From 6c8c3ad72c92779b606179857d3e821d846003ff Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E3=83=9E=E3=82=A4=E3=83=8E=E3=83=AB?= <97069334+MY-RV@users.noreply.github.com> Date: Sat, 19 Sep 2026 20:27:25 -0600 Subject: [PATCH 1/3] chore: relicense to MIT and drop release attestations Align with godo: MIT license, no provenance attestation step, and docs that promise checksums only. Fix release-local default version (was 0.2.0-dev). --- .github/workflows/release.yml | 9 -- .goreleaser.yaml | 2 +- CHANGELOG.md | 4 + LICENSE | 226 ++++------------------------------ README.md | 2 +- docs/dev/github-protection.md | 4 +- docs/distribution.md | 3 +- docs/guide/update.md | 3 - docs/install.md | 4 +- docs/release.md | 3 +- docs/roadmap.md | 2 +- docs/security.md | 1 - scripts/release-local.sh | 6 +- 13 files changed, 36 insertions(+), 233 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2993334..2636d09 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,9 +7,6 @@ on: permissions: contents: write - # Signed build provenance for every published artifact. - id-token: write - attestations: write jobs: release: @@ -33,9 +30,3 @@ jobs: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Optional: absent secret → tap/bucket push is skipped, not failed. TAP_GITHUB_TOKEN: ${{ secrets.TAP_GITHUB_TOKEN }} - - name: Attest build provenance - uses: actions/attest-build-provenance@v2 - with: - subject-path: | - dist/hensu_* - dist/checksums.txt diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 3b7e834..b08dc28 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -83,7 +83,7 @@ scoops: token: "{{ .Env.TAP_GITHUB_TOKEN }}" homepage: "https://github.com/MY-RV/hensu" description: "Machine-local config get/set/dump that agents can read without seeing values" - license: "Apache-2.0" + license: "MIT" skip_upload: '{{ if .Env.TAP_GITHUB_TOKEN }}false{{ else }}true{{ end }}' changelog: diff --git a/CHANGELOG.md b/CHANGELOG.md index 36cf1d1..6463804 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,10 @@ ## [Unreleased] +### Changed +- Relicensed to **MIT** (aligned with godo). Copies of `v0.1.0` remain under the Apache-2.0 grant they shipped with. +- Release workflow no longer publishes signed build provenance attestations (same shape as godo). Checksum verification for `--update` is unchanged. + ## [0.1.0] — 2026-09-19 ### Security diff --git a/LICENSE b/LICENSE index 702fbc4..38281b5 100644 --- a/LICENSE +++ b/LICENSE @@ -1,205 +1,21 @@ - - Apache License - Version 2.0, January 2004 - http://www.apache.org/licenses/ - - TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION - - 1. Definitions. - - "License" shall mean the terms and conditions for use, reproduction, - and distribution as defined by Sections 1 through 9 of this document. - - "Licensor" shall mean the copyright owner or entity authorized by - the copyright owner that is granting the License. - - "Legal Entity" shall mean the union of the acting entity and all - other entities that control, are controlled by, or are under common - control with that entity. For the purposes of this definition, - "control" means (i) the power, direct or indirect, to cause the - direction or management of such entity, whether by contract or - otherwise, or (ii) ownership of fifty percent (50%) or more of the - outstanding shares, or (iii) beneficial ownership of such entity. - - "You" (or "Your") shall mean an individual or Legal Entity - exercising permissions granted by this License. - - "Source" form shall mean the preferred form for making modifications, - including but not limited to software source code, documentation - source, and configuration files. - - "Object" form shall mean any form resulting from mechanical - transformation or translation of a Source form, including but - not limited to compiled object code, generated documentation, - and conversions to other media types. - - "Work" shall mean the work of authorship, whether in Source or - Object form, made available under the License, as indicated by a - copyright notice that is included in or attached to the work - (an example is provided in the Appendix below). - - "Derivative Works" shall mean any work, whether in Source or Object - form, that is based on (or derived from) the Work and for which the - editorial revisions, annotations, elaborations, or other modifications - represent, as a whole, an original work of authorship. For the purposes - of this License, Derivative Works shall not include works that remain - separable from, or merely link (or bind by name) to the interfaces of, - the Work and Derivative Works thereof. - - "Contribution" shall mean any work of authorship, including - the original version of the Work and any modifications or additions - to that Work or Derivative Works thereof, that is intentionally - submitted to Licensor for inclusion in the Work by the copyright owner - or by an individual or Legal Entity authorized to submit on behalf of - the copyright owner. For the purposes of this definition, "submitted" - means any form of electronic, verbal, or written communication sent - to the Licensor or its representatives, including but not limited to - communication on electronic mailing lists, source code control systems, - and issue tracking systems that are managed by, or on behalf of, the - Licensor for the purpose of discussing and improving the Work, but - excluding communication that is conspicuously marked or otherwise - designated in writing by the copyright owner as "Not a Contribution." - - "Contributor" shall mean Licensor and any individual or Legal Entity - on behalf of whom a Contribution has been received by Licensor and - subsequently incorporated within the Work. - - 2. Grant of Copyright License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - copyright license to reproduce, prepare Derivative Works of, - publicly display, publicly perform, sublicense, and distribute the - Work and such Derivative Works in Source or Object form. - - 3. Grant of Patent License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - (except as stated in this section) patent license to make, have made, - use, offer to sell, sell, import, and otherwise transfer the Work, - where such license applies only to those patent claims licensable - by such Contributor that are necessarily infringed by their - Contribution(s) alone or by combination of their Contribution(s) - with the Work to which such Contribution(s) was submitted. If You - institute patent litigation against any entity (including a - cross-claim or counterclaim in a lawsuit) alleging that the Work - or a Contribution incorporated within the Work constitutes direct - or contributory patent infringement, then any patent licenses - granted to You under this License for that Work shall terminate - as of the date such litigation is filed. - - 4. Redistribution. You may reproduce and distribute copies of the - Work or Derivative Works thereof in any medium, with or without - modifications, and in Source or Object form, provided that You - meet the following conditions: - - (a) You must give any other recipients of the Work or - Derivative Works a copy of this License; and - - (b) You must cause any modified files to carry prominent notices - stating that You changed the files; and - - (c) You must retain, in the Source form of any Derivative Works - that You distribute, all copyright, patent, trademark, and - attribution notices from the Source form of the Work, - excluding those notices that do not pertain to any part of - the Derivative Works; and - - (d) If the Work includes a "NOTICE" text file as part of its - distribution, then any Derivative Works that You distribute must - include a readable copy of the attribution notices contained - within such NOTICE file, excluding those notices that do not - pertain to any part of the Derivative Works, in at least one - of the following places: within a NOTICE text file distributed - as part of the Derivative Works; within the Source form or - documentation, if provided along with the Derivative Works; or, - within a display generated by the Derivative Works, if and - wherever such third-party notices normally appear. The contents - of the NOTICE file are for informational purposes only and - do not modify the License. You may add Your own attribution - notices within Derivative Works that You distribute, alongside - or as an addendum to the NOTICE text from the Work, provided - that such additional attribution notices cannot be construed - as modifying the License. - - You may add Your own copyright statement to Your modifications and - may provide additional or different license terms and conditions - for use, reproduction, or distribution of Your modifications, or - for any such Derivative Works as a whole, provided Your use, - reproduction, and distribution of the Work otherwise complies with - the conditions stated in this License. - - 5. Submission of Contributions. Unless You explicitly state otherwise, - any Contribution intentionally submitted for inclusion in the Work - by You to the Licensor shall be under the terms and conditions of - this License, without any additional terms or conditions. - Notwithstanding the above, nothing herein shall supersede or modify - the terms of any separate license agreement you may have executed - with Licensor regarding such Contributions. - - 6. Trademarks. This License does not grant permission to use the trade - names, trademarks, service marks, or product names of the Licensor, - except as required for reasonable and customary use in describing the - origin of the Work and reproducing the content of the NOTICE file. - - 7. Disclaimer of Warranty. Unless required by applicable law or - agreed to in writing, Licensor provides the Work (and each - Contributor provides its Contributions) on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or - implied, including, without limitation, any warranties or conditions - of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A - PARTICULAR PURPOSE. You are solely responsible for determining the - appropriateness of using or redistributing the Work and assume any - risks associated with Your exercise of permissions under this License. - - 8. Limitation of Liability. In no event and under no legal theory, - whether in tort (including negligence), contract, or otherwise, - unless required by applicable law (such as deliberate and grossly - negligent acts) or agreed to in writing, shall any Contributor be - liable to You for damages, including any direct, indirect, special, - incidental, or consequential damages of any character arising as a - result of this License or out of the use or inability to use the - Work (including but not limited to damages for loss of goodwill, - work stoppage, computer failure or malfunction, or any and all - other commercial damages or losses), even if such Contributor - has been advised of the possibility of such damages. - - 9. Accepting Warranty or Additional Liability. While redistributing - the Work or Derivative Works thereof, You may choose to offer, - and charge a fee for, acceptance of support, warranty, indemnity, - or other liability obligations and/or rights consistent with this - License. However, in accepting such obligations, You may act only - on Your own behalf and on Your sole responsibility, not on behalf - of any other Contributor, and only if You agree to indemnify, - defend, and hold each Contributor harmless for any liability - incurred by, or claims asserted against, such Contributor by reason - of your accepting any such warranty or additional liability. - - END OF TERMS AND CONDITIONS - - APPENDIX: How to apply the Apache License to your work. - - To apply the Apache License to your work, attach the following - boilerplate notice, with the fields enclosed by brackets "[]" - replaced with your own identifying information. (Don't include - the brackets!) The text should be enclosed in the appropriate - comment syntax for the file format. We also recommend that a - file or class name and description of purpose be included on the - same "printed page" as the copyright notice for easier - identification within third-party archives. - - Copyright 2026 MYRV - - Licensed under the Apache License, Version 2.0 (the "License"); - you may not use this file except in compliance with the License. - You may obtain a copy of the License at - - http://www.apache.org/licenses/LICENSE-2.0 - - Unless required by applicable law or agreed to in writing, software - distributed under the License is distributed on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - See the License for the specific language governing permissions and - limitations under the License. - - -Copyright 2026 MYRV +MIT License + +Copyright (c) 2026 MYRV + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md index 0bb52c8..4885397 100644 --- a/README.md +++ b/README.md @@ -42,4 +42,4 @@ go install github.com/my-rv/godo/cmd/godo@latest godo ci ``` -[Contributing](./CONTRIBUTING.md) · [Security](./SECURITY.md) · [Apache-2.0](./LICENSE) +[Contributing](./CONTRIBUTING.md) · [Security](./SECURITY.md) · [MIT](./LICENSE) diff --git a/docs/dev/github-protection.md b/docs/dev/github-protection.md index 6d34083..e8b59dc 100644 --- a/docs/dev/github-protection.md +++ b/docs/dev/github-protection.md @@ -21,7 +21,7 @@ Protect the `v*` pattern so a published version cannot be moved. Re-pointing a t ## Actions -The release workflow needs `contents: write` for the release itself, plus `id-token: write` and `attestations: write` for build provenance. Those are declared in the workflow, but the repository has to allow workflows to request them: Settings → Actions → General → Workflow permissions. +The release workflow needs `contents: write` (declared in the workflow). Settings → Actions → General → Workflow permissions must allow that. Add `TAP_GITHUB_TOKEN` as a repository secret — a PAT that can write to `MY-RV/homebrew-tap` and `MY-RV/scoop-bucket`. The built-in `GITHUB_TOKEN` cannot reach another repository. Without the secret the release still publishes; it just skips the cask and the manifest, leaving package users on the previous version. @@ -29,8 +29,6 @@ Add `TAP_GITHUB_TOKEN` as a repository secret — a PAT that can write to `MY-RV Enable private vulnerability reporting: Settings → Code security → Private vulnerability reporting. [SECURITY.md](../../SECURITY.md) points people at it, so it needs to exist before someone follows the instructions. -Dependabot alerts are worth having even for a module with this few dependencies — the ones it does have handle untrusted input. - ## Issues Both templates live in `.github/ISSUE_TEMPLATE/`. The bug one asks people not to paste real values, which matters more here than in most projects. diff --git a/docs/distribution.md b/docs/distribution.md index 730825d..1090698 100644 --- a/docs/distribution.md +++ b/docs/distribution.md @@ -28,10 +28,9 @@ The fully-qualified Homebrew name avoids clashing with unrelated taps. ```bash sha256sum -c checksums.txt --ignore-missing -gh attestation verify hensu_0.1.0_darwin_arm64 --repo MY-RV/hensu ``` -Every release artifact carries signed build provenance. `hensu --update` does the checksum half on its own and refuses a release that publishes none — see [install.md](./install.md). +`hensu --update` does that check on its own and refuses a release that publishes no checksums — see [install.md](./install.md). ## Not channels diff --git a/docs/guide/update.md b/docs/guide/update.md index eaca484..218b396 100644 --- a/docs/guide/update.md +++ b/docs/guide/update.md @@ -59,10 +59,7 @@ scoop update hensu ## Verifying by hand -Every release also carries signed build provenance, which is stronger than a checksum because it says *where the bytes were built*, not just that they did not change in transit: - ```bash -gh attestation verify hensu_0.1.1_darwin_arm64 --repo MY-RV/hensu sha256sum -c checksums.txt --ignore-missing ``` diff --git a/docs/install.md b/docs/install.md index 08d3f09..d8279d4 100644 --- a/docs/install.md +++ b/docs/install.md @@ -38,7 +38,7 @@ Tap and bucket are updated by GoReleaser on every release; available since `v0.1 - checksums in the release 2. Extract if needed, `chmod +x hensu`, move to `$PATH`. 3. Verify: `hensu --version`. -4. Verify provenance (optional): `gh attestation verify hensu___ --repo MY-RV/hensu` +4. Verify checksums: `sha256sum -c checksums.txt --ignore-missing` 5. Update later: `hensu --update` / `hensu --update-check` (requires public Releases; override: `HENSU_RELEASES_API`). `--update` compares SHA-256 against the release `checksums.txt` before replacing the binary. @@ -46,7 +46,7 @@ Tap and bucket are updated by GoReleaser on every release; available since `v0.1 ```bash ./scripts/release-local.sh -# o, si tenés godo en PATH: +# or, with godo on PATH: godo release-local ``` diff --git a/docs/release.md b/docs/release.md index 0563f19..652ef71 100644 --- a/docs/release.md +++ b/docs/release.md @@ -29,13 +29,12 @@ Output: `dist/hensu___` + `SHA256SUMS`. 1. `godo ci` green on `main` (on the remote, not only locally) 2. CHANGELOG with today's date 3. Annotated tag `vX.Y.Z` and push the tag -4. **release** workflow: gate (`godo ci`) → GoReleaser → archives, bare binaries and `checksums.txt` → Homebrew cask (`MY-RV/homebrew-tap`, `Casks/` directory) + Scoop bucket → provenance attestation +4. **release** workflow: gate (`godo ci`) → GoReleaser → archives, bare binaries and `checksums.txt` → Homebrew cask (`MY-RV/homebrew-tap`, `Casks/` directory) + Scoop bucket 5. Users: `brew`, `scoop`, direct download, `go install …@vX.Y.Z`, or `hensu --update` ## Verify a published artifact ```bash -gh attestation verify hensu_0.1.0_darwin_arm64 --repo MY-RV/hensu sha256sum -c checksums.txt --ignore-missing ``` diff --git a/docs/roadmap.md b/docs/roadmap.md index 734c3eb..69f42bb 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -7,7 +7,7 @@ What `v0.1` promises, what it does not, and what would have to be true for `v1.0 - The CLI contract in [contract.md](./contract.md): flags, commands, reveal modes, exit codes, key canonicalization, the `# FORMAT:` header. - `peek` as the default, and `trust` as the only way to raw output. - Atomic, locked, comment-preserving writes at mode `0600`. -- Checksum-verified `--update`, and signed provenance on every release artifact. +- Checksum-verified `--update`. ## Not promised in v0.1 diff --git a/docs/security.md b/docs/security.md index ae3e343..56f4fb7 100644 --- a/docs/security.md +++ b/docs/security.md @@ -11,7 +11,6 @@ Hensu reads and writes **machine-local config files** that often contain secrets | Concurrent writers | Lost updates / torn files | Sidecar flock (`*.hensu-lock`) + atomic rename | | Path confusion | Writing the wrong file | Explicit `--file`; default is cwd `./.env` only | | Self-update channel | Tampered or wrong binary replacing Hensu | SHA-256 checked against the release `checksums.txt`; no checksums → refuse | -| Released artifacts | Unverifiable provenance | Signed build provenance attestations on every release | | Lock sidecar | Extra file next to config | Expected; mode `0600`; do not delete while processes may wait | ## The default is not to show diff --git a/scripts/release-local.sh b/scripts/release-local.sh index 03fabff..d631010 100755 --- a/scripts/release-local.sh +++ b/scripts/release-local.sh @@ -2,7 +2,7 @@ # Build release-like artifacts locally (no GitHub upload). # Usage: # ./scripts/release-local.sh -# VERSION=v0.2.0 ./scripts/release-local.sh +# VERSION=v0.1.0 ./scripts/release-local.sh set -euo pipefail ROOT="$(cd "$(dirname "$0")/.." && pwd)" cd "$ROOT" @@ -12,9 +12,9 @@ if [[ -z "$VERSION" ]]; then if VERSION=$(git describe --tags --exact-match 2>/dev/null); then : elif VERSION=$(git describe --tags --always --dirty 2>/dev/null); then - VERSION="0.2.0-dev+${VERSION}" + VERSION="0.1.0-dev+${VERSION}" else - VERSION="0.2.0-dev" + VERSION="0.1.0-dev" fi fi VERSION="${VERSION#v}" From 90509ac7d1bde19eb589c4dee6f6b3f645320dea Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E3=83=9E=E3=82=A4=E3=83=8E=E3=83=AB?= <97069334+MY-RV@users.noreply.github.com> Date: Sat, 19 Sep 2026 20:34:01 -0600 Subject: [PATCH 2/3] chore: release v0.1.1 --- pkg.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkg.go b/pkg.go index ee5efb5..3c0d2b5 100644 --- a/pkg.go +++ b/pkg.go @@ -12,7 +12,7 @@ import "github.com/my-rv/hensu/internal/store" // Version identifies the module/CLI. Override at link time: // // -ldflags "-X github.com/my-rv/hensu.Version=1.2.3" -var Version = "0.1.0" +var Version = "0.1.1" type ( Format = store.Format From e383f91a6b64881d036c988980bed5f7aac7dd2f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E3=83=9E=E3=82=A4=E3=83=8E=E3=83=AB?= <97069334+MY-RV@users.noreply.github.com> Date: Sat, 19 Sep 2026 20:34:26 -0600 Subject: [PATCH 3/3] docs: record v0.1.1 changelog --- CHANGELOG.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 6463804..3b6f156 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## [Unreleased] +## [0.1.1] — 2026-09-19 + ### Changed - Relicensed to **MIT** (aligned with godo). Copies of `v0.1.0` remain under the Apache-2.0 grant they shipped with. - Release workflow no longer publishes signed build provenance attestations (same shape as godo). Checksum verification for `--update` is unchanged.