From 649fb51c1de7d578c5305b52bad2210bc584ca99 Mon Sep 17 00:00:00 2001 From: AIOSAI Date: Sat, 25 Apr 2026 22:42:05 -0700 Subject: [PATCH] =?UTF-8?q?feat(system):=20feat:=20DPLAN-0153=20Tracks=201?= =?UTF-8?q?-3=20=E2=80=94=20SECURITY.md=20+=20README=20scope=20to=20Claude?= =?UTF-8?q?=20Code/Linux/WSL=20+=20CHANGELOG.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: @devpulse --- CHANGELOG.md | 65 ++++++++++++++++++++++++++++++++++++++++++++++++++++ README.md | 24 +++++++++++++------ SECURITY.md | 56 ++++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 138 insertions(+), 7 deletions(-) create mode 100644 CHANGELOG.md create mode 100644 SECURITY.md diff --git a/CHANGELOG.md b/CHANGELOG.md new file mode 100644 index 00000000..9772f412 --- /dev/null +++ b/CHANGELOG.md @@ -0,0 +1,65 @@ +# Changelog + +All notable changes to AIPass are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/). + +## [Unreleased] + +### Added +- Codecov badge in README +- SECURITY.md security policy +- CHANGELOG.md (this file) +- README roadmap section for Mac/Windows/Codex/Gemini + +### Changed +- README scoped to Claude Code + Linux/WSL as primary supported platform +- Codex and Gemini CLI marked as experimental in README + +### Fixed +- Security scan: ignore CVE-2026-3219 (upstream pip vulnerability, no fix available) + +## [2.1.0] - 2026-04-25 + +### Added +- pip install hook shipping — bootstrap falls back to wheel-bundled `_hooks/` when AIPASS_HOME hooks dir missing (Docker-verified) +- "Need Help?" line in README with links to Discussions and feedback form +- `from . import handlers` in 6 branch `apps/__init__.py` files for Python 3.10 mock.patch compatibility +- `.gitignore` negation for spawn template `.trinity/` directories +- Non-fatal `json_handler.log_operation` in spawn `copy_template` +- Version sync: `__init__.py` updated from 2.0.0 to 2.1.0 +- Devpulse seedgo compliance: 97% to 100% (META headers, bypasses, README date) + +### Changed +- Coverage gate removed from CI — codecov tracks coverage separately via codecov-action +- `.claude/CLAUDE.md` cleaned: removed misplaced Git section (culture-only file now) + +### Fixed +- **92 CI test failures resolved — CI green for the first time** (PRs #438-441) + - 87 Python 3.10 mock.patch failures: `mock._dot_lookup` needs explicit handler imports + - 4 `test_usage_tracker` failures: Path mock moved from context manager to decorator + - 1 `test_grant_passport` failure: `.gitignore` blocked template `.trinity/` files from CI clone + - Coverage gate at 52% vs 70% threshold removed + +### Security +- Removed `--fail-under=70` coverage gate that blocked CI (not a security fix, but changes security-adjacent CI behavior) + +## [2.0.0] - 2026-04-11 + +First PyPI release. Core framework with 11 agents, drone routing, ai_mail dispatch, seedgo quality standards, and the full branch architecture. + +### Highlights +- 11 core agents: devpulse, drone, seedgo, prax, cli, ai_mail, api, flow, spawn, trigger, memory +- `pip install aipass` with `aipass init` project bootstrapping +- `drone @branch command` routing to any agent +- 33 automated quality standards via seedgo +- Agent-to-agent communication via ai_mail +- Plan lifecycle via flow (DPLAN, FPLAN, APLAN, TDPLAN templates) +- Memory persistence via `.trinity/` with automatic rollover to ChromaDB +- Cross-project access via AIPASS_HOME and feedback channel +- Hook system: auto_fix, pre_edit_gate, subagent_stop_gate +- Multi-CLI support scaffolding: Claude Code, Codex, Gemini CLI +- Windows CI workflow +- Security scan workflow (pip-audit + CodeQL) + +[Unreleased]: https://github.com/AIOSAI/AIPass/compare/v2.1.0...HEAD +[2.1.0]: https://github.com/AIOSAI/AIPass/compare/v2.0.0...v2.1.0 +[2.0.0]: https://github.com/AIOSAI/AIPass/releases/tag/v2.0.0 diff --git a/README.md b/README.md index 84b9728c..8dd0db63 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ [![Python 3.10+](https://img.shields.io/badge/python-3.10%2B-blue)](pyproject.toml) [![License: MIT](https://img.shields.io/badge/license-MIT-green)](LICENSE) [![PyPI](https://img.shields.io/pypi/v/aipass)](https://pypi.org/project/aipass/) -[![CLIs](https://img.shields.io/badge/CLIs-Claude%20%7C%20Codex%20%7C%20Gemini-purple)](#cli-support) +[![CLI](https://img.shields.io/badge/CLI-Claude%20Code-purple)](#cli-support) [![Give Feedback](https://img.shields.io/badge/Give-Feedback-brightgreen)](https://github.com/AIOSAI/AIPass/issues/new?template=feedback.yml) [![codecov](https://codecov.io/gh/AIOSAI/AIPass/graph/badge.svg)](https://codecov.io/gh/AIOSAI/AIPass) [![OSS Health](https://oss-health-monitor.vercel.app/api/badge/AIOSAI/AIPass)](https://github.com/volotat/OSS-Health-Monitor) @@ -45,7 +45,7 @@ What's missing isn't more agents — it's *presence*. Agents that have identity, ## What AIPass Does -AIPass is a local CLI framework that gives your AI agents **identity, memory, and teamwork**. Verified with Claude Code, Codex, and Gemini CLI. Designed for terminal-native coding agents that support instruction files, hooks, and subprocess invocation. +AIPass is a local CLI framework that gives your AI agents **identity, memory, and teamwork**. Built and tested with Claude Code on Linux/WSL. Designed for terminal-native coding agents that support instruction files, hooks, and subprocess invocation. **Start with one agent that remembers:** @@ -208,13 +208,13 @@ You don't need to memorize this list. Start with `devpulse`, use `drone` to reac ## CLI Support -AIPass works with three AI coding CLIs. Claude Code is the most tested. +AIPass is built and tested with **Claude Code** on Linux/WSL. | CLI | Autonomous Mode | Status | |-----|----------------|--------| | [Claude Code](https://docs.anthropic.com/en/docs/claude-code) | `claude -p "prompt" --permission-mode bypassPermissions` | Fully tested | -| [Codex](https://github.com/openai/codex) | `codex exec "prompt" --dangerously-bypass-approvals-and-sandbox` | Integrated, less tested | -| [Gemini CLI](https://github.com/google-gemini/gemini-cli) | `gemini -p "prompt" --approval-mode=yolo` | Integrated, less tested | +| [Codex](https://github.com/openai/codex) | `codex exec "prompt" --dangerously-bypass-approvals-and-sandbox` | Experimental — see [Roadmap](#roadmap) | +| [Gemini CLI](https://github.com/google-gemini/gemini-cli) | `gemini -p "prompt" --approval-mode=yolo` | Experimental — see [Roadmap](#roadmap) | setup.sh auto-detects which CLIs are installed and configures hooks for each. @@ -240,10 +240,20 @@ Each agent documents its own operational status in its branch README — what wo ## Requirements - Python 3.10+ -- At least one AI CLI: Claude Code (recommended), Codex, or Gemini CLI +- [Claude Code](https://docs.anthropic.com/en/docs/claude-code) +- Linux or WSL (primary supported platforms) - `sudo` access (for global CLI symlinks) - API keys optional (OpenRouter/OpenAI — for optional add-on agents) -- **Platforms:** Linux (tested, primary dev environment), macOS (untested), Windows (native testing in progress — see [open issues](https://github.com/AIOSAI/AIPass/issues?q=is%3Aissue+is%3Aopen+Windows)) + +## Roadmap + +These items have partial work done and are under ongoing testing: + +- **macOS support** — setup and bootstrap work in progress ([#360](https://github.com/AIOSAI/AIPass/issues/360)) +- **Windows native** — CI passing, real-world testing ongoing +- **Codex CLI** — hooks and AGENTS.md wired, needs end-to-end testing +- **Gemini CLI** — hooks and GEMINI.md wired, needs end-to-end testing +- **Fork contributor workflow** — improved error handling for fork-based PRs ([#329](https://github.com/AIOSAI/AIPass/issues/329)) --- diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..7cd7cf16 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,56 @@ +# Security Policy + +## Supported Versions + +| Version | Supported | +|---------|-----------| +| 2.1.x | Yes | +| < 2.1 | No | + +## Reporting a Vulnerability + +If you discover a security vulnerability in AIPass, please report it responsibly. + +**Do not open a public GitHub issue for security vulnerabilities.** + +Instead, use one of these methods: + +1. **GitHub Security Advisories** (preferred): [Report a vulnerability](https://github.com/AIOSAI/AIPass/security/advisories/new) +2. **Email**: aipass.system@gmail.com + +### What to include + +- Description of the vulnerability +- Steps to reproduce +- Affected version(s) +- Any potential impact + +### What to expect + +- Acknowledgment within 48 hours +- Status update within 7 days +- Fix timeline communicated once the issue is confirmed + +## Scope + +### In scope + +- AIPass Python package (`src/aipass/`) +- CLI entry points (`drone`, `aipass`) +- Hook scripts (`.claude/hooks/`) +- GitHub Actions workflows (`.github/workflows/`) + +### Out of scope + +- Third-party dependencies (report upstream) +- Issues requiring physical access to the machine +- Social engineering + +## Security Design + +AIPass runs locally. No data leaves your machine unless you explicitly configure external services. + +- **Secrets** are stored outside the repo at `~/.secrets/aipass/` and never committed +- **API keys** are handled by the `api` branch and never logged or exposed in output +- **Git operations** are sandboxed through `drone @git` with permission deny lists +- **Hook scripts** run in the Claude Code sandbox environment