Skip to content

Latest commit

ย 

History

History
88 lines (55 loc) ยท 3.18 KB

File metadata and controls

88 lines (55 loc) ยท 3.18 KB

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in claude-code-hooks, please do not open a public issue.

Instead, report it privately:

We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.

Supported Versions

Package Version Supported
@claude-code-hooks/sound 0.2.x Yes
@claude-code-hooks/security 0.1.x Yes
@claude-code-hooks/secrets 0.1.x Yes
@claude-code-hooks/core 0.1.x Yes

Only the latest minor version of each package receives security patches.

Scope

This policy covers:

  • All packages in the packages/ directory
  • The monorepo build/publish tooling

Out of scope:

  • Third-party dependencies (report upstream)
  • User-generated TTS/sound content

Security Design

These packages run as Claude Code hooks โ€” they execute in your local environment. The security and secrets packages specifically exist to add safety layers. Their design principles:

  • No network calls (except TTS generation in @claude-code-hooks/sound, which is opt-in)
  • No data exfiltration โ€” all scanning is local, nothing leaves your machine
  • Minimal dependencies โ€” smaller attack surface
  • Fail-open by default โ€” in warn mode, hooks never block your workflow

Disclosure Policy


๋ณด์•ˆ ์ •์ฑ… (ํ•œ๊ตญ์–ด)

์ทจ์•ฝ์  ๋ณด๊ณ 

claude-code-hooks์—์„œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ๋ฐœ๊ฒฌํ•˜๋ฉด ๊ณต๊ฐœ ์ด์Šˆ๋ฅผ ์—ด์ง€ ๋งˆ์„ธ์š”.

๋Œ€์‹ , ๋น„๊ณต๊ฐœ๋กœ ๋ณด๊ณ ํ•ด ์ฃผ์„ธ์š”:

  • GitHub ๋ณด์•ˆ ๊ถŒ๊ณ ๋ฅผ ํ†ตํ•ด ๋ณด๊ณ 
  • ๋˜๋Š” ๋ฉ”์ธํ…Œ์ด๋„ˆ์—๊ฒŒ ์ง์ ‘ ์ด๋ฉ”์ผ (GitHub ํ”„๋กœํ•„ ์ฐธ์กฐ)

48์‹œ๊ฐ„ ์ด๋‚ด์— ์ˆ˜์‹  ํ™•์ธ์„ ๋“œ๋ฆฌ๊ณ , ์‹ฌ๊ฐํ•œ ๋ฌธ์ œ์˜ ๊ฒฝ์šฐ 7์ผ ์ด๋‚ด์— ์ˆ˜์ • ๋˜๋Š” ์™„ํ™” ๋ฐฉ์•ˆ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

์ง€์› ๋ฒ„์ „

๊ฐ ํŒจํ‚ค์ง€์˜ ์ตœ์‹  ๋งˆ์ด๋„ˆ ๋ฒ„์ „๋งŒ ๋ณด์•ˆ ํŒจ์น˜๋ฅผ ๋ฐ›์Šต๋‹ˆ๋‹ค.

๋ฒ”์œ„

์ด ์ •์ฑ…์ด ์ ์šฉ๋˜๋Š” ๋ฒ”์œ„:

  • packages/ ๋””๋ ‰ํ† ๋ฆฌ์˜ ๋ชจ๋“  ํŒจํ‚ค์ง€
  • ๋ชจ๋…ธ๋ ˆํฌ ๋นŒ๋“œ/๋ฐฐํฌ ๋„๊ตฌ

๋ฒ”์œ„ ์™ธ:

  • ์„œ๋“œํŒŒํ‹ฐ ์˜์กด์„ฑ (์—…์ŠคํŠธ๋ฆผ์— ๋ณด๊ณ )
  • ์‚ฌ์šฉ์ž ์ƒ์„ฑ TTS/์‚ฌ์šด๋“œ ์ฝ˜ํ…์ธ 

๋ณด์•ˆ ์„ค๊ณ„

์ด ํŒจํ‚ค์ง€๋“ค์€ Claude Code ํ›…์œผ๋กœ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค โ€” ๋กœ์ปฌ ํ™˜๊ฒฝ์—์„œ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค. security์™€ secrets ํŒจํ‚ค์ง€๋Š” ์•ˆ์ „ ๊ณ„์ธต์„ ์ถ”๊ฐ€ํ•˜๊ธฐ ์œ„ํ•ด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค. ์„ค๊ณ„ ์›์น™:

  • ๋„คํŠธ์›Œํฌ ํ˜ธ์ถœ ์—†์Œ (@claude-code-hooks/sound์˜ TTS ์ƒ์„ฑ ์ œ์™ธ, ์ด๋Š” ์„ ํƒ์ )
  • ๋ฐ์ดํ„ฐ ์œ ์ถœ ์—†์Œ โ€” ๋ชจ๋“  ์Šค์บ”์€ ๋กœ์ปฌ์—์„œ ์ˆ˜ํ–‰, ์•„๋ฌด๊ฒƒ๋„ ์™ธ๋ถ€๋กœ ๋‚˜๊ฐ€์ง€ ์•Š์Œ
  • ์ตœ์†Œํ•œ์˜ ์˜์กด์„ฑ โ€” ๊ณต๊ฒฉ ํ‘œ๋ฉด ์ตœ์†Œํ™”
  • ๊ธฐ๋ณธ fail-open โ€” warn ๋ชจ๋“œ์—์„œ ํ›…์€ ์›Œํฌํ”Œ๋กœ์šฐ๋ฅผ ์ฐจ๋‹จํ•˜์ง€ ์•Š์Œ

๊ณต๊ฐœ ์ •์ฑ