Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
287 commits
Select commit Hold shift + click to select a range
59f532f
docs: define production readiness gate
aatuh May 28, 2026
f198625
fix: verify worker payload objects
aatuh May 28, 2026
b0a9973
ci: add live postgres release checks
aatuh May 28, 2026
a6cd72b
test: isolate github actions env
aatuh May 28, 2026
c39a78f
chore: require patched go toolchain
aatuh May 28, 2026
40ca5ea
chore: raise go patch floor
aatuh May 28, 2026
5a99a24
docs: add api contract precision matrix
aatuh May 28, 2026
21787de
test: enforce production coverage gate
aatuh May 28, 2026
73d00a1
ci: use node24 github actions
aatuh May 28, 2026
f69bf79
ci: use node24 artifact upload
aatuh May 28, 2026
5176856
fix: replay worker payload parsers
aatuh May 28, 2026
3e1159b
docs: tighten release ledger openapi contracts
aatuh May 28, 2026
afacdfe
test: add restore rehearsal coverage
aatuh May 28, 2026
a0c5ee1
feat: add api rate limiting hook
aatuh May 28, 2026
4c383fb
docs: specify operations readiness contracts
aatuh May 28, 2026
56ffd7b
style: format worker imports
aatuh May 28, 2026
6be9eed
feat: expand sdk contract coverage
aatuh May 28, 2026
b143794
ci: add signed release artifact workflow
aatuh May 28, 2026
e2c0039
docs: tighten source snapshot openapi contracts
aatuh May 28, 2026
bc04db8
ci: enforce production check in github actions
aatuh May 28, 2026
c5605b3
docs: tighten evidence openapi contracts
aatuh May 28, 2026
edaf75d
test: add migration compatibility gate
aatuh May 28, 2026
369bc41
fix: clean migration compatibility schemas safely
aatuh May 28, 2026
e1b0fd5
feat: fail closed on pending migrations
aatuh May 28, 2026
c6d26be
docs: tighten identity collector openapi contracts
aatuh May 28, 2026
edf8157
docs: tighten control openapi contracts
aatuh May 28, 2026
c38015c
docs: clarify remaining production backlog
aatuh May 28, 2026
1d1eca6
test: gate openapi contract precision
aatuh May 28, 2026
5f0cba4
docs: tighten system openapi contracts
aatuh May 28, 2026
f0eeb33
docs: tighten identity openapi contracts
aatuh May 28, 2026
b042761
docs: tighten release ledger openapi contracts
aatuh May 28, 2026
bd01734
docs: tighten risk policy openapi contracts
aatuh May 28, 2026
916ca28
docs: tighten contract signing openapi contracts
aatuh May 28, 2026
f990269
docs: tighten provenance openapi contracts
aatuh May 28, 2026
7ba94f4
docs: tighten evidence lifecycle openapi contracts
aatuh May 28, 2026
30fb8e8
docs: tighten source deployment openapi contracts
aatuh May 28, 2026
91696ef
docs: tighten collector openapi contracts
aatuh May 28, 2026
f1e7979
docs: tighten package report openapi contracts
aatuh May 28, 2026
4b64f2a
docs: complete openapi route schemas
aatuh May 28, 2026
3512d9a
docs: update openapi maturity status
aatuh May 28, 2026
1c7832a
build: add sdk route catalog check
aatuh May 28, 2026
a8b734c
test: add postgres restore rehearsal
aatuh May 28, 2026
c2af595
test: harden restore rehearsal copy
aatuh May 28, 2026
4ed95ea
feat: add external signing executor
aatuh May 28, 2026
fcd49f7
feat: verify object retention policy settings
aatuh May 28, 2026
7e8b22e
feat: verify public transparency inclusion proofs
aatuh May 28, 2026
ebf83dd
feat: rotate sso provider trust material
aatuh May 28, 2026
106b69c
fix: persist idempotency with relational identity rows
aatuh May 28, 2026
29cc8e0
feat: synchronize release ledger core rows
aatuh May 28, 2026
544abf0
feat: persist worker parser replay results
aatuh May 28, 2026
83132f3
feat: load core state from relational rows
aatuh May 28, 2026
32838ad
feat: persist portal token rows relationally
aatuh May 28, 2026
ff13941
feat: synchronize package retention rows
aatuh May 28, 2026
28c6337
feat: load package retention rows relationally
aatuh May 28, 2026
6e6c590
feat: recover identity rows relationally
aatuh May 28, 2026
8d94dbb
feat: synchronize risk build control rows
aatuh May 28, 2026
2918f27
feat: synchronize source deployment rows
aatuh May 28, 2026
49ddd76
feat: synchronize incident security rows
aatuh May 28, 2026
ba7f6c3
feat: recover future extension rows relationally
aatuh May 28, 2026
a656e0d
docs: align production readiness status
aatuh May 28, 2026
b38ba20
feat: prefer relational postgres loads in production
aatuh May 28, 2026
0c9cd2f
feat: version outbox parser jobs
aatuh May 28, 2026
d0ed7e7
fix: reject snapshot postgres loads in production
aatuh May 28, 2026
895cc55
feat: disable production snapshot writes
aatuh May 28, 2026
98cba52
docs: clarify remaining production hardening
aatuh May 28, 2026
b77482e
fix: require relational-only production loads
aatuh May 28, 2026
01964b3
feat: add sso session logout
aatuh May 28, 2026
4f08581
feat: add oidc discovery trust refresh
aatuh May 28, 2026
1fc6eae
feat: verify object-level retention samples
aatuh May 28, 2026
5f704d4
feat: fetch transparency inclusion proofs
aatuh May 28, 2026
9daa507
feat: add sso credential exchange
aatuh May 28, 2026
8181863
feat: map oidc groups to sso sessions
aatuh May 28, 2026
5d1843e
feat: support worker-owned sbom parsing
aatuh May 28, 2026
c807c67
feat: defer vulnerability scan parsing to workers
aatuh May 28, 2026
de08970
feat: defer openapi parsing to workers
aatuh May 28, 2026
7ba2b3f
feat: defer attestation parsing to workers
aatuh May 28, 2026
b76925c
feat: defer vex document parsing to workers
aatuh May 28, 2026
ede1fef
feat: create vex decisions in workers
aatuh May 28, 2026
d371646
docs: clarify worker parser readiness status
aatuh May 28, 2026
74f6e60
docs: define release candidate hardening profile
aatuh May 29, 2026
5192f69
chore: harden helm release candidate defaults
aatuh May 29, 2026
0c2de5c
feat: add focused critical mutation port
aatuh May 29, 2026
2e269ab
feat: persist critical mutations in postgres
aatuh May 29, 2026
74f2356
docs: document focused critical writes
aatuh May 29, 2026
3f3ee88
feat: add release candidate packaging gate
aatuh May 30, 2026
e343960
docs: align release candidate evidence workflow
aatuh May 30, 2026
d06ae81
docs: clarify release candidate API writer limit
aatuh May 30, 2026
dfca3cf
fix: make release note validation case insensitive
aatuh May 30, 2026
d27bf6d
feat: add focused release ledger mutations
aatuh May 31, 2026
f79705c
docs: document focused release ledger writes
aatuh May 31, 2026
77fc897
feat: route remaining state through relational persistence
aatuh May 31, 2026
3953338
feat: add aws kms signing executor
aatuh May 31, 2026
b6b76a1
feat: add oidc userinfo provider validation
aatuh May 31, 2026
632af59
feat: verify sample object legal hold
aatuh May 31, 2026
979f800
feat: enforce api writer lease
aatuh May 31, 2026
95aa998
docs: add release evidence scanner workflow
aatuh May 31, 2026
fe4c4f2
fix: release api writer lease with caller context
aatuh May 31, 2026
11deac5
docs: align release candidate evidence status
aatuh May 31, 2026
74206f7
docs: record maturity v2 implementation status
aatuh May 31, 2026
eac6785
docs: clarify remaining provider trust boundaries
aatuh May 31, 2026
9a489e5
fix: enforce single api writer mode
aatuh May 31, 2026
32aa5c7
feat: clarify gateway signing provider modes
aatuh May 31, 2026
c68aa38
feat: add provider validation gateway
aatuh May 31, 2026
ac24261
feat: add transparency proof gateway
aatuh May 31, 2026
3fb40bb
fix: avoid forwarding provider access tokens
aatuh May 31, 2026
104d8a3
docs: update maturity v2 status
aatuh May 31, 2026
b3eee7c
feat: add direct cloud kms signers
aatuh May 31, 2026
2d7d25e
docs: prepare controlled production candidate materials
aatuh May 31, 2026
772fe22
refactor: split ledger application services
aatuh May 31, 2026
bfea705
docs: record production readiness audits
aatuh May 31, 2026
9007d47
docs: track production readiness v2 remediation
aatuh May 31, 2026
ac0344b
chore: add community templates and demo gate
aatuh May 31, 2026
1b3ecb3
test: add black-box production readiness gate
aatuh May 31, 2026
3803da1
docs: refresh production readiness v2 public evidence
aatuh May 31, 2026
8935a20
refactor: split ledger and postgres helpers
aatuh May 31, 2026
84a5f01
docs: refresh production readiness v2 final sha
aatuh May 31, 2026
00bb14a
docs: stabilize production readiness evidence reference
aatuh May 31, 2026
60ae511
docs: track production readiness v3 remediation
aatuh May 31, 2026
148d76c
chore: harden public repository trust checks
aatuh May 31, 2026
94e9e23
chore: fix scorecard pinned action commit
aatuh May 31, 2026
5a5d3a1
ci: split scorecard publication and sarif upload
aatuh May 31, 2026
9e2bdf5
security: document content digest hashing
aatuh May 31, 2026
1c8b6fb
docs: track final readiness remediations
aatuh May 31, 2026
e3d2bb5
test: add digest fuzz smoke targets
aatuh May 31, 2026
0d05221
docs: mark external scorecard signals
aatuh May 31, 2026
f8778f9
docs: track production readiness v5 remediation
aatuh May 31, 2026
d828886
docs: publish release-backed readiness evidence
aatuh May 31, 2026
e604206
chore: add scorecard release signature alias
aatuh May 31, 2026
fa33c6e
chore: add in-toto release provenance asset
aatuh May 31, 2026
6581857
docs: record final readiness v5 scorecard status
aatuh May 31, 2026
afb4c41
chore: close readiness v6 repo-local gaps
aatuh May 31, 2026
3a8f1eb
docs: record public container image evidence
aatuh May 31, 2026
8e10571
chore: apply latest CodeQL action pin
aatuh May 31, 2026
fb813e2
docs: mark readiness v6 remediation complete
aatuh May 31, 2026
87f394f
docs: remove internal dotfile reports
aatuh May 31, 2026
ae698b4
docs(productization): lead with VEX-first evaluation path
aatuh May 31, 2026
12a05be
feat(decisions): add customer-safe lifecycle evidence links
aatuh May 31, 2026
e334d2e
chore(productization): track backlog progress
aatuh May 31, 2026
a38ffaf
feat(decisions): add vulnerability decision history
aatuh May 31, 2026
6988a2f
feat(decisions): add customer-safe decision summary
aatuh May 31, 2026
822b5b0
chore(sdk): refresh OpenAPI route catalog
aatuh May 31, 2026
cdf5175
feat(vex): add import parser reports
aatuh May 31, 2026
6bbee3a
test(vex): cover OpenVEX decision mapping
aatuh May 31, 2026
6a08acd
feat(decisions): link manual decisions to VEX
aatuh May 31, 2026
ef3a8d6
feat(packages): define customer package v2 manifest
aatuh May 31, 2026
3c870e7
feat(packages): add redaction profile presets
aatuh May 31, 2026
41cf6b5
feat(cli): verify customer packages offline
aatuh May 31, 2026
31df719
feat(viewer): improve package review workflow
aatuh May 31, 2026
476748f
docs(examples): add sample customer package
aatuh May 31, 2026
a9ae7c6
feat(reports): add readiness question sections
aatuh May 31, 2026
fa2b46c
feat(policy): expand release readiness checks
aatuh May 31, 2026
2ec346f
feat(packages): add customer safe gaps
aatuh May 31, 2026
13eaa98
docs(ci): add github actions quickstart
aatuh May 31, 2026
a6c3646
feat(cli): add one-shot release evidence upload
aatuh May 31, 2026
1b6ca83
feat(cli): formalize upload manifest validation
aatuh May 31, 2026
3164a0a
feat(api): add release evidence workflow endpoint
aatuh May 31, 2026
51a1e86
feat(api): add release security summary
aatuh May 31, 2026
6dc1e2a
docs(api): add release flow openapi examples
aatuh May 31, 2026
471ef3c
feat(package): add static customer package html report
aatuh May 31, 2026
6aff8d7
docs(ui): defer internal demo dashboard
aatuh May 31, 2026
e7812da
docs(ops): add pilot deployment checklist
aatuh May 31, 2026
139f7c9
docs(commercial): add design partner pilot offer
aatuh May 31, 2026
fb68e25
docs(marketing): add conservative product landing copy
aatuh May 31, 2026
a3e9807
docs(marketing): add category comparison
aatuh May 31, 2026
8f928f7
test(app): add vex-first release evidence flow
aatuh May 31, 2026
23f57ee
test(package): add redaction leakage guards
aatuh May 31, 2026
a62e499
test(package): add customer package manifest golden
aatuh May 31, 2026
7a7c893
docs(productization): add future backlog checkboxes
aatuh May 31, 2026
0bc68ae
feat(package): export api contract evidence
aatuh May 31, 2026
b0cfb8b
feat(portal): audit customer package downloads
aatuh May 31, 2026
c89b596
feat(reports): add CRA evidence templates
aatuh May 31, 2026
91206f1
feat(portal): add gated customer package exchange
aatuh May 31, 2026
5971d4f
feat(integrity): add custody review proofs
aatuh May 31, 2026
4ea8a3c
feat(portal): add reviewer access accounts
aatuh May 31, 2026
4a68d40
fix(postgres): normalize empty text arrays
aatuh May 31, 2026
532419c
chore(release): mark rc5 as current candidate
aatuh Jun 1, 2026
8432a72
ci(release): require explicit publish tokens
aatuh Jun 1, 2026
0db976a
test(coverage): require postgres for production gate
aatuh Jun 1, 2026
c465625
docs(security): document maintainer bypass posture
aatuh Jun 1, 2026
d3d4693
docs(product): add evaluator walkthrough
aatuh Jun 1, 2026
cc27bba
docs(product): add reviewer journey visual
aatuh Jun 1, 2026
80f3e9d
docs(product): focus README proof path
aatuh Jun 1, 2026
33a4d0f
feat(package): add reviewer proof checklist
aatuh Jun 1, 2026
38b6fee
docs(risk): define vulnerability decision taxonomy
aatuh Jun 1, 2026
8dcd7e9
feat(risk): add decision freshness metadata
aatuh Jun 1, 2026
d7e317e
feat(risk): link decisions to sbom context
aatuh Jun 1, 2026
4e6547b
feat(risk): add decision supporting refs
aatuh Jun 1, 2026
6c64c38
feat(package): export customer decision proof
aatuh Jun 1, 2026
0000497
feat(vex): report cyclonedx import issues
aatuh Jun 1, 2026
825e627
feat(vex): add import preview endpoints
aatuh Jun 1, 2026
131227f
feat(worker): record vex parser failures
aatuh Jun 1, 2026
ed3b23a
docs(ci): add github actions quickstart setup
aatuh Jun 1, 2026
75a40ed
feat(cli): add ci preflight checks
aatuh Jun 1, 2026
198d42d
test(ci): add local evidence simulation
aatuh Jun 1, 2026
8e075d5
ci(container): scope image signing permissions
aatuh Jun 1, 2026
04b060f
ci(release): split publishing permissions
aatuh Jun 1, 2026
ce7dc73
docs(production): refresh exit review
aatuh Jun 1, 2026
a5d336c
docs(production): add external controls matrix
aatuh Jun 1, 2026
9bb4fac
docs(production): clarify single writer stance
aatuh Jun 1, 2026
8ca83bd
docs(production): add gate troubleshooting
aatuh Jun 1, 2026
c7fc70b
docs(ux): define reviewer surface boundary
aatuh Jun 1, 2026
c20c87f
feat(portal): add token-scoped package review page
aatuh Jun 1, 2026
d979fed
test(packages): add reviewer workflow proof
aatuh Jun 1, 2026
6d07749
test(productization): preserve portal coverage gate
aatuh Jun 1, 2026
c1c2671
docs(product): close productization audit loop
aatuh Jun 1, 2026
efcb324
docs(product): mark external backlog dependencies
aatuh Jun 1, 2026
47b905f
docs(product): record provider backlog status
aatuh Jun 1, 2026
356273d
docs(product): document publishing secret dependency
aatuh Jun 1, 2026
085e35c
docs(product): refresh public backlog evidence
aatuh Jun 1, 2026
d4155b4
docs(product): remove productization dotfiles
aatuh Jun 1, 2026
650be76
ci(release): fix draft release publishing
aatuh Jun 1, 2026
61f0f1e
feat(site): add Astro marketing site
aatuh Jun 1, 2026
31145d3
feat(site): configure marketing site deployment
aatuh Jun 2, 2026
f8150a9
ci(site): grant Pages configure permission
aatuh Jun 2, 2026
0602a49
fix(site): keep localized hero words whole
aatuh Jun 2, 2026
cc7cad6
docs(release): sync current candidate metadata
aatuh Jun 2, 2026
fa8aa3e
docs(readme): clarify current production status
aatuh Jun 2, 2026
7ed39ee
test(release): check release truth drift
aatuh Jun 2, 2026
d0770a1
chore(deploy): pin production-like compose images
aatuh Jun 2, 2026
ae1107b
docs(release): expose production check evidence
aatuh Jun 2, 2026
8badaf8
docs(release): define stable exit criteria
aatuh Jun 2, 2026
f0665b6
docs(packages): add package viewer screenshots
aatuh Jun 2, 2026
908d74b
docs(demo): add customer CVE review proof
aatuh Jun 2, 2026
e34cc20
feat(site): add homepage demo path
aatuh Jun 2, 2026
7a12385
docs(readme): lead with buyer question
aatuh Jun 2, 2026
556baff
docs: split buyer and operator paths
aatuh Jun 2, 2026
70bdc52
docs(runbooks): add rotation and object recovery
aatuh Jun 2, 2026
2735565
docs(upgrade): define compatibility policy
aatuh Jun 2, 2026
e86f860
docs(license): add decision table
aatuh Jun 2, 2026
21a4f59
docs(contributing): add first contribution path
aatuh Jun 2, 2026
dcc8613
docs(deploy): add hardened reference deployment
aatuh Jun 2, 2026
aa89b0b
docs(config): add production environment example
aatuh Jun 2, 2026
9f5e79d
test(benchmark): add production-like benchmark evidence
aatuh Jun 2, 2026
8624a39
ci(release): add black-box release artifact check
aatuh Jun 2, 2026
d67959c
docs(ops): document HA strategy
aatuh Jun 2, 2026
9b77301
test(persistence): track decomposition inventory
aatuh Jun 2, 2026
f7fddab
docs(openapi): publish rendered api reference
aatuh Jun 2, 2026
2982da2
docs(sdk): add client quickstarts
aatuh Jun 2, 2026
4851d97
docs(ci): add github actions evidence guide
aatuh Jun 2, 2026
298fd1e
docs(integrations): add tool handoff templates
aatuh Jun 2, 2026
e3af073
test(release): add asset verification smoke check
aatuh Jun 2, 2026
46bef3b
feat(package-viewer): add reviewer dossier
aatuh Jun 2, 2026
f6ca5da
feat(package-viewer): show package proof summary
aatuh Jun 2, 2026
3755e87
docs(commercial): define readiness review offer
aatuh Jun 2, 2026
ea8ca8e
docs(product): compare adjacent evidence tools
aatuh Jun 2, 2026
8b7600f
docs(production): add readiness traceability matrix
aatuh Jun 2, 2026
782c178
docs(production): add internal exit checklist
aatuh Jun 2, 2026
c2de8a4
docs(production): record readiness audit closeout
aatuh Jun 2, 2026
f2f1869
docs(production): summarize internal readiness score
aatuh Jun 2, 2026
e7fe1bc
chore(deps): bump github/codeql-action from 4.36.0 to 4.36.2
dependabot[bot] Jun 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
26 changes: 26 additions & 0 deletions .api.env.example
Original file line number Diff line number Diff line change
@@ -1,8 +1,34 @@
EVYDENCE_ADDR=:8080
EVYDENCE_API_KEY_PEPPER=change-me-long-random-pepper
EVYDENCE_DATABASE_URL=postgres://evydence:change-me@localhost:5432/evydence?sslmode=disable
# Local default is snapshot_preferred. Production defaults to relational_only when unset.
# EVYDENCE_POSTGRES_LOAD_MODE=relational_only
EVYDENCE_OBJECT_STORE=filesystem
EVYDENCE_OBJECT_DIR=./tmp/objects
EVYDENCE_RATE_LIMIT_REQUESTS_PER_MINUTE=0
# Optional hardening mode for parser-backed uploads. When true, the API stores
# accepted records and the outbox worker writes parser-derived fields and
# OpenVEX-derived vulnerability decisions.
EVYDENCE_WORKER_OWNED_PARSER_SIDE_EFFECTS=false
EVYDENCE_SIGNING_KEY_MODE=external
# Optional external signing gateway. Use HTTPS outside localhost.
# EVYDENCE_SIGNING_EXECUTOR_URL=https://signer.example.test/sign
# EVYDENCE_SIGNING_EXECUTOR_TOKEN=replace-with-signing-gateway-token
# EVYDENCE_SIGNING_EXECUTOR_TIMEOUT_SECONDS=10
# Optional AWS KMS signing executor. Set EVYDENCE_SIGNING_KEY_MODE=aws-kms.
# EVYDENCE_AWS_REGION=eu-north-1
# EVYDENCE_AWS_KMS_KEY_ID=alias/evydence-release
# EVYDENCE_AWS_KMS_SIGNING_ALGORITHM=ECDSA_SHA_256
# EVYDENCE_AWS_KMS_TIMEOUT_SECONDS=10
# Optional OIDC discovery refresh tuning. HTTP is allowed only for localhost when explicitly enabled.
# EVYDENCE_OIDC_DISCOVERY_TIMEOUT_SECONDS=10
# EVYDENCE_OIDC_DISCOVERY_ALLOW_INSECURE_LOCALHOST=false
# Optional OIDC UserInfo live validation tuning. HTTP is allowed only for localhost when explicitly enabled.
# EVYDENCE_OIDC_USERINFO_TIMEOUT_SECONDS=10
# EVYDENCE_OIDC_USERINFO_ALLOW_INSECURE_LOCALHOST=false
# Optional public transparency proof fetch tuning. HTTP is allowed only for localhost when explicitly enabled.
# EVYDENCE_TRANSPARENCY_FETCH_TIMEOUT_SECONDS=10
# EVYDENCE_TRANSPARENCY_FETCH_ALLOW_INSECURE_LOCALHOST=false
# For MinIO/S3, set EVYDENCE_OBJECT_STORE=minio and provide:
# EVYDENCE_S3_ENDPOINT=localhost:9000
# EVYDENCE_S3_BUCKET=evydence
Expand Down
49 changes: 49 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
.git
.github
.refs
.trash

# Local secrets and environment overrides. Keep examples in git, but do not
# send operator-specific values into Docker build contexts.
.env
.env.*
.api.env
.api.env.*
.test.env
.test.env.*
*.pem
*.key
*.p12
*.pfx

# Release, backup, and generated evidence artifacts.
release-evidence
release-evidence/
backups
backups/
coverage.out
*.prof
*.pprof
*.test

# Build output and temporary files.
bin
bin/
dist
dist/
tmp
tmp/
__pycache__
**/__pycache__

# SDK build artifacts.
sdk/typescript/.build
sdk/typescript/node_modules
sdk/python/**/__pycache__

# Terraform local state/cache.
.terraform
**/.terraform
.terraform.lock.hcl
*.tfstate
*.tfstate.*
35 changes: 35 additions & 0 deletions .github/ISSUE_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# Issue Intake

Use the structured issue forms when GitHub shows them. This fallback template is
for clients that do not render issue forms.

Before posting, remove API keys, collector secrets, bearer tokens, session
tokens, portal tokens, private keys, provider credentials, database URLs,
raw evidence payloads, customer data, exploit payloads against third-party
systems, and unredacted customer package contents.

Security vulnerabilities should not be reported in public issues. Use GitHub
private vulnerability reporting when available, or follow `SECURITY.md` to
request a private intake channel without including vulnerability details in the
first contact.

## Summary

Describe the bug, documentation gap, feature request, or production-support
question.

## Environment

- Evydence commit, tag, or image digest:
- Deployment profile:
- PostgreSQL/object-store mode:
- Relevant command or endpoint:

## Evidence

List sanitized logs, commands, request IDs, report IDs, or reproduction steps.
Do not attach raw tenant evidence or secrets.

## Expected Outcome

Describe the result you expected and the result you observed.
69 changes: 69 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
name: Bug report
description: Report a reproducible Evydence defect without sharing secrets or raw evidence.
title: "bug: "
labels: ["bug", "triage"]
body:
- type: markdown
attributes:
value: |
Do not include API keys, bearer tokens, session tokens, private keys,
provider credentials, database URLs, raw evidence payloads, customer
data, or unredacted customer package contents. Use the private security
intake in SECURITY.md for suspected vulnerabilities.
- type: input
id: version
attributes:
label: Version or commit
description: Commit SHA, tag, image digest, or chart version.
placeholder: 842fb053f303b2a78eb3118be6a4536715571215
validations:
required: true
- type: dropdown
id: area
attributes:
label: Area
options:
- API
- CLI
- Worker/outbox
- PostgreSQL/migrations
- Object storage
- Signing/verification
- Reports/packages
- Deployment/Helm/Docker
- Documentation
- Other
validations:
required: true
- type: textarea
id: expected
attributes:
label: Expected behavior
validations:
required: true
- type: textarea
id: observed
attributes:
label: Observed behavior
description: Sanitize logs and redact sensitive values.
validations:
required: true
- type: textarea
id: reproduce
attributes:
label: Reproduction steps
description: Include exact commands, API paths, or configuration names when safe.
validations:
required: true
- type: textarea
id: validation
attributes:
label: Checks already run
placeholder: make test, make docs-check, make production-check
- type: checkboxes
id: safety
attributes:
label: Safety confirmation
options:
- label: I have not included secrets, raw evidence payloads, private keys, bearer tokens, provider credentials, database URLs, or customer data.
required: true
8 changes: 8 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
blank_issues_enabled: false
contact_links:
- name: Security vulnerability
url: https://github.com/aatuh/evydence/security
about: Use the private security intake described in SECURITY.md. Do not post suspected vulnerabilities publicly.
- name: Support policy
url: https://github.com/aatuh/evydence/blob/master/SUPPORT.md
about: Read support boundaries and sanitized-report expectations before opening an issue.
30 changes: 30 additions & 0 deletions .github/ISSUE_TEMPLATE/docs.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: Documentation issue
description: Report unclear, stale, missing, or misleading documentation.
title: "docs: "
labels: ["documentation", "triage"]
body:
- type: input
id: path
attributes:
label: Document path
placeholder: docs/tutorials/getting-started.md
validations:
required: true
- type: textarea
id: problem
attributes:
label: What is wrong or missing?
description: Include the exact command, section, or expectation that did not match reality.
validations:
required: true
- type: textarea
id: fix
attributes:
label: Suggested correction
- type: checkboxes
id: claims
attributes:
label: Claim safety
options:
- label: This issue does not ask Evydence to claim legal compliance, certification, complete SBOM coverage, authoritative scanner results, or secure releases.
required: true
47 changes: 47 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
name: Feature request
description: Propose a focused Evydence capability or integration.
title: "feat: "
labels: ["enhancement", "triage"]
body:
- type: textarea
id: problem
attributes:
label: Problem
description: What release-evidence, compliance-readiness, or operator workflow is blocked?
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed behavior
description: Describe the smallest useful capability.
validations:
required: true
- type: dropdown
id: boundary
attributes:
label: Trust boundary affected
options:
- API
- Tenant isolation/authz
- File upload/object storage
- Signing/verification
- Provider/collector integration
- Reports/packages/exports
- Deployment/operations
- Documentation only
- Other
validations:
required: true
- type: textarea
id: validation
attributes:
label: Acceptance test idea
description: What command, API flow, or report would prove the feature works?
- type: checkboxes
id: scope
attributes:
label: Scope confirmation
options:
- label: This request supports compliance readiness or technical evidence organization without asking for legal compliance, certification, or secure-release guarantees.
required: true
41 changes: 41 additions & 0 deletions .github/ISSUE_TEMPLATE/production_support.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: Production support question
description: Ask a non-sensitive self-hosting or operations question.
title: "ops: "
labels: ["operations", "triage"]
body:
- type: markdown
attributes:
value: |
Public issues are not a private support channel. Do not include secrets,
raw evidence payloads, customer data, private keys, bearer tokens,
database URLs, or provider credentials.
- type: dropdown
id: profile
attributes:
label: Deployment profile
options:
- Local evaluation
- Controlled internal self-hosted candidate
- Air-gapped self-hosted candidate
- Regulated self-hosted review
- Other
validations:
required: true
- type: textarea
id: question
attributes:
label: Question
validations:
required: true
- type: textarea
id: sanitized_config
attributes:
label: Sanitized configuration summary
description: Use variable names and redacted values only.
- type: checkboxes
id: safety
attributes:
label: Safety confirmation
options:
- label: I have redacted all secrets, raw payloads, customer data, bearer tokens, private keys, provider credentials, and database URLs.
required: true
26 changes: 26 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
version: 2
updates:
- package-ecosystem: gomod
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 5
labels:
- dependencies
- go
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 5
labels:
- dependencies
- github-actions
- package-ecosystem: docker
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 5
labels:
- dependencies
- docker
33 changes: 33 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# Pull Request

## Summary

-

## Change Type

- [ ] Documentation
- [ ] Tooling
- [ ] API contract
- [ ] Persistence/data
- [ ] Security/authz/session/secret handling
- [ ] Deployment/operations
- [ ] Refactor

## Security And Evidence Invariants

Confirm the change preserves tenant isolation, append-only evidence behavior,
safe errors/logs, conservative product language, and no compliance,
certification, complete-SBOM, scanner-authority, or secure-release claims.

## Validation

List the exact commands run and their results. Include skipped checks with the
reason.

## Sensitive Data Check

Confirm the PR does not include API keys, collector secrets, bearer tokens,
session tokens, portal tokens, private keys, provider credentials, database
URLs, raw evidence payloads, customer data, or unredacted customer package
contents.
Loading