Skip to content

Commit cafa5cb

Browse files
sumitakeclaude
andauthored
Phase 1: public repository foundation (toolchains, schemas, sanitizer, CI, release, governance) (#4)
* build: scaffold public foundation toolchains Pinned Go 1.26.5 (with actionlint/govulncheck/staticcheck/shfmt tool directives) and an npm workspace (Node 24.18.0/npm 12.0.1) with the single 'worker' member. Adds the buildinfo Go seam and the heartbeat protocol-version worker seam, both test-covered, plus editor/git/lint config and registered image/deploy placeholders (network broker split into parser and dialer per the reviewed architecture). No operational runtime. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * config: define synthetic public contracts Draft 2020-12 closed schemas + synthetic examples for fleet, host-profile, public-log-event, and notification-event, with an Ajv2020 strict/all-errors validator (validateFile) and TDD coverage (4 positive + 11 negative cases). The fleet schema requires all eight enumerated blocked-egress classes, per-repository concurrency maxima and archive-eligibility state, secret-reference names only, and the fixed evaluation/stale/unhealthy gates. Examples use synthetic values only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * security: enforce public-source sanitization Fail-closed public-source scanner (Python stdlib only) blocking deployment identifiers, secrets, non-synthetic IPs/domains/paths, and PII from the public repo, built against an adversarial-reviewed spec (Gemini+Grok, 2 rounds, 19 bypass classes). Covers public + special-use IPs via mathematical subnet membership on a shared normalizer, a vendor token/key table, RFC-3986 URI authority parsing, a bounded multi-alphabet decode-and-recheck (base64/base32/ base64url/hex, embedded content re-scanned with the full rule set), archive recursion by magic bytes, git history+metadata, LFS/submodule policy, a closed canonical-exception table, and an exact-content-hash allowlist (no path-exclude). Free-text PII is a documented residual requiring the local --private-denylist pre-publish scan. 117 tests; gitleaks defaults included. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * community: add public governance baseline SECURITY (GitHub private vulnerability reporting only), CONTRIBUTING (TDD, synthetic fixtures, signed commits, full-SHA action pins, hosted CI), Code of Conduct, changelog, third-party-notices placeholder, CODEOWNERS (* @sumitake), PR public-safety checklist, and structured issue forms — plus a stdlib metadata checker and tests. All public-safe and sanitizer-clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: add public architecture, trust, operations, and README Public-safe summaries of the reviewed design: architecture overview + trust boundaries, five operations runbooks (lifecycle, deployment/rollback, failover/ notifications, workflow migration, operations), and a pre-deployment README with a generic diagram. Deterministic link/anchor + operator-command checkers and docs-contract tests enforce heading order and reject unqualified live/verified claims. Synthetic values only; sanitizer-clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci: add stable hosted checks Five stable hosted CI contexts (go, worker, shell, repository-metadata, container) on ubuntu-24.04 with least-privilege permissions, timeouts, concurrency cancellation, persist-credentials:false, and full-SHA-pinned actions; a fail-closed workflow-policy checker (stdlib, restricted YAML parser) enforcing the pin table and trigger/runner/permission rules; and a manifest-driven image check (empty phase-1 manifest passes). Also enables the checks repo-wide: adds tests/**/__init__.py so unittest discovery finds all suites, and a .prettierignore + formatting pass so format:check is clean (design docs stay markdownlint-managed). 247 Python tests + 16 bats green; actionlint and the policy checker report exactly the five unique contexts. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * security: add hosted analysis and dependency automation Sanitization (Gitleaks over branch range on PRs, full history on push/schedule, plus sanitize_public.py --tracked always and --history on the release-gate events), CodeQL (go + javascript-typescript, GitHub-hosted, security-events), and PR dependency-review (fail on high severity + copyleft denylist) workflows, and Dependabot for actions/gomod/npm + docker across all six image dirs, no Renovate. Also fixes a latent policy-checker bug: subpath actions (e.g. github/codeql-action/init) are now pinned by their owning repo's reviewed SHA. Seven unique stable contexts; 252 tests green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ops: codify secure repository settings Non-executed bootstrap tooling: configure.sh --check (read-only) / --apply-foundation / --apply-ruleset, using GitHub REST API 2026-03-10 with read-back on every mutation. Foundation mode sets read-only workflow token, a narrow selected-actions allowlist, merge/security settings; ruleset mode first proves all seven contexts succeeded on the exact PR head SHA, then creates an active main ruleset (PRs, resolved conversations, linear history, signed commits, no deletion/force-push, six required checks) with a sole-maintainer zero-approval mode. 21 bats tests via a stub gh — no real API mutation — plus the two-stage runbook. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * release: add SBOM and provenance pipeline Deterministic source packager (git archive + commit-derived SOURCE_DATE_EPOCH + gzip -n, clean-tree + version + manifest + symlink-escape gates) producing one byte-identical tarball; a manifest restricting release subjects to the source archive; and a tag-triggered release workflow running the full seven-check suite, Trivy source/dist scans, archive-member sanitization, an Anchore SPDX SBOM, a third-party license inventory, SHA-256 checksums, pinned actions/attest provenance, and an immutable release upload (contents/id-token/attestations write only). Adds the release job id to the workflow-context test. 14 bats tests; reproducible-build verified. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test: close foundation verification gaps Full-matrix gate correction: prettier-format the repository-bootstrap runbook so format:check is clean across the tree. All seven stable contexts, the go/worker/ shell/repository-metadata/container/sanitization/dependency-review suites, the reproducible source package (byte-identical), Trivy HIGH/CRITICAL, signed-commit, and sanitizer gates pass. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1 parent c80d59a commit cafa5cb

89 files changed

Lines changed: 15668 additions & 2 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.dockerignore‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
.git/
2+
node_modules/
3+
dist/
4+
coverage/
5+
.wrangler/
6+
.env
7+
.env.*
8+
*.pem
9+
*.key
10+
private-overlay/
11+
*.local.*
12+
state/
13+
.DS_Store

‎.editorconfig‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
root = true
2+
3+
[*]
4+
charset = utf-8
5+
end_of_line = lf
6+
insert_final_newline = true
7+
trim_trailing_whitespace = true
8+
indent_style = space
9+
indent_size = 2
10+
11+
[*.go]
12+
indent_style = tab
13+
14+
[Makefile]
15+
indent_style = tab

‎.gitattributes‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
* text=auto eol=lf
2+
*.go text eol=lf
3+
*.sh text eol=lf
4+
*.png binary
5+
*.gz binary

‎.github/CODEOWNERS‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
* @sumitake

‎.github/ISSUE_TEMPLATE/bug.yml‎

Lines changed: 86 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,86 @@
1+
name: Bug report
2+
description: Report unexpected or incorrect behavior in Portable GHAR.
3+
title: "[bug]: "
4+
labels:
5+
- bug
6+
body:
7+
- type: markdown
8+
attributes:
9+
value: |
10+
Thanks for taking the time to file a bug report.
11+
12+
**Do not paste real logs, real configuration, real runtime state,
13+
hostnames, IP addresses, tokens, or any other deployment-specific
14+
detail into this form.** This repository and every issue on it are
15+
public. Use the synthetic placeholders described in
16+
[CONTRIBUTING.md](../../CONTRIBUTING.md) instead (for example
17+
`owner/repository`, `example-fleet`, `operator@example.invalid`).
18+
If you are reporting a security vulnerability instead of a bug,
19+
stop here and use
20+
[private vulnerability reporting](../../SECURITY.md) instead of
21+
this form.
22+
- type: textarea
23+
id: what-happened
24+
attributes:
25+
label: What happened?
26+
description: >-
27+
Describe the bug using synthetic examples only. Do not paste real
28+
logs, configuration, or runtime state.
29+
placeholder: >-
30+
Use sanitized, synthetic examples (e.g. owner/repository,
31+
example-fleet, operator@example.invalid).
32+
validations:
33+
required: true
34+
- type: textarea
35+
id: expected
36+
attributes:
37+
label: What did you expect to happen?
38+
description: A synthetic description of the expected behavior.
39+
validations:
40+
required: true
41+
- type: textarea
42+
id: repro
43+
attributes:
44+
label: Steps to reproduce
45+
description: >-
46+
Minimal reproduction steps using synthetic fixtures, config, or
47+
commands only -- never a real deployment's logs, config, or state.
48+
placeholder: |
49+
1. ...
50+
2. ...
51+
3. ...
52+
validations:
53+
required: true
54+
- type: input
55+
id: version
56+
attributes:
57+
label: Version / commit
58+
description: The tagged version or commit SHA you observed this on.
59+
placeholder: e.g. v0.1.0 or a full commit SHA
60+
validations:
61+
required: false
62+
- type: dropdown
63+
id: component
64+
attributes:
65+
label: Affected component
66+
options:
67+
- Build / toolchain
68+
- Config schemas
69+
- Sanitization tooling
70+
- CI / workflows
71+
- Documentation
72+
- Other
73+
validations:
74+
required: true
75+
- type: checkboxes
76+
id: acknowledgements
77+
attributes:
78+
label: Acknowledgements
79+
options:
80+
- label: >-
81+
I confirm this report contains no real logs, configuration,
82+
runtime state, secrets, or deployment identifiers -- synthetic
83+
examples only.
84+
required: true
85+
- label: This is not a security vulnerability report.
86+
required: true

‎.github/ISSUE_TEMPLATE/config.yml‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
blank_issues_enabled: false
2+
contact_links:
3+
- name: Report a security vulnerability
4+
url: https://github.com/sumitake/portable-ghar/security/advisories/new
5+
about: >-
6+
Please do not open a public issue for security vulnerabilities. Use
7+
GitHub private vulnerability reporting instead -- see SECURITY.md.

‎.github/ISSUE_TEMPLATE/feature.yml‎

Lines changed: 66 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,66 @@
1+
name: Feature request
2+
description: Suggest an idea or enhancement for Portable GHAR.
3+
title: "[feature]: "
4+
labels:
5+
- enhancement
6+
body:
7+
- type: markdown
8+
attributes:
9+
value: |
10+
Thanks for suggesting an improvement.
11+
12+
**Do not paste real logs, real configuration, real runtime state,
13+
hostnames, IP addresses, tokens, or any other deployment-specific
14+
detail into this form.** This repository and every issue on it are
15+
public. Use the synthetic placeholders described in
16+
[CONTRIBUTING.md](../../CONTRIBUTING.md) instead (for example
17+
`owner/repository`, `example-fleet`, `operator@example.invalid`).
18+
- type: textarea
19+
id: problem
20+
attributes:
21+
label: What problem does this solve?
22+
description: >-
23+
Describe the problem or gap using synthetic examples only. Do not
24+
paste real logs, configuration, or runtime state.
25+
placeholder: >-
26+
Use sanitized, synthetic examples (e.g. owner/repository,
27+
example-fleet, operator@example.invalid).
28+
validations:
29+
required: true
30+
- type: textarea
31+
id: proposal
32+
attributes:
33+
label: Proposed solution
34+
description: What would you like to see happen?
35+
validations:
36+
required: true
37+
- type: textarea
38+
id: alternatives
39+
attributes:
40+
label: Alternatives considered
41+
description: Any alternative approaches you considered and why you didn't pick them.
42+
validations:
43+
required: false
44+
- type: dropdown
45+
id: component
46+
attributes:
47+
label: Affected component
48+
options:
49+
- Build / toolchain
50+
- Config schemas
51+
- Sanitization tooling
52+
- CI / workflows
53+
- Documentation
54+
- Other
55+
validations:
56+
required: true
57+
- type: checkboxes
58+
id: acknowledgements
59+
attributes:
60+
label: Acknowledgements
61+
options:
62+
- label: >-
63+
I confirm this request contains no real logs, configuration,
64+
runtime state, secrets, or deployment identifiers -- synthetic
65+
examples only.
66+
required: true

‎.github/PULL_REQUEST_TEMPLATE.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
## Summary
2+
3+
<!-- What does this change do, and why? -->
4+
5+
## Test plan
6+
7+
<!-- How did you verify this? List the exact commands you ran. -->
8+
9+
- [ ] `python3 -m unittest discover -s tests -p 'test_*.py'` passes
10+
- [ ] Relevant new tests were written FIRST and observed to fail (TDD)
11+
12+
## PUBLIC-SAFETY checklist
13+
14+
This repository is public. Please confirm every item below before
15+
requesting review -- a reviewer cannot always tell from a diff alone
16+
whether a value is real or synthetic.
17+
18+
- [ ] This PR contains **no deployment identifiers** (account IDs, zone
19+
IDs, tunnel IDs, installation/client/app IDs, or any other
20+
environment-specific identifier).
21+
- [ ] This PR contains **no secrets** (tokens, keys, credentials,
22+
passwords, or anything secret-shaped), real or expired.
23+
- [ ] This PR contains **no real logs, real configuration, or real
24+
runtime state** -- only synthetic examples (see CONTRIBUTING.md for
25+
the placeholder conventions, e.g. `owner/repository`,
26+
`example-fleet`, `operator@example.invalid`).
27+
- [ ] I ran `python3 scripts/sanitize_public.py --tracked` locally and it
28+
reported `sanitization passed`.
29+
- [ ] I ran `python3 scripts/check_repository_metadata.py` locally (if
30+
this PR touches governance/repository metadata) and it exited 0.
31+
32+
## Additional context
33+
34+
<!-- Anything else a reviewer should know. -->

‎.github/dependabot.yml‎

Lines changed: 100 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,100 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: "github-actions"
4+
directory: "/"
5+
schedule:
6+
interval: "weekly"
7+
open-pull-requests-limit: 5
8+
groups:
9+
actions-minor-patch:
10+
update-types:
11+
- "minor"
12+
- "patch"
13+
14+
- package-ecosystem: "gomod"
15+
directory: "/"
16+
schedule:
17+
interval: "weekly"
18+
open-pull-requests-limit: 5
19+
groups:
20+
gomod-minor-patch:
21+
update-types:
22+
- "minor"
23+
- "patch"
24+
25+
- package-ecosystem: "npm"
26+
directory: "/"
27+
schedule:
28+
interval: "weekly"
29+
open-pull-requests-limit: 5
30+
groups:
31+
npm-minor-patch:
32+
update-types:
33+
- "minor"
34+
- "patch"
35+
36+
- package-ecosystem: "docker"
37+
directory: "/images/runner"
38+
schedule:
39+
interval: "weekly"
40+
open-pull-requests-limit: 3
41+
groups:
42+
docker-runner-minor-patch:
43+
update-types:
44+
- "minor"
45+
- "patch"
46+
47+
- package-ecosystem: "docker"
48+
directory: "/images/network-adapter"
49+
schedule:
50+
interval: "weekly"
51+
open-pull-requests-limit: 3
52+
groups:
53+
docker-network-adapter-minor-patch:
54+
update-types:
55+
- "minor"
56+
- "patch"
57+
58+
- package-ecosystem: "docker"
59+
directory: "/images/network-broker-parser"
60+
schedule:
61+
interval: "weekly"
62+
open-pull-requests-limit: 3
63+
groups:
64+
docker-network-broker-parser-minor-patch:
65+
update-types:
66+
- "minor"
67+
- "patch"
68+
69+
- package-ecosystem: "docker"
70+
directory: "/images/network-broker-dialer"
71+
schedule:
72+
interval: "weekly"
73+
open-pull-requests-limit: 3
74+
groups:
75+
docker-network-broker-dialer-minor-patch:
76+
update-types:
77+
- "minor"
78+
- "patch"
79+
80+
- package-ecosystem: "docker"
81+
directory: "/images/network-helper"
82+
schedule:
83+
interval: "weekly"
84+
open-pull-requests-limit: 3
85+
groups:
86+
docker-network-helper-minor-patch:
87+
update-types:
88+
- "minor"
89+
- "patch"
90+
91+
- package-ecosystem: "docker"
92+
directory: "/images/network-verifier"
93+
schedule:
94+
interval: "weekly"
95+
open-pull-requests-limit: 3
96+
groups:
97+
docker-network-verifier-minor-patch:
98+
update-types:
99+
- "minor"
100+
- "patch"

0 commit comments

Comments
 (0)