From 149cee6bcdb6943db3a55c35f95460316d2dd771 Mon Sep 17 00:00:00 2001 From: Codeman maintainer Date: Mon, 27 Jul 2026 14:00:26 +0200 Subject: [PATCH] docs: move SECURITY.md to .github/ and SPEEDRUN.md to docs/ MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Trims the repo root listing so the README is reached with less scrolling. Only these two were movable; the other five root .md files are load-bearing and stay put: - README.md / README.zh-CN.md — the landing page and the language-switcher entry point - CLAUDE.md — Claude Code loads project instructions from the ROOT path; moving it silently breaks every future session in this repo - AGENTS.md — the agent-convention file Codex reads from the root and injects as context (see the comments in session-routes.ts) - CHANGELOG.md — the changesets default writer emits it next to package.json, so moving it breaks `npm run version-packages` GitHub officially resolves .github/SECURITY.md, so the Security policy tab keeps working. Inbound links updated in both READMEs, CLAUDE.md and docs/versioning-policy.md. CHANGELOG.md also names SECURITY.md but is left alone: it is a historical record, not a live reference. The move broke a link the other direction too: SECURITY.md pointed at docs/security-architecture.md, which from .github/ resolved to .github/docs/... — repointed to ../docs/. All relative links in the six touched files verified resolving (62 links, 0 broken). Co-Authored-By: Claude Opus 5 (1M context) --- SECURITY.md => .github/SECURITY.md | 4 ++-- CLAUDE.md | 2 +- README.md | 2 +- README.zh-CN.md | 2 +- SPEEDRUN.md => docs/SPEEDRUN.md | 0 docs/versioning-policy.md | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) rename SECURITY.md => .github/SECURITY.md (97%) rename SPEEDRUN.md => docs/SPEEDRUN.md (100%) diff --git a/SECURITY.md b/.github/SECURITY.md similarity index 97% rename from SECURITY.md rename to .github/SECURITY.md index 07746163..6e378f6f 100644 --- a/SECURITY.md +++ b/.github/SECURITY.md @@ -4,7 +4,7 @@ Codeman launches AI coding sessions with `--dangerously-skip-permissions`, so th web UI is **by design a remote-code-execution surface for whoever can reach it**. The entire security model exists to control *who* that is. Please read this before exposing an instance beyond `localhost`. The full model lives in -[`docs/security-architecture.md`](docs/security-architecture.md). +[`docs/security-architecture.md`](../docs/security-architecture.md). ## Supported versions @@ -75,4 +75,4 @@ subscribe and send time), and tmux session names discovered on the shared socket are validated against the safe-name pattern before reaching any shell call site. For the detailed rationale, defenses, and recommended secure setups, see -[`docs/security-architecture.md`](docs/security-architecture.md). +[`docs/security-architecture.md`](../docs/security-architecture.md). diff --git a/CLAUDE.md b/CLAUDE.md index 55784247..c687d520 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -38,7 +38,7 @@ The production server caches static files for 1 year, `immutable` (`maxAge: '1y' ## COM Shorthand (Deployment) -Uses [Semantic Versioning](https://semver.org/) (`MAJOR.MINOR.PATCH`) via `@changesets/cli`. What SemVer actually covers (the CLI + documented env vars are public; the HTTP/SSE API, on-disk state, and experimental features are internal/unstable) is defined in `docs/versioning-policy.md`. Security reporting + known limitations live in `SECURITY.md`. +Uses [Semantic Versioning](https://semver.org/) (`MAJOR.MINOR.PATCH`) via `@changesets/cli`. What SemVer actually covers (the CLI + documented env vars are public; the HTTP/SSE API, on-disk state, and experimental features are internal/unstable) is defined in `docs/versioning-policy.md`. Security reporting + known limitations live in `.github/SECURITY.md`. When user says "COM": diff --git a/README.md b/README.md index c917089a..1f45bee7 100644 --- a/README.md +++ b/README.md @@ -604,7 +604,7 @@ When someone authenticates via QR, the desktop shows a notification toast with t ## Security -By default Codeman launches sessions with `--dangerously-skip-permissions`, so the web UI is by design a remote-code-execution surface for whoever can reach it — the whole security model exists to control _who_ that is. (The startup permission mode is configurable; see below.) Recent hardening (v0.9.0 + v0.9.5) closes the browser-driven attack paths that bite self-hosted dev tools. Full model: [`docs/security-architecture.md`](docs/security-architecture.md). **Found a vulnerability?** See [`SECURITY.md`](SECURITY.md) for private disclosure and the list of known limitations. +By default Codeman launches sessions with `--dangerously-skip-permissions`, so the web UI is by design a remote-code-execution surface for whoever can reach it — the whole security model exists to control _who_ that is. (The startup permission mode is configurable; see below.) Recent hardening (v0.9.0 + v0.9.5) closes the browser-driven attack paths that bite self-hosted dev tools. Full model: [`docs/security-architecture.md`](docs/security-architecture.md). **Found a vulnerability?** See [`SECURITY.md`](.github/SECURITY.md) for private disclosure and the list of known limitations. ### Network & access diff --git a/README.zh-CN.md b/README.zh-CN.md index de56c278..95b7e8ac 100644 --- a/README.zh-CN.md +++ b/README.zh-CN.md @@ -594,7 +594,7 @@ URL 被刻意保持精简(`/q/` 路径 + 6 字符码 ≈ 53–56 个字符) ## 安全 -Codeman 默认用 `--dangerously-skip-permissions` 启动会话,因此 Web UI 在设计上对任何能访问到它的人都是一个远程代码执行面 —— 整套安全模型的存在就是为了控制*谁*能访问。(启动权限模式可配置,见下文。)近期加固(v0.9.0 + v0.9.5)封堵了那些常困扰自托管开发工具的浏览器驱动攻击路径。完整模型:[`docs/security-architecture.md`](docs/security-architecture.md)。**发现了漏洞?** 私下披露方式与已知限制清单见 [`SECURITY.md`](SECURITY.md)。 +Codeman 默认用 `--dangerously-skip-permissions` 启动会话,因此 Web UI 在设计上对任何能访问到它的人都是一个远程代码执行面 —— 整套安全模型的存在就是为了控制*谁*能访问。(启动权限模式可配置,见下文。)近期加固(v0.9.0 + v0.9.5)封堵了那些常困扰自托管开发工具的浏览器驱动攻击路径。完整模型:[`docs/security-architecture.md`](docs/security-architecture.md)。**发现了漏洞?** 私下披露方式与已知限制清单见 [`SECURITY.md`](.github/SECURITY.md)。 ### 网络与访问 diff --git a/SPEEDRUN.md b/docs/SPEEDRUN.md similarity index 100% rename from SPEEDRUN.md rename to docs/SPEEDRUN.md diff --git a/docs/versioning-policy.md b/docs/versioning-policy.md index 01a72d49..44845689 100644 --- a/docs/versioning-policy.md +++ b/docs/versioning-policy.md @@ -75,5 +75,5 @@ allowance. The commitments above take effect at `1.0.0`. ## See also - `CLAUDE.md` — the COM release workflow (changesets, version bump, deploy) -- `SECURITY.md` — security reporting and the supported-version policy +- `.github/SECURITY.md` — security reporting and the supported-version policy - `docs/security-architecture.md` — the full trust model