode for direct administration.
Preserves the familiar WHM firewall workflow and provides a tested, backup-first migration path from the cpanel-csf RPM.
Uses the established DirectAdmin adapter with hardened argument validation, identity transitions and shell-free privileged execution.
Retains the CyberPanel integration while restricting privileged mutations to authenticated, CSRF-protected POST actions.
Supports the existing Control Web Panel administration path with the same signed package, parser limits and firewall-state safeguards.
Integrates with NodeWorx and enforces native FIREWALL authority, blocking secondary accounts that do not hold that permission.
Keeps the VestaCP CSF/LFD integration path while applying the common DCSF release, input-validation and recovery controls.
Supports CSF/LFD administration through Webmin with the same hardened backend and signed update channel.
Provides direct operation on supported RHEL- and Debian-family servers without requiring a hosting control panel.
The DataHouse Threat Feed is continuously refreshed through a controlled pipeline designed to reject malformed, stale and duplicate records.
Receive indicators from curated operational and research sources.
Confirm syntax, address scope, provenance and transport integrity.
Canonicalise records and eliminate duplicate or conflicting entries.
Expire indicators whose confidence or operational relevance has decayed.
The first signed DataHouse release is public. All 51 security remediations and all three operational controls passed the complete 54-gate release matrix.
The signed public package and installer are available.
Key information about the first production release.
Yes. DH20.01 is the latest and most hardened release in the DCSF line. It maps to signed technical package 15.10.4 and includes 51 verified security fixes plus three operational controls.
DCSF supports cPanel & WHM, DirectAdmin, CyberPanel, CWP, InterWorx, VestaCP and Webmin, plus a generic mode for supported RHEL- and Debian-family Linux servers.
The public register covers command and argument injection, ReDoS and resource exhaustion, file races, update-chain substitution, web-panel abuse, cluster spoofing and replay, process identity bypasses, DNS trust errors and firewall-state loss.
Yes. DH20.01 is public and maps to the signed DCSF 15.10.4 package. The bootstrap verifies every trust-bearing artifact before installation.