ci / check (push) Waiting to run
The first public release of LLeMbas CLI: a terminal coding agent and project manager for any LLM API, with permission modes, git snapshots, memory and skills, knowledge bases, MCP, voice, and a link to a LLeMbas instance whose web UI can work its sessions too. Signed Linux binaries for x64 and arm64. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
58 lines
2.7 KiB
Markdown
58 lines
2.7 KiB
Markdown
# Security
|
|
|
|
## Reporting a problem
|
|
|
|
Please report a vulnerability privately, not in a public issue: on GitHub, **Security → Report a
|
|
vulnerability** on [LLeMbas/LLeMbas-CLI](https://github.com/LLeMbas/LLeMbas-CLI/security).
|
|
|
|
Say what it is, how to reproduce it, and which version (`lembas --version`). You will get an
|
|
answer within a week. Fixes go out as a release, and the CHANGELOG says what was fixed once the release is out.
|
|
|
|
## Supported versions
|
|
|
|
Only the newest release. LLeMbas
|
|
CLI updates itself (`update.auto`), so staying on it is the default.
|
|
|
|
## What counts
|
|
|
|
LLeMbas CLI runs commands and changes files for a language model, so the model's output — and
|
|
everything the model reads: files, web pages, tool results, MCP servers — is treated as
|
|
untrusted. A report is most useful when it shows one of these:
|
|
|
|
- a tool call that runs, or changes something, **without the approval** the permission mode and
|
|
rules say it needs — including a way past the hardline list (refused in every mode) or a write
|
|
to a protected path (`~/.ssh`, `~/.gnupg`, `connections.yaml`);
|
|
- something a repository can do **before the user trusts it**, or in read-only mode, beyond being
|
|
read; or anything that weakens a global-only setting from a project;
|
|
- a way for the agent to change a setting it must not (permission rules, the hardline, MCP
|
|
servers, connections, the update source or key, `settings_tool`), or to loosen the permission
|
|
mode without being asked every time;
|
|
- an update that installs without a valid signature from the release key, an older release
|
|
installed as an update, or files written outside where the installer and uninstaller say;
|
|
- secrets — API keys, OAuth tokens — written somewhere readable, logged, or sent to a host other
|
|
than the one they belong to.
|
|
|
|
A model doing something unwise **with** the user's approval, or in `unrestricted` mode, is how
|
|
LLeMbas CLI is meant to work, not a vulnerability; ways to make that clearer are still welcome as
|
|
ordinary issues ([GitHub Issues](https://github.com/LLeMbas/LLeMbas-CLI/issues)).
|
|
|
|
## Verifying a release
|
|
|
|
Each release's `SHA256SUMS` is signed with the release key, an SSH ed25519 key used for nothing
|
|
else:
|
|
|
|
```
|
|
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDSZO3Byow7R3ZpOH3MCvpPIga2pZBzhfX5wXfNP1cLa
|
|
SHA256:aPrR1ptc5sIwmyJgmqtu1iXmciq466Wv9kZNfm8Ddmg
|
|
```
|
|
|
|
`get.sh` and the updater check it before installing anything. By hand:
|
|
|
|
```sh
|
|
echo "lembas-release ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDSZO3Byow7R3ZpOH3MCvpPIga2pZBzhfX5wXfNP1cLa" > allowed
|
|
ssh-keygen -Y verify -f allowed -I lembas-release -n lembas-release -s SHA256SUMS.sig < SHA256SUMS
|
|
sha256sum -c --ignore-missing SHA256SUMS
|
|
```
|
|
|
|
Tags and commits are signed too (SSH signatures, shown as verified on the forge).
|