Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .bestpractices.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
{
"osps_do_01_01": "Met",
"osps_do_01_01_justification": "Install, usage and safety semantics are documented in README.md and docs/USAGE.md.",
"osps_do_02_01": "Met",
"osps_do_02_01_justification": "Defects use repository issue templates and SUPPORT.md.",
"osps_gv_02_01": "Met",
"osps_gv_02_01_justification": "Public issues and pull requests are enabled.",
"osps_gv_03_01": "Met",
"osps_gv_03_01_justification": "See https://github.com/gexiro-global/forgeguard/blob/main/CONTRIBUTING.md",
"osps_le_02_01": "Met",
"osps_le_02_01_justification": "Apache-2.0 source license.",
"osps_le_02_02": "Met",
"osps_le_02_02_justification": "Release packaging includes the Apache-2.0 license.",
"osps_le_03_01": "Met",
"osps_le_03_01_justification": "See https://github.com/gexiro-global/forgeguard/blob/main/LICENSE",
"osps_le_03_02": "Met",
"osps_le_03_02_justification": "The license is included in source distributions and wheels.",
"osps_qa_01_01": "Met",
"osps_qa_01_01_justification": "Canonical public source: https://github.com/gexiro-global/forgeguard",
"osps_qa_01_02": "Met",
"osps_qa_01_02_justification": "GitHub publishes the repository commit history.",
"osps_qa_02_01": "Met",
"osps_qa_02_01_justification": "Direct dependencies are declared in pyproject.toml.",
"osps_qa_04_01": "N/A",
"osps_qa_04_01_justification": "ForgeGuard is a single-repository project.",
"osps_qa_05_01": "Met",
"osps_qa_05_01_justification": "Generated executables are built in CI and not committed.",
"osps_qa_05_02": "Met",
"osps_qa_05_02_justification": "Tracked images are documentation/brand assets, not executable binaries.",
"osps_vm_02_01": "Met",
"osps_vm_02_01_justification": "See https://github.com/gexiro-global/forgeguard/blob/main/SECURITY.md"
}
19 changes: 19 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
name: Dependency review

on:
pull_request:

permissions:
contents: read

jobs:
review:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Review dependency changes
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: high
42 changes: 42 additions & 0 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
name: OpenSSF Scorecard

on:
branch_protection_rule:
schedule:
- cron: "43 5 * * 3"
push:
branches: [main]

permissions: read-all

jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
security-events: write
id-token: write
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Run OpenSSF Scorecard
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: results.sarif
results_format: sarif
publish_results: true
- name: Preserve SARIF result
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: openssf-scorecard-sarif
path: results.sarif
retention-days: 5
if-no-files-found: error
- name: Upload SARIF to code scanning
uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
sarif_file: results.sarif
5 changes: 5 additions & 0 deletions GOVERNANCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Governance

ForgeGuard is maintained by Gexiro Global Enterprises Ltd. The maintainer reviews issues and pull requests, decides scope and releases, and may reject changes that add unauthorized discovery, exploit behavior, state-changing probes or ambiguous PASS conclusions.

Changes are proposed through GitHub pull requests and must pass CI. The current single-maintainer structure is disclosed in [MAINTAINERS.md](MAINTAINERS.md); no independent review, response-time guarantee or certification is claimed.
7 changes: 7 additions & 0 deletions MAINTAINERS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Maintainers

| Maintainer | Role | Contact |
|---|---|---|
| `@dzeusking-dev` | Project owner and release maintainer | [GitHub](https://github.com/dzeusking-dev) |

Security reports must use [SECURITY.md](SECURITY.md), not public issues.
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@
[![Python](https://img.shields.io/pypi/pyversions/forgeguard.svg)](https://pypi.org/project/forgeguard/)
[![License: Apache-2.0](https://img.shields.io/pypi/l/forgeguard.svg)](https://github.com/gexiro-global/forgeguard/blob/main/LICENSE)

[Security and trust evidence](docs/SECURITY-TRUST.md) documents the project's policies and automated checks. No certification or badge level is claimed.

Read-only security posture self-check for one explicitly authorized self-hosted Gitea instance.

ForgeGuard gives Gitea operators repeatable evidence about version posture, the fixed-version baseline for CVE-2026-27771, anonymous OCI registry-root behavior, and anonymous responses on a small allowlist of repository/API paths. It uses no exploit probes, performs no internet-wide discovery, and does not request private package contents, manifests, or blobs.
Expand Down
5 changes: 5 additions & 0 deletions SUPPORT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Support

Use [GitHub Issues](https://github.com/gexiro-global/forgeguard/issues) for reproducible defects and usage questions. Include the ForgeGuard and Python versions and a synthetic or redacted reproduction against a system you are authorized to assess.

Security vulnerabilities belong in a private report under [SECURITY.md](SECURITY.md). Do not publish credentials, private endpoints or third-party data.
11 changes: 11 additions & 0 deletions docs/SECURITY-TRUST.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Security and trust evidence

This page is an evidence index, not a certification. The evidence does not prove the project is vulnerability-free, does not establish a SLSA level, and does not imply OpenSSF affiliation or endorsement. Tool output describes observed posture; it is not proof of compromise or absence of compromise.

- [Security policy](../SECURITY.md), [security model](SECURITY_MODEL.md) and [authorized-use boundary](../AUTHORIZED_USE.md)
- [Contribution process](../CONTRIBUTING.md), [governance](../GOVERNANCE.md), [maintainers](../MAINTAINERS.md) and [support](../SUPPORT.md)
- CI runs lint, format, compile, tests, dependency checks and exact-wheel smoke checks.
- GitHub default CodeQL setup is active; dependency review, Dependabot, secret scanning and OpenSSF Scorecard supplement it.
- Third-party actions are pinned to immutable commit SHAs with version comments.

The Scorecard badge is intentionally withheld until a successful default-branch run has produced a public API result. `.bestpractices.json` contains evidence-backed automation proposals only; it is not an OpenSSF Best Practices or OSPS Baseline claim. A human must review any badge submission.
57 changes: 57 additions & 0 deletions security-insights.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
header:
schema-version: 2.2.0
last-updated: '2026-09-04'
last-reviewed: '2026-09-04'
url: https://raw.githubusercontent.com/gexiro-global/forgeguard/main/security-insights.yml
comment: This single-repository file reports current practices and makes no certification claim.
project:
name: ForgeGuard
homepage: https://gexiro.com/forgeguard
administrators:
- name: dzeusking-dev
affiliation: Gexiro Global Enterprises Ltd.
social: https://github.com/dzeusking-dev
primary: true
documentation:
quickstart-guide: https://github.com/gexiro-global/forgeguard#quickstart
detailed-guide: https://github.com/gexiro-global/forgeguard/blob/main/docs/USAGE.md
code-of-conduct: https://github.com/gexiro-global/forgeguard/blob/main/CODE_OF_CONDUCT.md
support-policy: https://github.com/gexiro-global/forgeguard/blob/main/SUPPORT.md
repositories:
- name: forgeguard
url: https://github.com/gexiro-global/forgeguard
comment: Canonical source and release repository.
vulnerability-reporting:
reports-accepted: true
bug-bounty-available: false
policy: https://github.com/gexiro-global/forgeguard/blob/main/SECURITY.md
repository:
url: https://github.com/gexiro-global/forgeguard
status: active
accepts-change-request: true
accepts-automated-change-request: true
no-third-party-packages: false
core-team:
- name: dzeusking-dev
affiliation: Gexiro Global Enterprises Ltd.
social: https://github.com/dzeusking-dev
primary: true
documentation:
contributing-guide: https://github.com/gexiro-global/forgeguard/blob/main/CONTRIBUTING.md
review-policy: https://github.com/gexiro-global/forgeguard/blob/main/GOVERNANCE.md
security-policy: https://github.com/gexiro-global/forgeguard/blob/main/SECURITY.md
governance: https://github.com/gexiro-global/forgeguard/blob/main/GOVERNANCE.md
dependency-management-policy: https://github.com/gexiro-global/forgeguard/blob/main/docs/SECURITY-TRUST.md
license:
url: https://github.com/gexiro-global/forgeguard/blob/main/LICENSE
expression: Apache-2.0
release:
changelog: https://github.com/gexiro-global/forgeguard/blob/main/CHANGELOG.md
automated-pipeline: true
distribution-points:
- uri: https://pypi.org/project/forgeguard/
comment: Published Python package.
security:
assessments:
self:
comment: Maintainer self-assessment only; no independent audit is claimed.