Claude 97d1257344 security-guidance: mask credential values in review feedback and session state
A finding quotes the offending line, so when the reviewer flagged a
hardcoded secret the Stop hook's feedback and the previous_findings
snapshot in ~/.claude/security carried the credential itself back into
the main conversation and onto disk (#96276, follow-up report).

Values recognized as credentials in vulnerableCode / fix / evidence text
are now masked to **** plus the last two characters at every boundary to
the main session and before they are stored: the value after a password /
secret / token / api_key-style key (code, JSON, YAML, .env, XML, Dockerfile
ENV), passwords in connection URLs, Authorization and curl -u credentials,
CLI credential flags, well-known API-key formats and private-key blocks,
plus, in findings classed as hardcoded secrets, other quoted literals and
long opaque tokens. The reviewer prompts are unchanged so diff anchoring
and the refute pass keep working on the raw quote; masking happens on the
way out. The commit-review guidance formatter now reuses format_findings.
2026-09-29 16:01:09 +00:00
2025-02-22 09:29:29 -08:00
2025-03-10 14:01:20 -07:00
2025-09-29 09:50:14 -07:00

Claude Code

npm

Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows -- all through natural language commands. Use it in your terminal, IDE, or tag @claude on Github.

Learn more in the official documentation.

Get started

Note

Installation via npm is deprecated. Use one of the recommended methods below.

For more installation options, uninstall steps, and troubleshooting, see the setup documentation.

  1. Install Claude Code:

    MacOS/Linux (Recommended):

    curl -fsSL https://claude.ai/install.sh | bash
    

    Homebrew (MacOS/Linux):

    brew install --cask claude-code
    

    Windows (Recommended):

    irm https://claude.ai/install.ps1 | iex
    

    WinGet (Windows):

    winget install Anthropic.ClaudeCode
    

    NPM (Deprecated):

    npm install -g @anthropic-ai/claude-code
    
  2. Navigate to your project directory and run claude.

Plugins

This repository includes several Claude Code plugins that extend functionality with custom commands and agents. See the plugins directory for detailed documentation on available plugins.

Reporting Bugs

We welcome your feedback. Use the /bug command to report issues directly within Claude Code, or file a GitHub issue.

Connect on Discord

Join the Claude Developers Discord to connect with other developers using Claude Code. Get help, share feedback, and discuss your projects with the community.

Data collection, usage, and retention

When you use Claude Code, we collect feedback, which includes usage data (such as code acceptance or rejections), associated conversation data, and user feedback submitted via the /bug command.

How we use your data

See our data usage policies.

Privacy safeguards

We have implemented several safeguards to protect your data, including limited retention periods for sensitive information, restricted access to user session data, and clear policies against using feedback for model training.

For full details, please review our Commercial Terms of Service and Privacy Policy.

S
Description
GitHub Trending: anthropics/claude-code
Readme
1.8 GiB
Languages
TypeScript 59.3%
Python 34.3%
Shell 5.7%
PowerShell 0.5%
Dockerfile 0.2%