Skip to content

v2.0.13 - Production-Ready Security Hardening

Choose a tag to compare

@wgsim wgsim released this 14 Feb 10:10
· 14 commits to main since this release

Production-Ready Security Release

This release completes comprehensive security hardening through iterative code review, eliminating all identified vulnerabilities and achieving production-ready status.

Security Achievements

  • PASS verdict from security reviewers
  • Zero PATH poisoning vulnerabilities - all external commands use absolute paths
  • Secure execution order - session setup completes before credentials enter environment
  • Bash 3.2+ compatibility - works on macOS default shell
  • 100% functionality preserved - all features working as designed

Security Fixes in v2.0 Series

Version Issue Fixed
v2.0.7 Restore terminal colors in SSH sessions
v2.0.8-9 Fix command substitution timing after secret operations
v2.0.10 Bash 3.2 compatibility + load_mcp_config positioning
v2.0.11 Move all session setup before credentials
v2.0.12 Use absolute paths for env/rm commands
v2.0.13 Fix last naked security command

What's Included

  • Secure credential management (macOS Keychain, Linux Secret Service, Windows ENV)
  • Session isolation (separate ~/.claude-glm config)
  • MCP (Model Context Protocol) support
  • Multi-platform compatibility (macOS, Linux, Windows)
  • Comprehensive documentation and troubleshooting guides

Installation

curl -fsSL https://raw.githubusercontent.com/wgsim/claude-glm-wrapper/main/scripts/install.sh | bash

See INSTALL.md for detailed instructions.

Security

This project implements comprehensive security practices:

  • All external commands use absolute paths
  • Credentials never exposed to user-modifiable PATH
  • Comprehensive .gitignore with 140+ security patterns
  • Automated secret scanning with pre-commit hooks

For security concerns, see SECURITY.md.


Full Changelog: v1.7.1...v2.0.13