Fixes land on main and in the next release. Older releases are not patched. · 修复只进 main 和下一个版本,旧版本不单独打补丁。
Please report privately through GitHub: Security → Report a vulnerability on this repository (private vulnerability reporting). Don't open a public issue for it. You should hear back within 7 days.
请通过 GitHub 私下报告:在本仓库点 Security → Report a vulnerability(私密漏洞报告),不要开公开 issue。一般 7 天内回复。
- A way for the tools to leak an API key: keys must only be read from environment variables, never written to files, logs or reports (hard rule 7 in
CLAUDE.md). · 工具可能泄露 API key 的途径:key 只能从环境变量读,不能写进文件、日志或报告(CLAUDE.md硬规则 7)。 - Instructions from third-party repositories reaching an agent:
references/fetch.shrenames other projects'CLAUDE.md,CLAUDE.local.md,AGENTS.md,.claude/,.agents/and.mcp.jsonso agents don't load them. A bypass is a security issue. · 第三方仓库的指令被 agent 读到:references/fetch.sh会把别人的CLAUDE.md、CLAUDE.local.md、AGENTS.md、.claude/、.agents/、.mcp.json改名,防止被 agent 自动加载。能绕过它就算安全问题。 - Shell or code injection through
bin/vharguments, project names, scripts or score files. · 通过bin/vh参数、项目名、稿子或配乐文件注入命令或代码。
Bugs in rendering, timing or sound quality are regular issues. · 渲染、时序、音质上的毛病请开普通 issue。