Commit Graph
15 Commits
Author SHA1 Message Date
AIOSAI 9048666c65 ci: OSSF scorecard hardening (DPLAN-0243) — hash-pin all standalone workflow pip installs via .github/requirements/ locks (pip/lint/build/e2e/audit, pip-compile --generate-hashes, 11/11 target-env closure verified incl. Windows colorama marker fix) + provenance attestation on publish (attest-build-provenance v4.1.1 SHA-pinned, id-token+attestations perms) + dependabot pip ecosystem for the new locks. Editable -e . installs untouched byte-identical. 5/5 fresh-venv --require-hashes installs green, 5/5 YAML parse, pinned ruff matches repo lint. First SSH-signed commit (repo config wired this session). 2026-07-15 12:21:22 -07:00
dependabot[bot] 329e8015d4 ci(deps): bump the codeql-action group with 3 updates
Bumps the codeql-action group with 3 updates: [github/codeql-action/upload-sarif](https://github.com/github/codeql-action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/upload-sarif` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9)

Updates `github/codeql-action/init` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9)

Updates `github/codeql-action/analyze` from 4.36.3 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9)

---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-action
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-action
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-action
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 08:02:50 +00:00
AIOSAI 3071ea8eac ci(deps): bump codeql-action init+analyze to v4.36.3 together + group future bumps
The split Dependabot PRs (#init, #analyze) each bumped one path in security.yml,
leaving the sibling at v4.36.2 -> CodeQL fails 'init and analyze must match'.
Bump both to v4.36.3 (SHA 54f647b) in one commit, and add a dependabot groups
block so codeql-action (init/analyze/upload-sarif, one monorepo release) always
lands as a single grouped PR. Fixes the two red Security Scan runs.
2026-07-05 02:07:18 -07:00
dependabot[bot] aea90da5c6 ci(deps): bump actions/setup-python from 6.2.0 to 6.3.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-27 08:02:22 +00:00
dependabot[bot] ef5ae933d0 ci(deps): bump actions/checkout from 6.0.3 to 7.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-20 08:02:50 +00:00
dependabot[bot] 4e2ead98a6 ci(deps): bump github/codeql-action from 4.36.0 to 4.36.2
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/7211b7c8077ea37d8641b6271f6a365a22a5fbfa...8aad20d150bbac5944a9f9d289da16a4b0d87c1e)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 16:09:17 +00:00
dependabot[bot] 285a8a5b5f ci(deps): bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 07:20:25 +00:00
AIOSAIandClaude Opus 4.8 1ee51f3295 ci(security): upgrade pip in dependency-scan, drop stale ignores
dependency-scan (pip-audit) was red: it scans the whole env, and the runner's
bundled pip 26.1.1 carries PYSEC-2026-196 (fixed in 26.1.2). The job was the
only CI job not upgrading pip. Now runs 'python -m pip install --upgrade pip'
before auditing — removes the vulnerable version outright instead of
suppressing it.

pip 26.1.2 also fixes CVE-2026-3219 and CVE-2026-6357 (both were pip vulns, per
pip-audit attributing them to the pip package), so the two now-stale
--ignore-vuln entries are removed — stale security ignores mask the exact CVEs
they name if those reappear elsewhere.

Verified in a clean reproduction of the job env (fresh venv, upgrade pip, pip
install -e ., pip-audit --skip-editable with NO ignores): 'No known
vulnerabilities found', exit 0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 04:54:11 -07:00
dependabot[bot] 62e639794f ci(deps): bump github/codeql-action from 4.35.3 to 4.36.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.3 to 4.36.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/e46ed2cbd01164d986452f91f178727624ae40d7...7211b7c8077ea37d8641b6271f6a365a22a5fbfa)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-30 08:02:55 +00:00
AIOSAI efa5aced74 ci: harden workflows — least-privilege permissions + SHA-pinned actions 2026-05-29 23:47:27 -07:00
AIOSAI 453c847359 fix(ci): auto-format on commit, decouple lint from tests, add codecov threshold 2026-05-12 22:41:03 -07:00
AIOSAIand@devpulse 3b8fa1fa5a feat(system): test
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-12 17:33:34 -07:00
AIOSAIand@devpulse 3d1d820e26 feat(system): fix(system): ruff format 13 hook/init files + pip-audit CVE-2026-6357 ignore — unblock CI lint and security
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-07 00:39:58 -07:00
AIOSAIand@devpulse ad53c78386 feat(system): fix: ignore CVE-2026-3219 pip vulnerability in security scan — upstream pip issue, no fix available yet
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-25 22:01:37 -07:00
AIOSAIandClaude Opus 4.6 f30443504c chore: add hooks, CI/CD infrastructure, ignore runtime JSON
- Transfer Claude Code hooks from internal: identity injector, email
  notification, auto-fix diagnostics, pre-compact recovery
- Add notification sounds for tool use, stop, and alerts
- Wire all hooks in .claude/settings.json
- Add global system prompt (.aipass/aipass_global_prompt.md)
- Add branch-local prompt placeholders for all modules
- Set up CI pipeline: lint (ruff) → test matrix (3.10-3.13) → coverage
- Add workflows: PyPI publish, security scanning, stale issues
- Add GitHub issue templates, dependabot, editorconfig
- Configure pytest norecursedirs and coverage fail-under=70
- Add *.json to gitignore — runtime JSON files constantly change
- Untrack runtime JSON (registry, plans, seed bypass, module data)
- Keep source JSON tracked via negation rules (json_templates, pack,
  spawn templates, settings, pyrightconfig)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 20:33:40 -08:00