Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -177,8 +177,8 @@ jobs:
- name: Check Documentation
run: |
echo "Checking required files..."
test -f README.md || (echo "❌ README.md missing" && exit 1)
test -f LICENSE || (echo "❌ LICENSE missing" && exit 1)
test -f README.adoc || test -f README.md || (echo "❌ README missing" && exit 1)
test -f LICENSE.txt || test -f LICENSE || (echo "❌ LICENSE missing" && exit 1)
test -f SECURITY.md || (echo "❌ SECURITY.md missing" && exit 1)
test -f CODE_OF_CONDUCT.md || (echo "❌ CODE_OF_CONDUCT.md missing" && exit 1)
test -f CONTRIBUTING.md || (echo "❌ CONTRIBUTING.md missing" && exit 1)
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,17 +14,17 @@ jobs:
security-events: write
id-token: write
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
with:
persist-credentials: false

- name: Run Scorecard
uses: ossf/scorecard-action@v2.3.1
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
with:
results_file: results.sarif
results_format: sarif

- name: Upload results
uses: github/codeql-action/upload-sarif@v3
uses: github/codeql-action/upload-sarif@662472033e021d55d94146f66f6058822b0b39fd # v3.28.1
with:
sarif_file: results.sarif
8 changes: 4 additions & 4 deletions .github/workflows/security-policy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,20 +4,20 @@ jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: Security checks
run: |
FAILED=false

# Block MD5/SHA1 for security (allow for checksums/caching)
WEAK_CRYPTO=$(grep -rE 'md5\(|sha1\(' --include="*.py" --include="*.rb" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" . 2>/dev/null | grep -v 'checksum\|cache\|test\|spec' | head -5 || true)
if [ -n "$WEAK_CRYPTO" ]; then
echo "⚠️ Weak crypto (MD5/SHA1) detected. Use SHA256+ for security:"
echo "$WEAK_CRYPTO"
fi

# Block HTTP URLs (except localhost)
HTTP_URLS=$(grep -rE 'https://[^l][^o][^c]' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.yaml" --include="*.yml" . 2>/dev/null | grep -v 'localhost\|127.0.0.1\|example\|test\|spec' | head -5 || true)
HTTP_URLS=$(grep -rE 'http://[^l][^o][^c]' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.yaml" --include="*.yml" . 2>/dev/null | grep -v 'localhost\|127.0.0.1\|example\|test\|spec' | head -5 || true)
if [ -n "$HTTP_URLS" ]; then
echo "⚠️ HTTP URLs found. Use HTTPS:"
echo "$HTTP_URLS"
Expand Down
33 changes: 25 additions & 8 deletions STATE.scm
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
'((version . "0.1.0")
(schema-version . "1.0")
(created . "2025-12-15")
(updated . "2025-12-15")
(updated . "2025-12-17")
(project . "double-track-browser")
(repo . "github.com/hyperpolymath/double-track-browser")))

Expand All @@ -41,18 +41,23 @@

(define current-position
'((phase . "v0.1 - Initial Setup and RSR Compliance")
(overall-completion . 25)
(overall-completion . 30)

(components
((rsr-compliance
((status . "complete")
(completion . 100)
(notes . "SHA-pinned actions, SPDX headers, multi-platform CI")))

(security
((status . "hardened")
(completion . 85)
(notes . "Fixed HTTP/HTTPS detection bug, SHA-pinned scorecard workflow, updated RSR validation for README.adoc/LICENSE.txt")))

(documentation
((status . "foundation")
(completion . 30)
(notes . "README exists, META/ECOSYSTEM/STATE.scm added")))
(completion . 35)
(notes . "README.adoc, META/ECOSYSTEM/STATE.scm, comprehensive SECURITY.md")))

(testing
((status . "minimal")
Expand All @@ -62,13 +67,16 @@
(core-functionality
((status . "in-progress")
(completion . 25)
(notes . "Initial implementation underway")))))
(notes . "Rust core with profile/activity/schedule modules, TypeScript shell scaffolded")))))

(working-features
("RSR-compliant CI/CD pipeline"
"Multi-platform mirroring (GitHub, GitLab, Bitbucket)"
"SPDX license headers on all files"
"SHA-pinned GitHub Actions"))))
"SHA-pinned GitHub Actions"
"CodeQL security scanning"
"OSSF Scorecard integration"
"Security policy enforcement workflow"))))

;;;============================================================================
;;; ROUTE TO MVP
Expand Down Expand Up @@ -151,6 +159,15 @@

(define session-history
'((snapshots
((date . "2025-12-17")
(session . "security-hardening-review")
(accomplishments
("Fixed critical HTTP/HTTPS detection bug in security-policy.yml"
"SHA-pinned scorecard.yml actions for supply chain security"
"Updated RSR validation to support README.adoc and LICENSE.txt"
"Reviewed all SCM files for correctness"
"Updated STATE.scm with current project status"))
(notes . "Security audit and SCM review session"))
((date . "2025-12-15")
(session . "initial-state-creation")
(accomplishments
Expand Down Expand Up @@ -185,10 +202,10 @@
(define state-summary
'((project . "double-track-browser")
(version . "0.1.0")
(overall-completion . 25)
(overall-completion . 30)
(next-milestone . "v0.2 - Core Functionality")
(critical-blockers . 0)
(high-priority-issues . 0)
(updated . "2025-12-15")))
(updated . "2025-12-17")))

;;; End of STATE.scm
4 changes: 2 additions & 2 deletions justfile
Original file line number Diff line number Diff line change
Expand Up @@ -182,8 +182,8 @@ validate-rsr:
echo "📋 Checking RSR compliance..."
echo ""
echo "Documentation:"
[[ -f README.md ]] && echo " ✅ README.md" || echo " ❌ README.md"
[[ -f LICENSE ]] && echo " ✅ LICENSE" || echo " ❌ LICENSE"
[[ -f README.adoc || -f README.md ]] && echo " ✅ README" || echo " ❌ README"
[[ -f LICENSE.txt || -f LICENSE ]] && echo " ✅ LICENSE" || echo " ❌ LICENSE"
[[ -f SECURITY.md ]] && echo " ✅ SECURITY.md" || echo " ❌ SECURITY.md"
[[ -f CODE_OF_CONDUCT.md ]] && echo " ✅ CODE_OF_CONDUCT.md" || echo " ❌ CODE_OF_CONDUCT.md"
[[ -f CONTRIBUTING.md ]] && echo " ✅ CONTRIBUTING.md" || echo " ❌ CONTRIBUTING.md"
Expand Down
Loading