* docs: sync to Claude Code v2.1.245 Sync the tutorial, its four translations, and both learner-facing skills against Claude Code v2.1.245 (was anchored at v2.1.235). The graded material turned out to be staler than the tutorials it grades. The lesson READMEs already said "31 hook events", "six rewind options" and "six permission modes"; the quiz and self-assessment still said 25, 5 and 5, so learners were scored against a wrong answer and then sent to a lesson that contradicted it. Seven such claims are fixed here. Two long-standing doc defects were also verified against official docs: - Hook default timeout was documented as 60 seconds. It is 600 for command/http/mcp_tool (30 for prompt, 60 for agent), with per-event overrides. Wrong in five places. - Skill precedence was documented as enterprise > project > personal. The official order is enterprise > personal > project. question-bank.md Lesson 03 Q9 already graded the correct order, so the lesson had been contradicting its own quiz. Fixed - Hook default timeout 60s -> 600s, with per-event overrides - Skill precedence: project and personal were swapped - Memory "overrides root CLAUDE.md" -> concatenation model (last holdouts after the quiz was aligned in #164) - permissionMode frontmatter omitted `auto` (English + vi/ja/uk); the quiz was right and the docs were wrong - Built-in subagent `Bash` no longer exists upstream -> renamed to `claude` - `/undo` is absent from the official commands reference -> marked deprecated - `backgroundTasks` settings block was fabricated -> replaced with CLAUDE_CODE_DISABLE_BACKGROUND_TASKS and the concurrency env var - Plugin manifest field is `lspServers`, not inline `lsp` - vi/05-mcp documented `claude mcp add --transport ws`, which upstream explicitly does not support - Self-assessment could never reach its own maximum score: rounds cap at 4+4+4+3+4 = 19, not 20 - 13 dangling quiz `Review:` pointers, two of which named another lesson - Skill description cap: 1024 chars -> 1,536 combined with `when_to_use` Added - WebSocket (`ws`) MCP transport, undocumented until now - Concise output style (v2.1.237), a fifth built-in - modelPicker, promptCacheTtl, subagentPromptCacheTtl, modelPricing, keybindingFlavor settings - ANTHROPIC_DEFAULT_MODEL env var - Hook `async`, `asyncRewake`, `shell`, `statusMessage`, `retry` keys; `agent` type marked experimental - /design canvas, Remote Control out of research preview, notify_when_idle, plugin manifest fields (workflows, channels, dependencies, outputStyles) Deferred deliberately: the reserved `synced` skills folder, and a bulk footer stamp across the translations. zh/ carries none of the P0 claims (it is abridged upstream of this run), so it has no P0 sub-tasks rather than fabricated English. Mermaid validation did not run in this environment (mmdc absent); CI covers it. * fix(docs): propagate v2.1.245 corrections to CATALOG, translations, and stale enumerations * fix(docs): propagate built-in subagent rename to uk/vi/zh CATALOG and zh lesson
3.8 KiB
Chính Sách Bảo Mật / Security Policy
Tổng Quan / Overview
Bảo mật của dự án Claude How To là quan trọng đối với chúng tôi. Tài liệu này phác thảo các thực hành bảo mật của chúng và mô tả cách báo cáo các lỗ hổng bảo mật một cách có trách nhiệm.
Các Phiên Bản Được Hỗ Trợ / Supported Versions
Chúng tôi cung cấp các bản cập nhật bảo mật cho các phiên bản sau:
| Phiên Bản | Trạng Thái | Hỗ Trợ Đến |
|---|---|---|
| Mới nhất (main) | ✅ Hoạt Động | Hiện tại + 6 tháng |
Lưu ý: Là một dự án hướng dẫn giáo dục, chúng tôi tập trung vào việc duy trì các thực hành tốt nhất hiện tại và bảo mật tài liệu hơn là hỗ trợ phiên bản truyền thống. Các bản cập nhật được áp dụng trực tiếp vào nhánh chính.
Thực Hành Bảo Mật / Security Practices
Bảo Mật Code
-
Quản Lý Dependency
- Tất cả dependencies Python được pinned trong
requirements.txt - Cập nhật thường xuyên qua dependabot và review thủ công
- Quét bảo mật với Bandit trên mỗi commit
- Pre-commit hooks cho các kiểm tra bảo mật
- Tất cả dependencies Python được pinned trong
-
Chất Lượng Code
- Linting với Ruff bắt các vấn đề phổ biến
- Kiểm tra kiểu với mypy ngăn các lỗ hổng liên quan đến kiểu
- Pre-commit hooks thực thi các tiêu chuẩn
- Tất cả các thay đổi được review trước khi gộp
-
Kiểm Soát Truy Cập
- Bảo vệ nhánh trên nhánh
main - Yêu cầu review trước khi gộp
- Các kiểm tra trạng thái phải pass trước khi gộp
- Quyền ghi hạn chế đến repository
- Bảo vệ nhánh trên nhánh
Bảo Mật Tài Liệu
-
Không Secrets trong Ví Dụ
- Tất cả API keys trong ví dụ là placeholders
- Credentials không bao giờ được hardcode
- Các file
.env.examplehiển thị các biến được yêu cầu - Cảnh báo rõ về quản lý secret
-
Thực Hành Bảo Mật Tốt Nhất
- Các ví dụ minh họa các mẫu an toàn
- Cảnh báo bảo mật được làm nổi bật trong tài liệu
- Links đến các hướng dẫn bảo mật chính thức
- Xử lý credential được thảo luận trong các phần liên quan
-
Review Nội Dung
- Tất cả tài liệu được review cho các vấn đề bảo mật
- Các cân nhắc bảo mật trong hướng dẫn đóng góp
- Xác thực các liên kết và tham khảo bên ngoài
Báo Cáo Một Lỗ Hổng Bảo Mật / Reporting a Vulnerability
Vấn Đề Bảo Mật Chúng Tôi Quan Tâm
Chúng tôi đánh giá cao các báo cáo về:
- Lỗ hổng code trong scripts hoặc ví dụ
- Lỗ hổng dependency trong các gói Python
- Vấn đề mật mã trong bất kỳ ví dụ code nào
- Lỗi Xác Thực/Ủy Quy trong tài liệu
- Rủi ro lộ dữ liệu trong ví dụ cấu hình
- Lỗ hổng tiêm nhiễm (SQL, command, v.v.)
Cách Báo Cáo / How to Report
Vui lòng báo cáo các lỗ hổng bảo mật một cách riêng tư:
- Gửi email đến: security@example.com
- Sử dụng tiêu đề email: [Security] Mô tả ngắn gọn
- Cung cấp đủ chi tiết để chúng tôi tái tạo và xác nhận vấn đề
Chúng tôi sẽ:
- Xác nhận nhận trong vòng 48 giờ
- Cung cấp timeline cho việc sửa
- Thông báo khi bản vá đã được phát hành
- Công khai thừa nhận báo cáo của bạn (nếu bạn muốn)
Thank you for helping keep Claude How To secure!
Cập Nhật Lần Cuối: Ngày 25 tháng 8 năm 2026 Phiên Bản Claude Code: 2.1.245 Nguồn: