AIOSAI
9048666c65
ci: OSSF scorecard hardening (DPLAN-0243) — hash-pin all standalone workflow pip installs via .github/requirements/ locks (pip/lint/build/e2e/audit, pip-compile --generate-hashes, 11/11 target-env closure verified incl. Windows colorama marker fix) + provenance attestation on publish (attest-build-provenance v4.1.1 SHA-pinned, id-token+attestations perms) + dependabot pip ecosystem for the new locks. Editable -e . installs untouched byte-identical. 5/5 fresh-venv --require-hashes installs green, 5/5 YAML parse, pinned ruff matches repo lint. First SSH-signed commit (repo config wired this session).
2026-07-15 12:21:22 -07:00
dependabot[bot]
aea90da5c6
ci(deps): bump actions/setup-python from 6.2.0 to 6.3.0
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 6.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-27 08:02:22 +00:00
dependabot[bot]
ef5ae933d0
ci(deps): bump actions/checkout from 6.0.3 to 7.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-20 08:02:50 +00:00
dependabot[bot]
61cb963ed6
ci(deps): bump sigstore/gh-action-sigstore-python from 3.3.0 to 3.4.0
...
Bumps [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python ) from 3.3.0 to 3.4.0.
- [Release notes](https://github.com/sigstore/gh-action-sigstore-python/releases )
- [Changelog](https://github.com/sigstore/gh-action-sigstore-python/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sigstore/gh-action-sigstore-python/compare/04cffa1d795717b140764e8b640de88853c92acc...5b79a39c381910c090341a2c9b0bf022c8b387e1 )
---
updated-dependencies:
- dependency-name: sigstore/gh-action-sigstore-python
dependency-version: 3.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-13 08:02:20 +00:00
AIPass
1deb786c8a
Merge pull request #637 from AIOSAI/dev
...
security(ci): least-privilege token on e2e-wheel workflow + W24 changelog (also carries playbook commit 6b89fcd)
2026-06-08 10:36:14 -07:00
AIOSAI and Claude Opus 4.8
076110a2fb
security(release): sign GitHub Release artifacts with Sigstore (keyless)
...
publish.yml github-release job now signs the wheel + sdist via
sigstore/gh-action-sigstore-python (pinned v3.3.0 / 04cffa1d), keyless OIDC,
and attaches the .sigstore.json bundles to the GitHub Release through the
existing dist/* glob. Added id-token: write to the job for OIDC.
PyPI uploads were already attested (Trusted Publishing); Scorecard's
Signed-Releases check inspects GitHub Releases, which only carried bare wheels
-> score 0. .sigstore.json is in Scorecard's recognized signatureExtensions.
Verified: action globs ./dist/*.whl ./dist/*.tar.gz (action.py:202), auto-attach
gated on release-event (we trigger on push:tags) so we upload via dist/* and set
release-signing-artifacts:false. First live proof = next v* tag.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-08 10:19:51 -07:00
dependabot[bot]
285a8a5b5f
ci(deps): bump actions/checkout from 6.0.2 to 6.0.3
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 6.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 07:20:25 +00:00
dependabot[bot]
0a617586d5
ci(deps): bump actions/download-artifact from 6.0.0 to 8.0.1
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 6.0.0 to 8.0.1.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/018cc2cf5baa6db3ef3c5f8a56943fffe632ef53...3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: 8.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-30 08:02:57 +00:00
AIOSAI
efa5aced74
ci: harden workflows — least-privilege permissions + SHA-pinned actions
2026-05-29 23:47:27 -07:00
AIOSAI
5fe96307a4
ci: cut GitHub Release on tag from CHANGELOG
...
- publish.yml: new github-release job runs after PyPI publish, extracts the
top CHANGELOG section as release notes, attaches dist, creates the Release
via gh. Same v* tag now drives PyPI + GitHub Release.
- CHANGELOG W22 entry
2026-05-29 15:54:07 -07:00
dependabot[bot]
4c43610816
ci(deps): bump actions/upload-artifact from 4 to 7 ( #40 )
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v7 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-14 23:06:57 -07:00
AIOSAI and Claude Opus 4.6
f30443504c
chore: add hooks, CI/CD infrastructure, ignore runtime JSON
...
- Transfer Claude Code hooks from internal: identity injector, email
notification, auto-fix diagnostics, pre-compact recovery
- Add notification sounds for tool use, stop, and alerts
- Wire all hooks in .claude/settings.json
- Add global system prompt (.aipass/aipass_global_prompt.md)
- Add branch-local prompt placeholders for all modules
- Set up CI pipeline: lint (ruff) → test matrix (3.10-3.13) → coverage
- Add workflows: PyPI publish, security scanning, stale issues
- Add GitHub issue templates, dependabot, editorconfig
- Configure pytest norecursedirs and coverage fail-under=70
- Add *.json to gitignore — runtime JSON files constantly change
- Untrack runtime JSON (registry, plans, seed bypass, module data)
- Keep source JSON tracked via negation rules (json_templates, pack,
spawn templates, settings, pyrightconfig)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-06 20:33:40 -08:00