Repository navigation
feat(claude-code): bundle security-guidance and claude-security plugins - #199
Merged
Merged
Conversation
- Install security-guidance and claude-security from claude-plugins-official in the init-plugins.sh template - Bake python3 + python3-venv (~+41 MB) into the base stage: both plugins' hooks and scripts need Python, and the image had none (security-guidance's hooks would exit 1 on every edit); the sandbox firewall blocks runtime apt - Assert python3/ensurepip in the image verify steps (ci.yml + build workflow) - Document both plugins and the sandbox PyPI allowlist note in the README
… cost in size roadmap - SECURITY_GUIDANCE_DISABLE stops the reviews but not the SessionStart venv bootstrap (~100 MB claude-agent-sdk wheel into ~/.claude); say so - Log python3/python3-venv (+41 MB disk, ~13 MB compressed, layer sharing and per-bump rebuild unchanged) in the image size roadmap
gatezh
force-pushed
the
feat/claude-code-security-plugins
branch
from
October 6, 2026 21:03
244c7cc to
1faeed1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Add Anthropic's
security-guidanceandclaude-securityplugins to theclaude-codeinit-plugins.shtemplate, and bake Python 3 into the image so they actually run.Why
Both plugins are in
claude-plugins-official(already registered), so the template change is just two entries. Both run on Python, though, and the image had no Python.node:24-trixie-slimships no interpreter. Without it,security-guidance'sPostToolUse/Stophooks exit 1 on every edit and turn, andclaude-securitycan't run its scan scripts. The sandbox firewall blocksdeb.debian.org, so consumers can'tapt-get installPython at runtime. It has to live inbase, the same reasoning asopenssh-client(#110).Changes
init-plugins.sh: installsecurity-guidance@claude-plugins-officialandclaude-security@claude-plugins-officialDockerfile(basestage, so both targets get it): addpython3(3.13 on trixie) andpython3-venv. The plugins only use the standard library.python3-venvprovidesensurepip, whichsecurity-guidanceneeds to build itsclaude-agent-sdkvenv in~/.claude/security/(persisted by the~/.claudevolume).ci.yml+build-claude-code.yml, all 4 matrix entries): assertpython3 -c 'import ensurepip'claude-code/README.md: add python3 to the tools table, add both plugins to the bundled-plugins table, and add a note onsecurity-guidance's runtime SDK downloaddocs/plans/…image-size-roadmap.md): record the Python cost in the core-image table and the measurements logNotes
security-guidanceneedsclaude-agent-sdk(a ~100 MB wheel that bundles its own Claude Code binary), fetched from PyPI on first session start into the~/.claudevolume, not the image.SECURITY_GUIDANCE_DISABLE=1does not skip that bootstrap. In the sandbox: the default-deny firewall blocks the fetch. The plugin then falls back to the single-call diff review, and edit-time pattern warnings and Stop reviews keep working. The README tells sandbox consumers to allowlistpypi.org+files.pythonhosted.orgif they want the full reviewer.security-guidanceruns an LLM diff review at the end of every turn and on each commit/push. Consumers can turn it off withSECURITY_GUIDANCE_DISABLE=1(or the finer-grainedENABLE_*vars) or drop it from theirinit-plugins.shcopy.python3+python3-venvwith--no-install-recommendsadds about 41 MB on disk, measured on a cleannode:24-trixie-slim. That's the smallest set that works:python3-minimal(+18 MB) lackshttp/urllib, which both plugins import.python3-venv(+5 MB) is cheaper thanpython3-pip(+15 MB) for the SDK venv.node(about 50 ms → 240 ms per call), andsecurity-guidancefires on every edit.pythonimage stage are all larger, and apt is the canonical route on Debian.init-plugins.sh. The Python they need arrives with the next image pull.Fits the layer/cache work from #183 and #196
Rebased onto
master(incl. #196 and #195). Builtmasterand this branch side by side, both targets:RUNinbase. That layer rarely changes and sits above thesharedstage, so both targets share it and no layer is added. Adding it busts the cache below it once; after that, Claude Code bumps still rebuild only the Claude Code and agent-browser layers.--no-install-recommends, so no apt lists or caches ship in the image. The compressed download grows by about 13 MB (gzip of the added files).ARG, no Renovate entry: apt packages are unpinned by policy (.hadolint.yamlignores DL3008).Verification (local, amd64)
defaultandsandboxtargets after the rebase; the CI verify commands from bothci.ymlandbuild-claude-code.ymlpass on eachsecurity-guidancePostToolUsehook flagged ayaml.load()write (.py) and aninnerHTMLwrite (.js)claude-securitybannerhook rendered (exit 0)python3 -m venv+pipwork.hadolint.yaml) and actionlint are clean