diff --git a/.bestpractices.json b/.bestpractices.json new file mode 100644 index 0000000..3b14dc5 --- /dev/null +++ b/.bestpractices.json @@ -0,0 +1,32 @@ +{ + "osps_do_01_01": "Met", + "osps_do_01_01_justification": "Install, usage and safety semantics are documented in README.md and docs/USAGE.md.", + "osps_do_02_01": "Met", + "osps_do_02_01_justification": "Defects use repository issue templates and SUPPORT.md.", + "osps_gv_02_01": "Met", + "osps_gv_02_01_justification": "Public issues and pull requests are enabled.", + "osps_gv_03_01": "Met", + "osps_gv_03_01_justification": "See https://github.com/gexiro-global/forgeguard/blob/main/CONTRIBUTING.md", + "osps_le_02_01": "Met", + "osps_le_02_01_justification": "Apache-2.0 source license.", + "osps_le_02_02": "Met", + "osps_le_02_02_justification": "Release packaging includes the Apache-2.0 license.", + "osps_le_03_01": "Met", + "osps_le_03_01_justification": "See https://github.com/gexiro-global/forgeguard/blob/main/LICENSE", + "osps_le_03_02": "Met", + "osps_le_03_02_justification": "The license is included in source distributions and wheels.", + "osps_qa_01_01": "Met", + "osps_qa_01_01_justification": "Canonical public source: https://github.com/gexiro-global/forgeguard", + "osps_qa_01_02": "Met", + "osps_qa_01_02_justification": "GitHub publishes the repository commit history.", + "osps_qa_02_01": "Met", + "osps_qa_02_01_justification": "Direct dependencies are declared in pyproject.toml.", + "osps_qa_04_01": "N/A", + "osps_qa_04_01_justification": "ForgeGuard is a single-repository project.", + "osps_qa_05_01": "Met", + "osps_qa_05_01_justification": "Generated executables are built in CI and not committed.", + "osps_qa_05_02": "Met", + "osps_qa_05_02_justification": "Tracked images are documentation/brand assets, not executable binaries.", + "osps_vm_02_01": "Met", + "osps_vm_02_01_justification": "See https://github.com/gexiro-global/forgeguard/blob/main/SECURITY.md" +} diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000..fb481f3 --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,19 @@ +name: Dependency review + +on: + pull_request: + +permissions: + contents: read + +jobs: + review: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Check out repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Review dependency changes + uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 + with: + fail-on-severity: high diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml new file mode 100644 index 0000000..30ecaa3 --- /dev/null +++ b/.github/workflows/scorecard.yml @@ -0,0 +1,42 @@ +name: OpenSSF Scorecard + +on: + branch_protection_rule: + schedule: + - cron: "43 5 * * 3" + push: + branches: [main] + +permissions: read-all + +jobs: + analysis: + name: Scorecard analysis + runs-on: ubuntu-latest + timeout-minutes: 15 + permissions: + contents: read + security-events: write + id-token: write + steps: + - name: Check out repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Run OpenSSF Scorecard + uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3 + with: + results_file: results.sarif + results_format: sarif + publish_results: true + - name: Preserve SARIF result + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: openssf-scorecard-sarif + path: results.sarif + retention-days: 5 + if-no-files-found: error + - name: Upload SARIF to code scanning + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + with: + sarif_file: results.sarif diff --git a/GOVERNANCE.md b/GOVERNANCE.md new file mode 100644 index 0000000..e663d79 --- /dev/null +++ b/GOVERNANCE.md @@ -0,0 +1,5 @@ +# Governance + +ForgeGuard is maintained by Gexiro Global Enterprises Ltd. The maintainer reviews issues and pull requests, decides scope and releases, and may reject changes that add unauthorized discovery, exploit behavior, state-changing probes or ambiguous PASS conclusions. + +Changes are proposed through GitHub pull requests and must pass CI. The current single-maintainer structure is disclosed in [MAINTAINERS.md](MAINTAINERS.md); no independent review, response-time guarantee or certification is claimed. diff --git a/MAINTAINERS.md b/MAINTAINERS.md new file mode 100644 index 0000000..ba56d32 --- /dev/null +++ b/MAINTAINERS.md @@ -0,0 +1,7 @@ +# Maintainers + +| Maintainer | Role | Contact | +|---|---|---| +| `@dzeusking-dev` | Project owner and release maintainer | [GitHub](https://github.com/dzeusking-dev) | + +Security reports must use [SECURITY.md](SECURITY.md), not public issues. diff --git a/README.md b/README.md index 20796de..7f6969c 100644 --- a/README.md +++ b/README.md @@ -5,6 +5,8 @@ [![Python](https://img.shields.io/pypi/pyversions/forgeguard.svg)](https://pypi.org/project/forgeguard/) [![License: Apache-2.0](https://img.shields.io/pypi/l/forgeguard.svg)](https://github.com/gexiro-global/forgeguard/blob/main/LICENSE) +[Security and trust evidence](docs/SECURITY-TRUST.md) documents the project's policies and automated checks. No certification or badge level is claimed. + Read-only security posture self-check for one explicitly authorized self-hosted Gitea instance. ForgeGuard gives Gitea operators repeatable evidence about version posture, the fixed-version baseline for CVE-2026-27771, anonymous OCI registry-root behavior, and anonymous responses on a small allowlist of repository/API paths. It uses no exploit probes, performs no internet-wide discovery, and does not request private package contents, manifests, or blobs. diff --git a/SUPPORT.md b/SUPPORT.md new file mode 100644 index 0000000..ce47da3 --- /dev/null +++ b/SUPPORT.md @@ -0,0 +1,5 @@ +# Support + +Use [GitHub Issues](https://github.com/gexiro-global/forgeguard/issues) for reproducible defects and usage questions. Include the ForgeGuard and Python versions and a synthetic or redacted reproduction against a system you are authorized to assess. + +Security vulnerabilities belong in a private report under [SECURITY.md](SECURITY.md). Do not publish credentials, private endpoints or third-party data. diff --git a/docs/SECURITY-TRUST.md b/docs/SECURITY-TRUST.md new file mode 100644 index 0000000..aff7c41 --- /dev/null +++ b/docs/SECURITY-TRUST.md @@ -0,0 +1,11 @@ +# Security and trust evidence + +This page is an evidence index, not a certification. The evidence does not prove the project is vulnerability-free, does not establish a SLSA level, and does not imply OpenSSF affiliation or endorsement. Tool output describes observed posture; it is not proof of compromise or absence of compromise. + +- [Security policy](../SECURITY.md), [security model](SECURITY_MODEL.md) and [authorized-use boundary](../AUTHORIZED_USE.md) +- [Contribution process](../CONTRIBUTING.md), [governance](../GOVERNANCE.md), [maintainers](../MAINTAINERS.md) and [support](../SUPPORT.md) +- CI runs lint, format, compile, tests, dependency checks and exact-wheel smoke checks. +- GitHub default CodeQL setup is active; dependency review, Dependabot, secret scanning and OpenSSF Scorecard supplement it. +- Third-party actions are pinned to immutable commit SHAs with version comments. + +The Scorecard badge is intentionally withheld until a successful default-branch run has produced a public API result. `.bestpractices.json` contains evidence-backed automation proposals only; it is not an OpenSSF Best Practices or OSPS Baseline claim. A human must review any badge submission. diff --git a/security-insights.yml b/security-insights.yml new file mode 100644 index 0000000..7465f8e --- /dev/null +++ b/security-insights.yml @@ -0,0 +1,57 @@ +header: + schema-version: 2.2.0 + last-updated: '2026-09-04' + last-reviewed: '2026-09-04' + url: https://raw.githubusercontent.com/gexiro-global/forgeguard/main/security-insights.yml + comment: This single-repository file reports current practices and makes no certification claim. +project: + name: ForgeGuard + homepage: https://gexiro.com/forgeguard + administrators: + - name: dzeusking-dev + affiliation: Gexiro Global Enterprises Ltd. + social: https://github.com/dzeusking-dev + primary: true + documentation: + quickstart-guide: https://github.com/gexiro-global/forgeguard#quickstart + detailed-guide: https://github.com/gexiro-global/forgeguard/blob/main/docs/USAGE.md + code-of-conduct: https://github.com/gexiro-global/forgeguard/blob/main/CODE_OF_CONDUCT.md + support-policy: https://github.com/gexiro-global/forgeguard/blob/main/SUPPORT.md + repositories: + - name: forgeguard + url: https://github.com/gexiro-global/forgeguard + comment: Canonical source and release repository. + vulnerability-reporting: + reports-accepted: true + bug-bounty-available: false + policy: https://github.com/gexiro-global/forgeguard/blob/main/SECURITY.md +repository: + url: https://github.com/gexiro-global/forgeguard + status: active + accepts-change-request: true + accepts-automated-change-request: true + no-third-party-packages: false + core-team: + - name: dzeusking-dev + affiliation: Gexiro Global Enterprises Ltd. + social: https://github.com/dzeusking-dev + primary: true + documentation: + contributing-guide: https://github.com/gexiro-global/forgeguard/blob/main/CONTRIBUTING.md + review-policy: https://github.com/gexiro-global/forgeguard/blob/main/GOVERNANCE.md + security-policy: https://github.com/gexiro-global/forgeguard/blob/main/SECURITY.md + governance: https://github.com/gexiro-global/forgeguard/blob/main/GOVERNANCE.md + dependency-management-policy: https://github.com/gexiro-global/forgeguard/blob/main/docs/SECURITY-TRUST.md + license: + url: https://github.com/gexiro-global/forgeguard/blob/main/LICENSE + expression: Apache-2.0 + release: + changelog: https://github.com/gexiro-global/forgeguard/blob/main/CHANGELOG.md + automated-pipeline: true + distribution-points: + - uri: https://pypi.org/project/forgeguard/ + comment: Published Python package. + security: + assessments: + self: + comment: Maintainer self-assessment only; no independent audit is claimed.