Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

### Fixed

- **A killed hook spawn no longer leaves a copy of the OAuth token on disk.**
spawnllm ran its isolated `claude -p` calls against a temp config directory
and wrote a `.credentials.json` copy of the token into it for the child to
read. Every spawn killed before its cleanup left that copy behind, and Claude
Code migrated each one into a login-Keychain item. One machine carried 345.
0.13.4 passes the token through `CLAUDE_CODE_OAUTH_TOKEN`, so spawnllm writes
no copy at all. The floor moves from `>=0.13.2` to `>=0.13.4`: an older
resolution still carries the leak.

## [12.41.0] - 2026-09-17

### Added
Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ dependencies = [
"filelock>=3",
"pathspec>=0.12",
"loguru>=0.7.3",
"spawnllm>=0.13.2,<0.14",
"spawnllm>=0.13.4,<0.14",
"mcp>=2.0,<3",
]

Expand Down
10 changes: 5 additions & 5 deletions uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading