mirror of
https://github.com/NanmiCoder/claude-code-haha.git
synced 2026-10-10 11:53:10 +08:00
docs: add signing and privacy policies
This commit is contained in:
@@ -0,0 +1,56 @@
|
||||
---
|
||||
title: Code signing policy
|
||||
nav_title: Signing policy
|
||||
description: Signing scope, responsible roles, approval, verification, and revocation rules for official Claude Code Haha releases.
|
||||
order: 5
|
||||
---
|
||||
|
||||
# Code signing policy
|
||||
|
||||
This policy applies to official Windows releases of Claude Code Haha. The project is applying for free code signing through the SignPath Foundation. Until onboarding is complete, the Windows download page will continue to identify installers as unsigned. After onboarding, only artifacts that comply with this policy will be submitted for signing.
|
||||
|
||||
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
|
||||
|
||||
The service is provided by [SignPath.io](https://about.signpath.io) and the [SignPath Foundation](https://signpath.org).
|
||||
|
||||
## Signing scope
|
||||
|
||||
Signing is limited to the Windows desktop application, project-owned sidecars, and final x64 and ARM64 NSIS installers built from source owned by this project in [NanmiCoder/cc-haha](https://github.com/NanmiCoder/cc-haha).
|
||||
|
||||
Release packages may include third-party or upstream open-source components distributed under their respective licenses. Those components may be bundled unchanged, but they will not be signed as binaries owned by Claude Code Haha. The certificate will not be used for other projects, personal builds, debug builds, or files of unknown origin.
|
||||
|
||||
## Trusted source and build
|
||||
|
||||
- The only trusted source is a protected release commit or tag in the public GitHub repository.
|
||||
- Official Windows artifacts are built by version-controlled GitHub Actions workflows on GitHub-hosted runners.
|
||||
- Every signing request must be traceable to a specific commit, release tag, workflow run, and build artifact.
|
||||
- An artifact must not be published if signing fails, its origin is unclear, or its metadata does not match the release.
|
||||
|
||||
## Responsible roles
|
||||
|
||||
- **Authors / Committers:** [@NanmiCoder](https://github.com/NanmiCoder), plus external contributors whose changes have been reviewed and accepted.
|
||||
- **Reviewers:** [@NanmiCoder](https://github.com/NanmiCoder); external contributions require maintainer review before entering an official release commit.
|
||||
- **Approvers:** [@NanmiCoder](https://github.com/NanmiCoder).
|
||||
|
||||
Team members must enable multi-factor authentication for their GitHub and SignPath accounts. This page will be updated when roles or members change.
|
||||
|
||||
## Approval and release
|
||||
|
||||
Every signing request for an official release requires manual approval by an Approver. Automatic approval and approval bypasses are not permitted. Before approval, the commit or tag, build workflow, target architecture, file name, product name, version, and release notes must be checked. An artifact may be uploaded to GitHub Releases only after approval and signature verification.
|
||||
|
||||
## User verification
|
||||
|
||||
After onboarding is complete, a Windows installer can be inspected in PowerShell:
|
||||
|
||||
```powershell
|
||||
Get-AuthenticodeSignature ".\Claude-Code-Haha-<version>-win-x64.exe" |
|
||||
Format-List Status, StatusMessage, SignerCertificate, TimeStamperCertificate
|
||||
```
|
||||
|
||||
Continue with installation only when `Status` is `Valid`, the product and version are expected, and the file came from this project's [GitHub Releases](https://github.com/NanmiCoder/cc-haha/releases).
|
||||
|
||||
## Security incidents and revocation
|
||||
|
||||
Report suspected misuse of the certificate, signing accounts, build process, or release artifacts through a [private GitHub security advisory](https://github.com/NanmiCoder/cc-haha/security/advisories/new) or by email to [relakkes@gmail.com](mailto:relakkes@gmail.com). The maintainer will pause affected releases and signing requests, remove affected downloads, investigate the source, and ask the SignPath Foundation to revoke the certificate or signature when necessary.
|
||||
|
||||
See [Privacy and network access](./privacy.md) for the software's network and local-data behavior.
|
||||
@@ -114,6 +114,10 @@ If the download stalls, you probably can't reach GitHub. The same panel has an "
|
||||
The installer's data protection is not a backup. Keep your own copy of anything you can't afford to lose.
|
||||
:::
|
||||
|
||||
## Code signing policy
|
||||
|
||||
See the [Code signing policy](./code-signing.md) for the Windows signing scope, manual approval, responsible roles, and verification steps. Until SignPath Foundation onboarding is complete, Windows releases remain explicitly identified as unsigned. See [Privacy and network access](./privacy.md) for network and local-data behavior.
|
||||
|
||||
## Next
|
||||
|
||||
Go to [Connect a model](./models.md). Until a model is connected, the app opens but can't send a single message.
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
---
|
||||
title: Privacy and network access
|
||||
nav_title: Privacy
|
||||
description: What Claude Code Haha stores locally, when it uses the network, and how to remove its data.
|
||||
order: 6
|
||||
---
|
||||
|
||||
# Privacy and network access
|
||||
|
||||
Claude Code Haha is a local-first, open-source development tool. The project itself does not operate a cloud backend that receives session content. The application is not fully offline: when you choose a model provider, MCP server, messaging integration, or update feature, relevant data is sent to the third-party service you selected or configured.
|
||||
|
||||
## Data stored locally
|
||||
|
||||
The application stores sessions, workspace records, provider configuration, skills, agents, memory, UI settings, and logs on your device. Primary user data lives under `~/.claude`; some desktop state is managed in the operating system's application-data directory. Authentication tokens and API keys are kept locally, but are sent to the selected service when needed to authenticate a request.
|
||||
|
||||
## When the application uses the network
|
||||
|
||||
Depending on the features you enable, the application may send the following information:
|
||||
|
||||
- **Model and OAuth services:** Prompts, attachments, selected code context, tool results, model parameters, and authentication information are sent to the model or account provider you choose.
|
||||
- **MCP servers and external tools:** Configured MCP servers, search, image generation, and other tools receive the input required to perform the requested operation.
|
||||
- **Messaging and remote access:** If you enable Telegram, Feishu, WeChat, DingTalk, WhatsApp, or remote H5 access, selected session content, messages, and connection metadata pass through the relevant platform or a relay you configure.
|
||||
- **Updates:** The application contacts GitHub Releases to check versions and, when requested, download installers.
|
||||
- **Web links:** Opening documentation, login pages, or other links causes the browser to connect directly to the destination site.
|
||||
- **Upstream runtime traffic:** The bundled upstream agent runtime may contact diagnostic, analytics, or feature-flag services depending on the provider and configuration. Set `DISABLE_TELEMETRY=1` and `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1` to reduce or disable nonessential traffic.
|
||||
|
||||
Each third-party service processes the data it receives under its own privacy policy. Review the provider's terms before use, and do not send secrets, personal information, or private code to a service you do not trust.
|
||||
|
||||
## What the project maintainers do not do
|
||||
|
||||
The project maintainers do not sell user data or place advertising based on personal data in the application. The maintainers do not receive locally stored sessions or configuration unless you choose to include them in an issue, discussion, log, or security report.
|
||||
|
||||
## Removing data
|
||||
|
||||
Uninstalling the application does not automatically delete sessions and configuration under `~/.claude`. To remove local data completely, first back up anything you want to keep, then manually delete `~/.claude` and the Claude Code Haha data in your operating system's application-data directory. To remove data already sent to a third-party service, follow that provider's process.
|
||||
|
||||
## Contact
|
||||
|
||||
For privacy or security questions, contact the maintainer through a [private GitHub security advisory](https://github.com/NanmiCoder/cc-haha/security/advisories/new) or at [relakkes@gmail.com](mailto:relakkes@gmail.com).
|
||||
|
||||
Last updated: August 5, 2026.
|
||||
@@ -0,0 +1,56 @@
|
||||
---
|
||||
title: Code signing policy
|
||||
nav_title: 签名政策
|
||||
description: Claude Code Haha 正式发布包的签名范围、责任角色、审批、验证与撤销规则。
|
||||
order: 5
|
||||
---
|
||||
|
||||
# Code signing policy
|
||||
|
||||
本政策适用于 Claude Code Haha 的正式 Windows 发布包。项目正在申请 SignPath Foundation 免费代码签名;接入完成前,Windows 下载页会继续明确标注安装包尚未签名。接入完成后,只有符合本政策的构建产物才会提交签名。
|
||||
|
||||
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
|
||||
|
||||
服务由 [SignPath.io](https://about.signpath.io) 和 [SignPath Foundation](https://signpath.org) 提供。
|
||||
|
||||
## 签名范围
|
||||
|
||||
签名仅用于本项目拥有并从 [NanmiCoder/cc-haha](https://github.com/NanmiCoder/cc-haha) 源码构建的 Windows 桌面程序、项目自有 sidecar,以及最终的 x64 和 ARM64 NSIS 安装包。
|
||||
|
||||
发布包可能包含在各自许可证下分发的第三方或上游开源组件。这些组件可以原样打包,但不会以 Claude Code Haha 自有二进制的身份签名。证书不会用于其他项目、个人构建、调试构建或来源不明的文件。
|
||||
|
||||
## 可信来源与构建
|
||||
|
||||
- 唯一可信源码来源是公开 GitHub 仓库的受保护发布提交或标签。
|
||||
- 正式 Windows 产物由仓库内受版本控制的 GitHub Actions 工作流在 GitHub 托管的运行器上构建。
|
||||
- 签名请求必须能追溯到具体提交、发布标签、工作流运行和构建产物。
|
||||
- 签名失败、来源不明或元数据不一致的产物不得发布。
|
||||
|
||||
## 责任角色
|
||||
|
||||
- **Authors / Committers:** [@NanmiCoder](https://github.com/NanmiCoder),以及提交经审核贡献的外部贡献者。
|
||||
- **Reviewers:** [@NanmiCoder](https://github.com/NanmiCoder);外部贡献必须经过维护者审核后才能进入正式发布提交。
|
||||
- **Approvers:** [@NanmiCoder](https://github.com/NanmiCoder)。
|
||||
|
||||
团队成员必须为 GitHub 和 SignPath 账户启用多因素认证。角色或成员发生变化时,本页会同步更新。
|
||||
|
||||
## 审批与发布
|
||||
|
||||
每一次正式发布的签名请求都必须由 Approver 手动审批,不允许自动批准或绕过审批。批准前需要核对提交或标签、构建工作流、目标架构、文件名、产品名称、版本和发布说明。审批完成并验证签名后,产物才可以上传到 GitHub Releases。
|
||||
|
||||
## 用户验证
|
||||
|
||||
接入完成后,可以在 PowerShell 中检查 Windows 安装包:
|
||||
|
||||
```powershell
|
||||
Get-AuthenticodeSignature ".\Claude-Code-Haha-<version>-win-x64.exe" |
|
||||
Format-List Status, StatusMessage, SignerCertificate, TimeStamperCertificate
|
||||
```
|
||||
|
||||
只在 `Status` 为 `Valid`、产品与版本符合预期且文件来自本项目 [GitHub Releases](https://github.com/NanmiCoder/cc-haha/releases) 时继续安装。
|
||||
|
||||
## 安全事件与撤销
|
||||
|
||||
如发现证书、签名账户、构建流程或发布产物可能被滥用,请通过 [GitHub 私密安全报告](https://github.com/NanmiCoder/cc-haha/security/advisories/new) 或发送邮件至 [relakkes@gmail.com](mailto:relakkes@gmail.com) 报告。维护者会暂停相关发布和签名请求、移除受影响的下载、调查来源,并在需要时联系 SignPath Foundation 撤销证书或签名。
|
||||
|
||||
软件联网与本地数据处理方式见[隐私与联网说明](./privacy.md)。
|
||||
@@ -114,6 +114,10 @@ cp .env.example .env
|
||||
安装器的数据保护不等于备份。真正重要的东西请自己另存一份。
|
||||
:::
|
||||
|
||||
## Code signing policy
|
||||
|
||||
Windows 安装包的签名范围、人工审批、责任角色和验证方法见 [Code signing policy](./code-signing.md)。在 SignPath Foundation 接入完成前,Windows Release 仍会明确标注为未签名;软件联网和本地数据处理方式见[隐私与联网说明](./privacy.md)。
|
||||
|
||||
## 装完之后
|
||||
|
||||
去 [连接模型服务](./models.md)。没接模型之前,应用能打开,但发不出任何一条消息。
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
---
|
||||
title: 隐私与联网说明
|
||||
nav_title: 隐私与联网
|
||||
description: Claude Code Haha 在本机保存什么、何时访问网络,以及如何清理数据。
|
||||
order: 6
|
||||
---
|
||||
|
||||
# 隐私与联网说明
|
||||
|
||||
Claude Code Haha 是本地优先的开源开发工具,项目本身不运营用于接收会话内容的云端后端。应用并非完全离线:当你选择模型服务、MCP、IM 或更新功能时,相关数据会发送到你选择或配置的第三方服务。
|
||||
|
||||
## 本地保存的数据
|
||||
|
||||
应用会在本机保存会话、工作区记录、服务商配置、技能、Agent、记忆、界面设置和日志。主要用户数据位于 `~/.claude`,部分桌面端状态由操作系统的应用数据目录管理。认证令牌和 API Key 会保存在本机,但在调用你选择的服务时会发送给对应服务完成认证。
|
||||
|
||||
## 何时访问网络
|
||||
|
||||
根据你启用的功能,应用可能发送以下信息:
|
||||
|
||||
- **模型与 OAuth 服务:** 你提交的提示词、附件、所选代码上下文、工具结果、模型参数和认证信息会发送给你选择的模型或账号服务商。
|
||||
- **MCP 与外部工具:** 配置的 MCP 服务器、搜索、图像生成及其他工具会收到完成相应操作所需的输入。
|
||||
- **IM 与远程访问:** 启用 Telegram、飞书、微信、钉钉、WhatsApp 或远程 H5 后,所选会话内容、消息和连接元数据会经过对应平台或你配置的中继服务。
|
||||
- **更新:** 应用会访问 GitHub Releases 检查版本并按你的操作下载安装包。
|
||||
- **网页链接:** 打开文档、登录页或其他网页时,浏览器会直接连接目标站点。
|
||||
- **上游运行时流量:** 随应用提供的上游 Agent 运行时可能根据服务商和配置请求诊断、分析或功能开关服务。可以设置 `DISABLE_TELEMETRY=1` 和 `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1`,减少或关闭非必要流量。
|
||||
|
||||
每个第三方服务都按其自己的隐私政策处理收到的数据。使用前请检查对应服务商的条款,不要向未受信任的服务发送密钥、个人信息或私有代码。
|
||||
|
||||
## 项目维护者不会做的事
|
||||
|
||||
本项目维护者不会出售用户数据,也不会在应用中投放基于个人数据的广告。除非你主动在 Issue、讨论、日志或安全报告中提交,否则维护者不会收到你本机保存的会话和配置。
|
||||
|
||||
## 删除数据
|
||||
|
||||
卸载应用不会自动删除 `~/.claude` 中的会话与配置。需要彻底清理时,请先备份要保留的内容,再手动删除 `~/.claude` 以及操作系统应用数据目录中的 Claude Code Haha 数据。删除已发送给第三方服务的数据,需要按该服务商提供的流程操作。
|
||||
|
||||
## 联系方式
|
||||
|
||||
隐私或安全问题可以通过 [GitHub 私密安全报告](https://github.com/NanmiCoder/cc-haha/security/advisories/new) 或 [relakkes@gmail.com](mailto:relakkes@gmail.com) 联系维护者。
|
||||
|
||||
本说明最近更新于 2026 年 8 月 5 日。
|
||||
Reference in New Issue
Block a user