Merge pull request #444 from AIOSAI/system/devpulse-feat-dplan-0153-tracks-1-3-securitymd-readme-scope

feat(system): feat: DPLAN-0153 Tracks 1-3 — SECURITY.md + README scope to Claude Code/Linux/WSL + CHANGELOG.md
This commit is contained in:
AIPass
2026-04-25 23:26:15 -07:00
committed by GitHub
3 changed files with 138 additions and 7 deletions
+65
View File
@@ -0,0 +1,65 @@
# Changelog
All notable changes to AIPass are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/).
## [Unreleased]
### Added
- Codecov badge in README
- SECURITY.md security policy
- CHANGELOG.md (this file)
- README roadmap section for Mac/Windows/Codex/Gemini
### Changed
- README scoped to Claude Code + Linux/WSL as primary supported platform
- Codex and Gemini CLI marked as experimental in README
### Fixed
- Security scan: ignore CVE-2026-3219 (upstream pip vulnerability, no fix available)
## [2.1.0] - 2026-04-25
### Added
- pip install hook shipping — bootstrap falls back to wheel-bundled `_hooks/` when AIPASS_HOME hooks dir missing (Docker-verified)
- "Need Help?" line in README with links to Discussions and feedback form
- `from . import handlers` in 6 branch `apps/__init__.py` files for Python 3.10 mock.patch compatibility
- `.gitignore` negation for spawn template `.trinity/` directories
- Non-fatal `json_handler.log_operation` in spawn `copy_template`
- Version sync: `__init__.py` updated from 2.0.0 to 2.1.0
- Devpulse seedgo compliance: 97% to 100% (META headers, bypasses, README date)
### Changed
- Coverage gate removed from CI — codecov tracks coverage separately via codecov-action
- `.claude/CLAUDE.md` cleaned: removed misplaced Git section (culture-only file now)
### Fixed
- **92 CI test failures resolved — CI green for the first time** (PRs #438-441)
- 87 Python 3.10 mock.patch failures: `mock._dot_lookup` needs explicit handler imports
- 4 `test_usage_tracker` failures: Path mock moved from context manager to decorator
- 1 `test_grant_passport` failure: `.gitignore` blocked template `.trinity/` files from CI clone
- Coverage gate at 52% vs 70% threshold removed
### Security
- Removed `--fail-under=70` coverage gate that blocked CI (not a security fix, but changes security-adjacent CI behavior)
## [2.0.0] - 2026-04-11
First PyPI release. Core framework with 11 agents, drone routing, ai_mail dispatch, seedgo quality standards, and the full branch architecture.
### Highlights
- 11 core agents: devpulse, drone, seedgo, prax, cli, ai_mail, api, flow, spawn, trigger, memory
- `pip install aipass` with `aipass init` project bootstrapping
- `drone @branch command` routing to any agent
- 33 automated quality standards via seedgo
- Agent-to-agent communication via ai_mail
- Plan lifecycle via flow (DPLAN, FPLAN, APLAN, TDPLAN templates)
- Memory persistence via `.trinity/` with automatic rollover to ChromaDB
- Cross-project access via AIPASS_HOME and feedback channel
- Hook system: auto_fix, pre_edit_gate, subagent_stop_gate
- Multi-CLI support scaffolding: Claude Code, Codex, Gemini CLI
- Windows CI workflow
- Security scan workflow (pip-audit + CodeQL)
[Unreleased]: https://github.com/AIOSAI/AIPass/compare/v2.1.0...HEAD
[2.1.0]: https://github.com/AIOSAI/AIPass/compare/v2.0.0...v2.1.0
[2.0.0]: https://github.com/AIOSAI/AIPass/releases/tag/v2.0.0
+17 -7
View File
@@ -2,7 +2,7 @@
[![Python 3.10+](https://img.shields.io/badge/python-3.10%2B-blue)](pyproject.toml)
[![License: MIT](https://img.shields.io/badge/license-MIT-green)](LICENSE)
[![PyPI](https://img.shields.io/pypi/v/aipass)](https://pypi.org/project/aipass/)
[![CLIs](https://img.shields.io/badge/CLIs-Claude%20%7C%20Codex%20%7C%20Gemini-purple)](#cli-support)
[![CLI](https://img.shields.io/badge/CLI-Claude%20Code-purple)](#cli-support)
[![Give Feedback](https://img.shields.io/badge/Give-Feedback-brightgreen)](https://github.com/AIOSAI/AIPass/issues/new?template=feedback.yml)
[![codecov](https://codecov.io/gh/AIOSAI/AIPass/graph/badge.svg)](https://codecov.io/gh/AIOSAI/AIPass)
[![OSS Health](https://oss-health-monitor.vercel.app/api/badge/AIOSAI/AIPass)](https://github.com/volotat/OSS-Health-Monitor)
@@ -45,7 +45,7 @@ What's missing isn't more agents — it's *presence*. Agents that have identity,
## What AIPass Does
AIPass is a local CLI framework that gives your AI agents **identity, memory, and teamwork**. Verified with Claude Code, Codex, and Gemini CLI. Designed for terminal-native coding agents that support instruction files, hooks, and subprocess invocation.
AIPass is a local CLI framework that gives your AI agents **identity, memory, and teamwork**. Built and tested with Claude Code on Linux/WSL. Designed for terminal-native coding agents that support instruction files, hooks, and subprocess invocation.
**Start with one agent that remembers:**
@@ -208,13 +208,13 @@ You don't need to memorize this list. Start with `devpulse`, use `drone` to reac
## CLI Support
AIPass works with three AI coding CLIs. Claude Code is the most tested.
AIPass is built and tested with **Claude Code** on Linux/WSL.
| CLI | Autonomous Mode | Status |
|-----|----------------|--------|
| [Claude Code](https://docs.anthropic.com/en/docs/claude-code) | `claude -p "prompt" --permission-mode bypassPermissions` | Fully tested |
| [Codex](https://github.com/openai/codex) | `codex exec "prompt" --dangerously-bypass-approvals-and-sandbox` | Integrated, less tested |
| [Gemini CLI](https://github.com/google-gemini/gemini-cli) | `gemini -p "prompt" --approval-mode=yolo` | Integrated, less tested |
| [Codex](https://github.com/openai/codex) | `codex exec "prompt" --dangerously-bypass-approvals-and-sandbox` | Experimental — see [Roadmap](#roadmap) |
| [Gemini CLI](https://github.com/google-gemini/gemini-cli) | `gemini -p "prompt" --approval-mode=yolo` | Experimental — see [Roadmap](#roadmap) |
setup.sh auto-detects which CLIs are installed and configures hooks for each.
@@ -240,10 +240,20 @@ Each agent documents its own operational status in its branch README — what wo
## Requirements
- Python 3.10+
- At least one AI CLI: Claude Code (recommended), Codex, or Gemini CLI
- [Claude Code](https://docs.anthropic.com/en/docs/claude-code)
- Linux or WSL (primary supported platforms)
- `sudo` access (for global CLI symlinks)
- API keys optional (OpenRouter/OpenAI — for optional add-on agents)
- **Platforms:** Linux (tested, primary dev environment), macOS (untested), Windows (native testing in progress — see [open issues](https://github.com/AIOSAI/AIPass/issues?q=is%3Aissue+is%3Aopen+Windows))
## Roadmap
These items have partial work done and are under ongoing testing:
- **macOS support** — setup and bootstrap work in progress ([#360](https://github.com/AIOSAI/AIPass/issues/360))
- **Windows native** — CI passing, real-world testing ongoing
- **Codex CLI** — hooks and AGENTS.md wired, needs end-to-end testing
- **Gemini CLI** — hooks and GEMINI.md wired, needs end-to-end testing
- **Fork contributor workflow** — improved error handling for fork-based PRs ([#329](https://github.com/AIOSAI/AIPass/issues/329))
---
+56
View File
@@ -0,0 +1,56 @@
# Security Policy
## Supported Versions
| Version | Supported |
|---------|-----------|
| 2.1.x | Yes |
| < 2.1 | No |
## Reporting a Vulnerability
If you discover a security vulnerability in AIPass, please report it responsibly.
**Do not open a public GitHub issue for security vulnerabilities.**
Instead, use one of these methods:
1. **GitHub Security Advisories** (preferred): [Report a vulnerability](https://github.com/AIOSAI/AIPass/security/advisories/new)
2. **Email**: aipass.system@gmail.com
### What to include
- Description of the vulnerability
- Steps to reproduce
- Affected version(s)
- Any potential impact
### What to expect
- Acknowledgment within 48 hours
- Status update within 7 days
- Fix timeline communicated once the issue is confirmed
## Scope
### In scope
- AIPass Python package (`src/aipass/`)
- CLI entry points (`drone`, `aipass`)
- Hook scripts (`.claude/hooks/`)
- GitHub Actions workflows (`.github/workflows/`)
### Out of scope
- Third-party dependencies (report upstream)
- Issues requiring physical access to the machine
- Social engineering
## Security Design
AIPass runs locally. No data leaves your machine unless you explicitly configure external services.
- **Secrets** are stored outside the repo at `~/.secrets/aipass/` and never committed
- **API keys** are handled by the `api` branch and never logged or exposed in output
- **Git operations** are sandboxed through `drone @git` with permission deny lists
- **Hook scripts** run in the Claude Code sandbox environment