v2.0.13 - Production-Ready Security Hardening
Production-Ready Security Release
This release completes comprehensive security hardening through iterative code review, eliminating all identified vulnerabilities and achieving production-ready status.
Security Achievements
- PASS verdict from security reviewers
- Zero PATH poisoning vulnerabilities - all external commands use absolute paths
- Secure execution order - session setup completes before credentials enter environment
- Bash 3.2+ compatibility - works on macOS default shell
- 100% functionality preserved - all features working as designed
Security Fixes in v2.0 Series
| Version | Issue Fixed |
|---|---|
| v2.0.7 | Restore terminal colors in SSH sessions |
| v2.0.8-9 | Fix command substitution timing after secret operations |
| v2.0.10 | Bash 3.2 compatibility + load_mcp_config positioning |
| v2.0.11 | Move all session setup before credentials |
| v2.0.12 | Use absolute paths for env/rm commands |
| v2.0.13 | Fix last naked security command |
What's Included
- Secure credential management (macOS Keychain, Linux Secret Service, Windows ENV)
- Session isolation (separate ~/.claude-glm config)
- MCP (Model Context Protocol) support
- Multi-platform compatibility (macOS, Linux, Windows)
- Comprehensive documentation and troubleshooting guides
Installation
curl -fsSL https://raw.githubusercontent.com/wgsim/claude-glm-wrapper/main/scripts/install.sh | bashSee INSTALL.md for detailed instructions.
Security
This project implements comprehensive security practices:
- All external commands use absolute paths
- Credentials never exposed to user-modifiable PATH
- Comprehensive .gitignore with 140+ security patterns
- Automated secret scanning with pre-commit hooks
For security concerns, see SECURITY.md.
Full Changelog: v1.7.1...v2.0.13