mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
docs: move SECURITY.md to .github/ and SPEEDRUN.md to docs/
Trims the repo root listing so the README is reached with less scrolling. Only these two were movable; the other five root .md files are load-bearing and stay put: - README.md / README.zh-CN.md — the landing page and the language-switcher entry point - CLAUDE.md — Claude Code loads project instructions from the ROOT path; moving it silently breaks every future session in this repo - AGENTS.md — the agent-convention file Codex reads from the root and injects as context (see the comments in session-routes.ts) - CHANGELOG.md — the changesets default writer emits it next to package.json, so moving it breaks `npm run version-packages` GitHub officially resolves .github/SECURITY.md, so the Security policy tab keeps working. Inbound links updated in both READMEs, CLAUDE.md and docs/versioning-policy.md. CHANGELOG.md also names SECURITY.md but is left alone: it is a historical record, not a live reference. The move broke a link the other direction too: SECURITY.md pointed at docs/security-architecture.md, which from .github/ resolved to .github/docs/... — repointed to ../docs/. All relative links in the six touched files verified resolving (62 links, 0 broken). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -4,7 +4,7 @@ Codeman launches AI coding sessions with `--dangerously-skip-permissions`, so th
|
|||||||
web UI is **by design a remote-code-execution surface for whoever can reach it**.
|
web UI is **by design a remote-code-execution surface for whoever can reach it**.
|
||||||
The entire security model exists to control *who* that is. Please read this before
|
The entire security model exists to control *who* that is. Please read this before
|
||||||
exposing an instance beyond `localhost`. The full model lives in
|
exposing an instance beyond `localhost`. The full model lives in
|
||||||
[`docs/security-architecture.md`](docs/security-architecture.md).
|
[`docs/security-architecture.md`](../docs/security-architecture.md).
|
||||||
|
|
||||||
## Supported versions
|
## Supported versions
|
||||||
|
|
||||||
@@ -75,4 +75,4 @@ subscribe and send time), and tmux session names discovered on the shared socket
|
|||||||
are validated against the safe-name pattern before reaching any shell call site.
|
are validated against the safe-name pattern before reaching any shell call site.
|
||||||
|
|
||||||
For the detailed rationale, defenses, and recommended secure setups, see
|
For the detailed rationale, defenses, and recommended secure setups, see
|
||||||
[`docs/security-architecture.md`](docs/security-architecture.md).
|
[`docs/security-architecture.md`](../docs/security-architecture.md).
|
||||||
@@ -38,7 +38,7 @@ The production server caches static files for 1 year, `immutable` (`maxAge: '1y'
|
|||||||
|
|
||||||
## COM Shorthand (Deployment)
|
## COM Shorthand (Deployment)
|
||||||
|
|
||||||
Uses [Semantic Versioning](https://semver.org/) (`MAJOR.MINOR.PATCH`) via `@changesets/cli`. What SemVer actually covers (the CLI + documented env vars are public; the HTTP/SSE API, on-disk state, and experimental features are internal/unstable) is defined in `docs/versioning-policy.md`. Security reporting + known limitations live in `SECURITY.md`.
|
Uses [Semantic Versioning](https://semver.org/) (`MAJOR.MINOR.PATCH`) via `@changesets/cli`. What SemVer actually covers (the CLI + documented env vars are public; the HTTP/SSE API, on-disk state, and experimental features are internal/unstable) is defined in `docs/versioning-policy.md`. Security reporting + known limitations live in `.github/SECURITY.md`.
|
||||||
|
|
||||||
When user says "COM":
|
When user says "COM":
|
||||||
|
|
||||||
|
|||||||
@@ -604,7 +604,7 @@ When someone authenticates via QR, the desktop shows a notification toast with t
|
|||||||
|
|
||||||
## Security
|
## Security
|
||||||
|
|
||||||
By default Codeman launches sessions with `--dangerously-skip-permissions`, so the web UI is by design a remote-code-execution surface for whoever can reach it — the whole security model exists to control _who_ that is. (The startup permission mode is configurable; see below.) Recent hardening (v0.9.0 + v0.9.5) closes the browser-driven attack paths that bite self-hosted dev tools. Full model: [`docs/security-architecture.md`](docs/security-architecture.md). **Found a vulnerability?** See [`SECURITY.md`](SECURITY.md) for private disclosure and the list of known limitations.
|
By default Codeman launches sessions with `--dangerously-skip-permissions`, so the web UI is by design a remote-code-execution surface for whoever can reach it — the whole security model exists to control _who_ that is. (The startup permission mode is configurable; see below.) Recent hardening (v0.9.0 + v0.9.5) closes the browser-driven attack paths that bite self-hosted dev tools. Full model: [`docs/security-architecture.md`](docs/security-architecture.md). **Found a vulnerability?** See [`SECURITY.md`](.github/SECURITY.md) for private disclosure and the list of known limitations.
|
||||||
|
|
||||||
### Network & access
|
### Network & access
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -594,7 +594,7 @@ URL 被刻意保持精简(`/q/` 路径 + 6 字符码 ≈ 53–56 个字符)
|
|||||||
|
|
||||||
## 安全
|
## 安全
|
||||||
|
|
||||||
Codeman 默认用 `--dangerously-skip-permissions` 启动会话,因此 Web UI 在设计上对任何能访问到它的人都是一个远程代码执行面 —— 整套安全模型的存在就是为了控制*谁*能访问。(启动权限模式可配置,见下文。)近期加固(v0.9.0 + v0.9.5)封堵了那些常困扰自托管开发工具的浏览器驱动攻击路径。完整模型:[`docs/security-architecture.md`](docs/security-architecture.md)。**发现了漏洞?** 私下披露方式与已知限制清单见 [`SECURITY.md`](SECURITY.md)。
|
Codeman 默认用 `--dangerously-skip-permissions` 启动会话,因此 Web UI 在设计上对任何能访问到它的人都是一个远程代码执行面 —— 整套安全模型的存在就是为了控制*谁*能访问。(启动权限模式可配置,见下文。)近期加固(v0.9.0 + v0.9.5)封堵了那些常困扰自托管开发工具的浏览器驱动攻击路径。完整模型:[`docs/security-architecture.md`](docs/security-architecture.md)。**发现了漏洞?** 私下披露方式与已知限制清单见 [`SECURITY.md`](.github/SECURITY.md)。
|
||||||
|
|
||||||
### 网络与访问
|
### 网络与访问
|
||||||
|
|
||||||
|
|||||||
@@ -75,5 +75,5 @@ allowance. The commitments above take effect at `1.0.0`.
|
|||||||
## See also
|
## See also
|
||||||
|
|
||||||
- `CLAUDE.md` — the COM release workflow (changesets, version bump, deploy)
|
- `CLAUDE.md` — the COM release workflow (changesets, version bump, deploy)
|
||||||
- `SECURITY.md` — security reporting and the supported-version policy
|
- `.github/SECURITY.md` — security reporting and the supported-version policy
|
||||||
- `docs/security-architecture.md` — the full trust model
|
- `docs/security-architecture.md` — the full trust model
|
||||||
|
|||||||
Reference in New Issue
Block a user