Skip to content

fix: publish history-safe Claude plugin v0.3.1 - #3

Merged
TerminallyLazy merged 1 commit into
mainfrom
codex/security-guidance-v0.3.1
Aug 24, 2026
Merged

fix: publish history-safe Claude plugin v0.3.1#3
TerminallyLazy merged 1 commit into
mainfrom
codex/security-guidance-v0.3.1

Conversation

@TerminallyLazy

@TerminallyLazy TerminallyLazy commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Summary

  • remove token-bearing export examples and require shell-appropriate no-echo or secret-manager injection
  • route support and vulnerability reporting through the canonical repository
  • synchronize the plugin and marketplace at v0.3.1 with regression validation

Validation

  • python3 scripts/validate.py
  • claude plugin validate .
  • JSON validation
  • git diff --check

Carries the reviewed fixes from TerminallyLazy/Tree-Ring-Memory#48 into the public Claude marketplace source.

High-level PR Summary

This PR publishes version 0.3.1 of the Tree Ring Memory Claude plugin with critical security improvements. The changes remove unsafe token-bearing export examples from documentation, replacing them with guidance to use history-safe, no-echo prompts or secret manager injection for the TREE_RING_COORDINATOR_TOKEN. Support and vulnerability reporting URLs are updated to point to the canonical repository rather than the plugin-specific repository. The version is synchronized across marketplace and plugin manifests, and validation checks are enhanced to enforce these security requirements and prevent regression.

⏱️ Estimated Review Time: 15-30 minutes

💡 Review Order Suggestion
Order File Path
1 scripts/validate.py
2 .claude-plugin/plugin.json
3 .claude-plugin/marketplace.json
4 SUBMISSION.md
5 skills/tree-ring-memory/SKILL.md
6 SECURITY.md
7 PRIVACY.md
8 TERMS.md

Need help? Join our Discord

@coderabbitai

coderabbitai Bot commented Aug 24, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 9fd89d58-aa9a-45ee-b24e-c9f105cdb3f9


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@TerminallyLazy
TerminallyLazy merged commit 18fd654 into main Aug 24, 2026
2 of 3 checks passed
@TerminallyLazy
TerminallyLazy deleted the codex/security-guidance-v0.3.1 branch August 24, 2026 04:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant