Report vulnerabilities privately via GitHub Security Advisories on SylphxAI/lockdocs. Do not open public issues for sensitive reports.
- lockdocs reads lockfiles and installed package files. Its network use is:
the embedding model, downloaded once from huggingface.co at a pinned
revision and checked against a pinned SHA-256 (disable with
LOCKDOCS_EMBED=0or--offline); anonymous GitHub requests on the first query that needs them (since 0.4.0; disable with--no-fetchorLOCKDOCS_FETCH=0): a git tag lookup on github.com and one tarball per repository from codeload.github.com for public docs at the resolved release commit, falling back to api.github.com / raw.githubusercontent.com file by file when the archive is too large or the download fails; and, only withlockdocs fetch,--fetchorLOCKDOCS_FETCH=1, package archives from the registries below and docs-site files from GitHub (aGITHUB_TOKEN/GH_TOKENin the environment is sent to api.github.com only, and only for these explicit fetches; it is never sent to github.com, codeload.github.com or raw.githubusercontent.com, and never on automatic requests). No project data is ever sent: requests name public packages, versions and file paths. - With fetching enabled it downloads only the exact package versions requested,
from registry.npmjs.org, pypi.org / files.pythonhosted.org, static.crates.io
and proxy.golang.org, over HTTPS. Archives are unpacked with path checks (no
absolute paths, no
..), only documentation and source files are written, and downloads are capped at 64 MB. - Subprocesses: the system
python3once (to list its site-packages; disable withLOCKDOCS_NO_SYSTEM_PYTHON=1), and theclaudeCLI inlockdocs setup. - The MCP server speaks stdio only.
- The cache lives in your OS cache directory (
LOCKDOCS_CACHEoverrides it) and holds extracted docs and symbols of your dependencies.