fix: OS release prep - bootstrap script, deps, docs

- Fix bootstrap script (.env.example.local → .env.example)
- Fix @langchain/core version conflict (^1.0.1 → ^0.3.0)
- Add settings:open event listener for LocalKeyGate button
- Pin Next.js to 15.1.3 (was "latest")
- Default runtime to 'local' mode
- Remove desktop app references from UI text
- Rewrite MCP docs for web-only context
- Add SECURITY.md, CODE_OF_CONDUCT.md, CHANGELOG.md
- Add docs/README.md, docs/TROUBLESHOOTING.md
- Update README with platform support table

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
“BeeRad”
2025-12-30 12:24:56 +11:00
co-authored by Claude Opus 4.5
parent ffbd47563e
commit 0e6bf12ad3
15 changed files with 394 additions and 72 deletions
+34
View File
@@ -0,0 +1,34 @@
# Security Policy
## Reporting a Vulnerability
If you discover a security vulnerability, please report it privately:
1. **Do NOT open a public issue**
2. Email: security@ra-h.app (or use GitHub Security Advisories)
3. Include: description, steps to reproduce, potential impact
We will respond within 48 hours and work with you on a fix.
## Supported Versions
| Version | Supported |
|---------|-----------|
| 0.1.x | ✅ |
## Security Considerations
### API Keys
- API keys are stored locally in your browser's localStorage
- Keys are never sent to any server except the respective AI provider (OpenAI, Anthropic)
- Clear your browser data to remove stored keys
### Local Database
- All data is stored locally in SQLite at `~/Library/Application Support/RA-H/db/rah.sqlite`
- No data is sent to external servers (except AI API calls with your keys)
- Back up this file to preserve your data
### MCP Server
- The MCP server binds only to `127.0.0.1` (localhost)
- Do not expose it to external networks
- Only connect trusted AI assistants