Please report security issues privately through GitHub's private vulnerability reporting, not in a public issue. You'll get a response within a few days. Fixes are released as patch versions.
Only the latest release gets security fixes.
paceline runs on every Claude Code status line refresh and edits ~/.claude/settings.json during install and uninstall. The issues that matter most:
- Terminal injection. Any way that a folder name, git branch name, or status payload field can get an escape sequence or control character into the output.
- Code execution. Any way that a repository, config file, or state file can make paceline run a command.
- Settings damage. Any way that
installoruninstallcan corrupt or lose the contents ofsettings.json, or write astatusLinecommand that runs something other than paceline. - Supply chain. Anything that could make a release binary differ from what this repository's code builds.
- No dependencies: only the Go standard library. Tests fail if a module is added, or if shipped code imports
os/exec,net,syscall,unsafe, orplugin. - Go source must be ASCII, so bidi overrides and zero-width characters can't hide in the code ("Trojan Source"). Non-ASCII text is written as
\uescapes. - All output from outside sources is stripped of C0 and C1 controls, zero-width characters, and bidi overrides, with length caps. The tests try real escape-sequence attacks against every field.
- Git data is read from files, never by running
git, and reads are limited in size. - Config and state files are validated by type and size. Unknown keys are ignored, and each value is checked on its own, so one bad key never discards the rest.
- The installer refuses to overwrite unparseable settings or another tool's status line (unless
--force), backs up first, writes atomically, and rejects install paths containing shell metacharacters. - CI pins every GitHub Action to a commit SHA, runs
govulncheck, golangci-lint with gosec, and the race detector, and installs the Node release tooling with--ignore-scripts. - Releases are reproducible (
-trimpath, fixed timestamps) and every archive has a signed build provenance attestation you can check withgh attestation verify.