LLeMbas CLI 1.0.0
ci / check (push) Waiting to run

The first public release of LLeMbas CLI: a terminal coding agent and project manager for any LLM
API, with permission modes, git snapshots, memory and skills, knowledge bases, MCP, voice, and a
link to a LLeMbas instance whose web UI can work its sessions too. Signed Linux binaries for x64
and arm64.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
HomerandClaude Opus 5.5 committed 2026-10-09 21:59:03 +00:00
commit f9bad01ed7
355 files changed
+47028

No files matched your search

+57
View File
@@ -0,0 +1,57 @@
# Security
## Reporting a problem
Please report a vulnerability privately, not in a public issue: on GitHub, **Security → Report a
vulnerability** on [LLeMbas/LLeMbas-CLI](https://github.com/LLeMbas/LLeMbas-CLI/security).
Say what it is, how to reproduce it, and which version (`lembas --version`). You will get an
answer within a week. Fixes go out as a release, and the CHANGELOG says what was fixed once the release is out.
## Supported versions
Only the newest release. LLeMbas
CLI updates itself (`update.auto`), so staying on it is the default.
## What counts
LLeMbas CLI runs commands and changes files for a language model, so the model's output — and
everything the model reads: files, web pages, tool results, MCP servers — is treated as
untrusted. A report is most useful when it shows one of these:
- a tool call that runs, or changes something, **without the approval** the permission mode and
rules say it needs — including a way past the hardline list (refused in every mode) or a write
to a protected path (`~/.ssh`, `~/.gnupg`, `connections.yaml`);
- something a repository can do **before the user trusts it**, or in read-only mode, beyond being
read; or anything that weakens a global-only setting from a project;
- a way for the agent to change a setting it must not (permission rules, the hardline, MCP
servers, connections, the update source or key, `settings_tool`), or to loosen the permission
mode without being asked every time;
- an update that installs without a valid signature from the release key, an older release
installed as an update, or files written outside where the installer and uninstaller say;
- secrets — API keys, OAuth tokens — written somewhere readable, logged, or sent to a host other
than the one they belong to.
A model doing something unwise **with** the user's approval, or in `unrestricted` mode, is how
LLeMbas CLI is meant to work, not a vulnerability; ways to make that clearer are still welcome as
ordinary issues ([GitHub Issues](https://github.com/LLeMbas/LLeMbas-CLI/issues)).
## Verifying a release
Each release's `SHA256SUMS` is signed with the release key, an SSH ed25519 key used for nothing
else:
```
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDSZO3Byow7R3ZpOH3MCvpPIga2pZBzhfX5wXfNP1cLa
SHA256:aPrR1ptc5sIwmyJgmqtu1iXmciq466Wv9kZNfm8Ddmg
```
`get.sh` and the updater check it before installing anything. By hand:
```sh
echo "lembas-release ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDSZO3Byow7R3ZpOH3MCvpPIga2pZBzhfX5wXfNP1cLa" > allowed
ssh-keygen -Y verify -f allowed -I lembas-release -n lembas-release -s SHA256SUMS.sig < SHA256SUMS
sha256sum -c --ignore-missing SHA256SUMS
```
Tags and commits are signed too (SSH signatures, shown as verified on the forge).