Merge pull request #444 from AIOSAI/system/devpulse-feat-dplan-0153-tracks-1-3-securitymd-readme-scope
feat(system): feat: DPLAN-0153 Tracks 1-3 — SECURITY.md + README scope to Claude Code/Linux/WSL + CHANGELOG.md
This commit is contained in:
@@ -0,0 +1,65 @@
|
||||
# Changelog
|
||||
|
||||
All notable changes to AIPass are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
### Added
|
||||
- Codecov badge in README
|
||||
- SECURITY.md security policy
|
||||
- CHANGELOG.md (this file)
|
||||
- README roadmap section for Mac/Windows/Codex/Gemini
|
||||
|
||||
### Changed
|
||||
- README scoped to Claude Code + Linux/WSL as primary supported platform
|
||||
- Codex and Gemini CLI marked as experimental in README
|
||||
|
||||
### Fixed
|
||||
- Security scan: ignore CVE-2026-3219 (upstream pip vulnerability, no fix available)
|
||||
|
||||
## [2.1.0] - 2026-04-25
|
||||
|
||||
### Added
|
||||
- pip install hook shipping — bootstrap falls back to wheel-bundled `_hooks/` when AIPASS_HOME hooks dir missing (Docker-verified)
|
||||
- "Need Help?" line in README with links to Discussions and feedback form
|
||||
- `from . import handlers` in 6 branch `apps/__init__.py` files for Python 3.10 mock.patch compatibility
|
||||
- `.gitignore` negation for spawn template `.trinity/` directories
|
||||
- Non-fatal `json_handler.log_operation` in spawn `copy_template`
|
||||
- Version sync: `__init__.py` updated from 2.0.0 to 2.1.0
|
||||
- Devpulse seedgo compliance: 97% to 100% (META headers, bypasses, README date)
|
||||
|
||||
### Changed
|
||||
- Coverage gate removed from CI — codecov tracks coverage separately via codecov-action
|
||||
- `.claude/CLAUDE.md` cleaned: removed misplaced Git section (culture-only file now)
|
||||
|
||||
### Fixed
|
||||
- **92 CI test failures resolved — CI green for the first time** (PRs #438-441)
|
||||
- 87 Python 3.10 mock.patch failures: `mock._dot_lookup` needs explicit handler imports
|
||||
- 4 `test_usage_tracker` failures: Path mock moved from context manager to decorator
|
||||
- 1 `test_grant_passport` failure: `.gitignore` blocked template `.trinity/` files from CI clone
|
||||
- Coverage gate at 52% vs 70% threshold removed
|
||||
|
||||
### Security
|
||||
- Removed `--fail-under=70` coverage gate that blocked CI (not a security fix, but changes security-adjacent CI behavior)
|
||||
|
||||
## [2.0.0] - 2026-04-11
|
||||
|
||||
First PyPI release. Core framework with 11 agents, drone routing, ai_mail dispatch, seedgo quality standards, and the full branch architecture.
|
||||
|
||||
### Highlights
|
||||
- 11 core agents: devpulse, drone, seedgo, prax, cli, ai_mail, api, flow, spawn, trigger, memory
|
||||
- `pip install aipass` with `aipass init` project bootstrapping
|
||||
- `drone @branch command` routing to any agent
|
||||
- 33 automated quality standards via seedgo
|
||||
- Agent-to-agent communication via ai_mail
|
||||
- Plan lifecycle via flow (DPLAN, FPLAN, APLAN, TDPLAN templates)
|
||||
- Memory persistence via `.trinity/` with automatic rollover to ChromaDB
|
||||
- Cross-project access via AIPASS_HOME and feedback channel
|
||||
- Hook system: auto_fix, pre_edit_gate, subagent_stop_gate
|
||||
- Multi-CLI support scaffolding: Claude Code, Codex, Gemini CLI
|
||||
- Windows CI workflow
|
||||
- Security scan workflow (pip-audit + CodeQL)
|
||||
|
||||
[Unreleased]: https://github.com/AIOSAI/AIPass/compare/v2.1.0...HEAD
|
||||
[2.1.0]: https://github.com/AIOSAI/AIPass/compare/v2.0.0...v2.1.0
|
||||
[2.0.0]: https://github.com/AIOSAI/AIPass/releases/tag/v2.0.0
|
||||
@@ -2,7 +2,7 @@
|
||||
[](pyproject.toml)
|
||||
[](LICENSE)
|
||||
[](https://pypi.org/project/aipass/)
|
||||
[](#cli-support)
|
||||
[](#cli-support)
|
||||
[](https://github.com/AIOSAI/AIPass/issues/new?template=feedback.yml)
|
||||
[](https://codecov.io/gh/AIOSAI/AIPass)
|
||||
[](https://github.com/volotat/OSS-Health-Monitor)
|
||||
@@ -45,7 +45,7 @@ What's missing isn't more agents — it's *presence*. Agents that have identity,
|
||||
|
||||
## What AIPass Does
|
||||
|
||||
AIPass is a local CLI framework that gives your AI agents **identity, memory, and teamwork**. Verified with Claude Code, Codex, and Gemini CLI. Designed for terminal-native coding agents that support instruction files, hooks, and subprocess invocation.
|
||||
AIPass is a local CLI framework that gives your AI agents **identity, memory, and teamwork**. Built and tested with Claude Code on Linux/WSL. Designed for terminal-native coding agents that support instruction files, hooks, and subprocess invocation.
|
||||
|
||||
**Start with one agent that remembers:**
|
||||
|
||||
@@ -208,13 +208,13 @@ You don't need to memorize this list. Start with `devpulse`, use `drone` to reac
|
||||
|
||||
## CLI Support
|
||||
|
||||
AIPass works with three AI coding CLIs. Claude Code is the most tested.
|
||||
AIPass is built and tested with **Claude Code** on Linux/WSL.
|
||||
|
||||
| CLI | Autonomous Mode | Status |
|
||||
|-----|----------------|--------|
|
||||
| [Claude Code](https://docs.anthropic.com/en/docs/claude-code) | `claude -p "prompt" --permission-mode bypassPermissions` | Fully tested |
|
||||
| [Codex](https://github.com/openai/codex) | `codex exec "prompt" --dangerously-bypass-approvals-and-sandbox` | Integrated, less tested |
|
||||
| [Gemini CLI](https://github.com/google-gemini/gemini-cli) | `gemini -p "prompt" --approval-mode=yolo` | Integrated, less tested |
|
||||
| [Codex](https://github.com/openai/codex) | `codex exec "prompt" --dangerously-bypass-approvals-and-sandbox` | Experimental — see [Roadmap](#roadmap) |
|
||||
| [Gemini CLI](https://github.com/google-gemini/gemini-cli) | `gemini -p "prompt" --approval-mode=yolo` | Experimental — see [Roadmap](#roadmap) |
|
||||
|
||||
setup.sh auto-detects which CLIs are installed and configures hooks for each.
|
||||
|
||||
@@ -240,10 +240,20 @@ Each agent documents its own operational status in its branch README — what wo
|
||||
## Requirements
|
||||
|
||||
- Python 3.10+
|
||||
- At least one AI CLI: Claude Code (recommended), Codex, or Gemini CLI
|
||||
- [Claude Code](https://docs.anthropic.com/en/docs/claude-code)
|
||||
- Linux or WSL (primary supported platforms)
|
||||
- `sudo` access (for global CLI symlinks)
|
||||
- API keys optional (OpenRouter/OpenAI — for optional add-on agents)
|
||||
- **Platforms:** Linux (tested, primary dev environment), macOS (untested), Windows (native testing in progress — see [open issues](https://github.com/AIOSAI/AIPass/issues?q=is%3Aissue+is%3Aopen+Windows))
|
||||
|
||||
## Roadmap
|
||||
|
||||
These items have partial work done and are under ongoing testing:
|
||||
|
||||
- **macOS support** — setup and bootstrap work in progress ([#360](https://github.com/AIOSAI/AIPass/issues/360))
|
||||
- **Windows native** — CI passing, real-world testing ongoing
|
||||
- **Codex CLI** — hooks and AGENTS.md wired, needs end-to-end testing
|
||||
- **Gemini CLI** — hooks and GEMINI.md wired, needs end-to-end testing
|
||||
- **Fork contributor workflow** — improved error handling for fork-based PRs ([#329](https://github.com/AIOSAI/AIPass/issues/329))
|
||||
|
||||
---
|
||||
|
||||
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
# Security Policy
|
||||
|
||||
## Supported Versions
|
||||
|
||||
| Version | Supported |
|
||||
|---------|-----------|
|
||||
| 2.1.x | Yes |
|
||||
| < 2.1 | No |
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you discover a security vulnerability in AIPass, please report it responsibly.
|
||||
|
||||
**Do not open a public GitHub issue for security vulnerabilities.**
|
||||
|
||||
Instead, use one of these methods:
|
||||
|
||||
1. **GitHub Security Advisories** (preferred): [Report a vulnerability](https://github.com/AIOSAI/AIPass/security/advisories/new)
|
||||
2. **Email**: aipass.system@gmail.com
|
||||
|
||||
### What to include
|
||||
|
||||
- Description of the vulnerability
|
||||
- Steps to reproduce
|
||||
- Affected version(s)
|
||||
- Any potential impact
|
||||
|
||||
### What to expect
|
||||
|
||||
- Acknowledgment within 48 hours
|
||||
- Status update within 7 days
|
||||
- Fix timeline communicated once the issue is confirmed
|
||||
|
||||
## Scope
|
||||
|
||||
### In scope
|
||||
|
||||
- AIPass Python package (`src/aipass/`)
|
||||
- CLI entry points (`drone`, `aipass`)
|
||||
- Hook scripts (`.claude/hooks/`)
|
||||
- GitHub Actions workflows (`.github/workflows/`)
|
||||
|
||||
### Out of scope
|
||||
|
||||
- Third-party dependencies (report upstream)
|
||||
- Issues requiring physical access to the machine
|
||||
- Social engineering
|
||||
|
||||
## Security Design
|
||||
|
||||
AIPass runs locally. No data leaves your machine unless you explicitly configure external services.
|
||||
|
||||
- **Secrets** are stored outside the repo at `~/.secrets/aipass/` and never committed
|
||||
- **API keys** are handled by the `api` branch and never logged or exposed in output
|
||||
- **Git operations** are sandboxed through `drone @git` with permission deny lists
|
||||
- **Hook scripts** run in the Claude Code sandbox environment
|
||||
Reference in New Issue
Block a user