forked from bchanot/claude
Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
740c3d8c3e | ||
|
|
e59e26890e |
@@ -84,3 +84,20 @@ stopwords = ['''publish/reject''']
|
||||
[[allowlists]]
|
||||
description = "Claude Code IDE lock files"
|
||||
paths = ['''(^|/)ide/[0-9]+\.lock$''']
|
||||
|
||||
# ── 2026-09-15 — Claude Code daemon/session runtime state, triaged on macOS.
|
||||
# Same class as the IDE locks above: written by Claude Code itself, machine-
|
||||
# local, ephemeral. Verified before allowlisting — roster.json's hits are the
|
||||
# rendezvousSock/ptySock unix-socket paths and the sessionId UUID (paths, not
|
||||
# credentials); sessions/*.key IS a real per-worker key, but 0600 and outside
|
||||
# git. Neither directory is reachable from a commit: link.sh exposes exactly
|
||||
# seven repo symlinks under ~/.claude (CLAUDE.md, settings.json, hooks, agents,
|
||||
# skills, lib, templates) and these are not among them, so `git ls-files` can
|
||||
# never see them. Scoped to the two exact filenames, NOT to the directories —
|
||||
# a stray copy landing beside them stays detected.
|
||||
[[allowlists]]
|
||||
description = "Claude Code daemon roster + per-session keys (machine-local runtime state)"
|
||||
paths = [
|
||||
'''(^|/)\.claude/daemon/roster\.json$''',
|
||||
'''(^|/)\.claude/sessions/[0-9]+\.[0-9a-f]{64}\.key$''',
|
||||
]
|
||||
|
||||
Reference in New Issue
Block a user