<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Singularity</title><link>https://singularity.sg/tags/security/</link><description>Recent content in Security on Singularity</description><generator>Hugo</generator><language>en-SG</language><copyright>(c) {year} Abhishek Dujari</copyright><lastBuildDate>Sat, 12 Sep 2026 16:50:24 +0800</lastBuildDate><atom:link href="https://singularity.sg/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>dsh-docker: DeepSeek Harness in a Locked-Down Container</title><link>https://singularity.sg/2026/09/dsh-docker-deepseek-harness-in-a-locked-down-container/</link><pubDate>Sat, 12 Sep 2026 16:50:24 +0800</pubDate><guid>https://singularity.sg/2026/09/dsh-docker-deepseek-harness-in-a-locked-down-container/</guid><description>&lt;p&gt;I built &lt;a href="https://github.com/abshkd/dsh-docker"&gt;dsh-docker&lt;/a&gt; to run the DeepSeek Harness Web UI in a small, locked-down Docker container. The Harness is useful, but it can also read and edit files, run commands, install plugins, and store model credentials. I wanted a repeatable setup where the agent starts with a much smaller view of the host.&lt;/p&gt;
&lt;p&gt;This builds on my earlier note about &lt;a href="https://singularity.sg/2026/08/deepseek-released-the-agent-harness-too/"&gt;why I want to try DeepSeek Harness&lt;/a&gt;. The difference here is packaging and containment rather than another agent plugin.&lt;/p&gt;</description></item></channel></rss>