Skip to content

Security: liuzhao1225/claudex

SECURITY.md

Security Policy

Supported versions

Only the latest Claudex release receives security fixes.

Reporting a vulnerability

Do not open a public issue when a report contains credentials, OAuth artifacts, source code, or a working exploit. Use the repository's private vulnerability reporting form.

Include the Claudex version, operating system and architecture, a redacted reproduction, and the expected security boundary. Never attach ChatGPT, Codex, Claude, or CLIProxyAPI credentials.

Boundaries

Claudex downloads and runs a pinned third-party CLIProxyAPI binary. Reports about Claudex's installer, checksum validation, local binding, secret handling, process ownership, update, rollback, or uninstall logic belong here. Upstream CLIProxyAPI vulnerabilities should also be reported to its maintainers.

There aren't any published security advisories