All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
- Add Linux headless fallback to
ZAI_API_KEYwhenlibsecret/secret-toolis unavailable or lookup fails - Improve launcher guidance with Linux fallback message when credential fetch fails
- Update troubleshooting for
org.freedesktop.secretstimeout and missing login collection cases
- Add deterministic
claudebinary resolution via optionalCLAUDE_BINincredentials/security.conf - Extend trusted runtime fallback probes to common user-local install paths (
~/.local/bin,~/.npm-global/bin,~/.volta/bin,~/.nvm/...) - Auto-detect and persist
CLAUDE_BINduring install whenclaudeis available - Prevent launcher failures caused by restricted PATH-only resolution in non-standard environments
- Expand
${HOME}/$HOMEforGLM_INSTALL_DIRwhen loadingcredentials/security.confincredentials/common.sh - Prevent false absolute-path validation failures in
scripts/install.shandscripts/uninstall.shwhen config uses HOME variable notation
- CI: exclude ShellCheck false positives
SC2317andSC2329
- MCP/Plugin sync between GLM sessions and global config
- Remove obsolete
CLAUDE_SETTINGSreference
- Implement per-session
CLAUDE_CONFIG_DIRisolation
2.0.13 - 2026-02-14
- PRODUCTION READY: Achieved PASS verdict from external security reviewers (Codex & Gemini)
- Fixed last naked
securitycommand incheck_keychain_accessible()- use absolute path/usr/bin/security - Eliminated all PATH poisoning vulnerabilities through 10 rounds of external review
Final security hardening release. All external commands now use absolute paths. Zero known vulnerabilities.
2.0.12 - 2026-02-14
- Use absolute paths for ALL remaining external commands:
/usr/bin/env,/bin/rm - Update all
securitycommands incredentials/macos.shto use/usr/bin/security(9 locations) - Prevent PATH-dependent execution of security-critical operations
2.0.11 - 2026-02-14
- MAJOR RESTRUCTURING: Move ALL session setup operations before credential fetch
- Ensure no external commands execute after credentials enter environment
- Complete execution order: setup → validate → fetch credentials → launch
- Eliminate command execution vulnerability window
2.0.10 - 2026-02-14
- Fix command substitution in
load_mcp_config()- move call before credentials - Add Bash 3.2 compatibility for macOS default shell
- Use builtin
printf '%(%s)T'for Bash 4.2+, fallback to/bin/datefor older versions
- Bash compatibility issue on macOS (default Bash 3.2 doesn't support
printf '%(%s)T')
2.0.9 - 2026-02-14
- Fix command substitution timing issues after secret operations
- Move
claude_binresolution to start ofmain()before credential fetch
2.0.8 - 2026-02-14
- Fix 3 critical issues from external review round 4
- Improve command execution order relative to credential operations
2.0.7 - 2026-02-14
- Restore terminal colors in SSH sessions by preserving
TERMenvironment variable - Change
TERM=dumbtoTERM="${TERM:-xterm-256color}"for better SSH experience
2.0.6 - 2026-02-13
- Add portable path canonicalization function
canonicalize_path()inscripts/common-utils.sh - Replace all
realpath -mcalls with portable implementation (GNU/BSD compatible)
- Fix 5 critical regressions from v2.0.5:
- Remove
readonly PATHthat conflicts withsetup_path() - Fix
realpath -mportability issue (GNU-only flag, not available on BSD/macOS) - Fix
localkeyword at top-level inbin/glm-cleanup-sessions
- Remove
2.0.5 - 2026-02-13
- Fix all 9 critical issues from external review round 3 (Codex & Gemini)
- Comprehensive PATH hardening and command injection prevention
- Validate all external command paths
- Prevent PATH manipulation attacks
2.0.4 - 2026-02-12
- Fix all 7 remaining code quality issues from comprehensive review
- Improve error handling and edge cases
2.0.3 - 2026-02-12
- Fix 4 critical bugs from comprehensive code review
- Improve robustness and error handling
2.0.2 - 2026-02-12
- Fix all 8 vulnerabilities from external review round 2 (Codex & Gemini)
- Strengthen credential handling security
- Improve input validation
2.0.1 - 2026-02-12
- Fix all 12 vulnerabilities from external review round 1 (Codex & Gemini)
- 6 HIGH severity
- 4 MEDIUM severity
- 2 LOW severity
- Initial comprehensive security hardening
- Security quick start guide
- Automated secret scanning with gitleaks
- Pre-commit hooks for credential protection
2.0.0 - 2026-02-11
- CLAUDE_CONFIG_DIR isolation: GLM sessions use separate
~/.claude-glmconfig directory - Session-specific settings for complete isolation from official Claude sessions
- Comprehensive error handling and validation
- Security automation:
- Automated gitleaks secret scanning
- Pre-commit hooks
- Comprehensive
.gitignorewith 140+ security patterns
- BREAKING: GLM sessions now use isolated config directory (
~/.claude-glm) - Default GLM model mappings updated for GLM 5 release (2026-02-11):
- Haiku:
glm-4.5-air→glm-4.6 - Sonnet:
glm-4.6→glm-4.7 - Opus:
glm-4.7→glm-5
- Haiku:
- Settings.json sync issues between GLM and official Claude sessions
- Model selection persistence across sessions
1.7.1 - 2026-02-10
- Documentation updates for v1.7.0 features
1.7.0 - 2026-02-10
- Session cleanup utility:
glm-cleanup-sessions--list: View all sessions with details--keep N: Keep last N sessions--session <id>: Delete specific sessions--dry-run: Preview deletions
- Update utility:
glm-update - Session-isolated settings for GLM (prevents UI state pollution)
- Force opus model to override UI state caching
- Improved session management and cleanup
1.6.0 - 2026-02-09
- Session-isolated settings file per GLM invocation
- Prevent settings pollution between sessions
- Automatic cleanup on exit
- Each
claude-by-glminvocation creates isolated session config
1.5.0 - 2026-02-08
- Add comprehensive input validation
- Document environment variable exposure
- Improve credential handling security
1.4.3 - 2026-02-08
- Remove unsupported
-toption fromsecurity add-generic-password - Add keychain unlock for SSH/non-interactive sessions
1.4.2 - 2026-02-08
- Remove incorrect
-Uflag usage insecurity add-generic-password
1.4.1 - 2026-02-08
- Validate password before storing in keychain
- Check
securitycommand output for errors - Better error messages for keychain operations
1.4.0 - 2026-02-08
- Interactive API key input with validation and retry loop
- Better user experience for key installation
1.3.9 - 2026-02-07
- Relax overly restrictive ACL permissions in macOS keychain
- Improve keychain accessibility
1.3.8 - 2026-02-07
- Handle unset
ZDOTDIRvariable in install script - Improve zsh configuration detection
1.3.7 - 2026-02-07
- Interactive account name prompt in
install-key.sh - Better handling of custom account names
1.3.6 - 2026-02-07
- Use service-only lookup for macOS Keychain (org-managed device compatibility)
- Add
GLM_ALLOW_SERVICE_ONLY_KEYCHAINopt-in flag
1.3.5 - 2026-02-07
- Handle macOS Keychain account name prefixes on org-managed devices
- Fallback to service-only lookup when needed
1.3.0 - 2026-02-06
- BREAKING: Rename install directory from
.glm-mcpto.claude-glm-mcp - Improve clarity and avoid conflicts
1.2.0 - 2026-02-05
- Centralize configuration in
credentials/security.conf - Fix critical security issues in credential handling
- Improve credential storage security
- Fix permission issues
1.1.0 - 2026-02-04
- Multi-platform credential storage support:
- macOS: Keychain (
securitycommand) - Linux: libsecret (
secret-tool) - Windows: Environment variable (
ZAI_API_KEY)
- macOS: Keychain (
- Platform abstraction layer for credentials
1.0.0 - 2026-02-03
- Initial release: GLM MCP Wrapper System
- Secure credential management with macOS Keychain
- Z.ai GLM model support (GLM 4.5-air, 4.6, 4.7)
- Optional Z.ai MCP server integration
- Installation and setup scripts
- Basic documentation
- 2.x.x: Security-hardened production releases
- 1.x.x: Feature development releases
- 0.x.x: Pre-release/experimental