Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .claude/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,3 +85,11 @@ Both are FOSS with independent governance (no Big Tech).
- SHA-pinned dependencies
- SPDX license headers on all files


## Estate scripts β€” `putative-scripts/`

The estate maintenance scripts from the retired `hyperpolymath/estate-scripts`
repo were imported on 2026-10-06 into `putative-scripts/` (see its
`README.adoc` for provenance and what was excluded). They are untriaged: group
them into `scripts/`, `repo-scripts/` or `tools/`, or delete them, rather than
adding new scripts beside them. Many contain machine-specific absolute paths.
6 changes: 6 additions & 0 deletions llm-warmup-dev.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,9 @@ See README.adoc for overview.
* License: PMPL-1.0-or-later
* Part of hyperpolymath ecosystem
* See EXPLAINME.adoc for architecture

=== Estate scripts (putative-scripts/)

* `putative-scripts/` holds the estate maintenance scripts imported on
2026-10-06 from the retired `estate-scripts` repo. They are untriaged:
read `putative-scripts/README.adoc` before running or moving any of them.
24 changes: 24 additions & 0 deletions putative-scripts/99-net-hardening.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Network hardening β€” Debian WSL (2026-07-13). Reversible: delete this file + `sudo sysctl --system`.
# Reverse-path filtering (drop spoofed src)
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
# SYN flood mitigation
net.ipv4.tcp_syncookies = 1
# Ignore/never-send ICMP redirects (MITM route injection)
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
# No source routing
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv6.conf.all.accept_source_route = 0
# Log spoofed/martian packets
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.default.log_martians = 1
# Ignore broadcast pings + bogus ICMP errors
net.ipv4.icmp_echo_ignore_broadcasts = 1
net.ipv4.icmp_ignore_bogus_error_responses = 1
182 changes: 182 additions & 0 deletions putative-scripts/ACTION_PLAN.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,182 @@
# CI/CD Fixes - Action Plan

**SPDX-License-Identifier: MPL-2.0**
**Date: 2026-09-11**

## Current Status

### βœ… Completed
- Foundation fixes applied to `knot-rider` and `standards` repos
- Estate-wide propagation: 17 repos identified and fix branches created
- All fix branches use SHA-pinned actions with persist-credentials: false
- GPG signing documentation created
- Hypatia secrets scanner verification rule created

### ⚠️ Requires Attention
- Merge conflicts in some repos (main branch advanced)
- Failing CI checks (license compliance) in some repos
- PRs need to be created/merged manually

## PR Status Summary

### Existing PRs (Need Action)

| Repo | PR # | State | Issue | Action Required |
|------|------|-------|-------|-----------------|
| jtv-halting-islands-ct | #17 | CONFLICTING/DIRTY | Merge conflicts | Update branch, resolve conflicts |
| idaptik-ums | #88 | MERGEABLE/BLOCKED | License hygiene fails | Fix license issues |
| casket-ssg | #91 | MERGEABLE/BLOCKED | License compliance fails | Fix license issues |

### Repos Without PRs (Need PR Creation)

The following repos have fix branches but no PRs yet:
- oikosbot
- awesome-idris2
- rsr-julia-library-template-repo
- rsr-template-repo
- Cliometrics.jl
- Cliodynamics.jl
- JuliaForChildren.jl
- academic-workflow-suite
- neurophone
- hermeneia
- ipv6-tools
- ipfs-overlay
- universal-modding-studio

**Action**: Run `gh pr create --base main --head chore/apply-foundation-ci-fixes-20260911` in each repo

## Next Steps

### 1. Resolve Merge Conflicts

For repos with CONFLICTING state:

```bash
cd /path/to/repo
git checkout main
git pull origin main
git checkout chore/apply-foundation-ci-fixes-20260911
git merge main # Resolve conflicts
# Or: git merge --theirs main # If main changes should be kept
# Or: git merge --ours main # If fix changes should be kept
git push origin chore/apply-foundation-ci-fixes-20260911
```

### 2. Fix Failing Checks

For repos with BLOCKED state due to license checks:

- Check the failing workflow in GitHub UI
- Review license compliance issues
- Fix any license header issues
- Add required license files
- Re-run CI

### 3. Create Missing PRs

For repos without PRs:

```bash
cd /path/to/repo
gh pr create --base main --head chore/apply-foundation-ci-fixes-20260911 \
--title "fix(ci): apply foundation CI/CD security fixes" \
--body "Apply foundational CI/CD security fixes:

- Update CodeQL workflow to SHA-pinned actions with persist-credentials: false
- Update reusable workflow pins to current standards main SHAs
- Add persist-credentials: false to all checkout actions

Generated by Mistral Vibe.
Co-Authored-By: Mistral Vibe <vibe@mistral.ai>"
```

### 4. Enable Auto-Merge

For each PR:

```bash
gh pr merge <PR_NUMBER> --squash --auto
```

Or via GitHub UI:
1. Go to PR
2. Click "Merge" dropdown
3. Select "Merge pull request"
4. Check "Squash and merge"
5. Click "Merge"

### 5. Verify Fixes

After merging, verify the fixes are applied:

```bash
cd /path/to/repo
git checkout main
git pull origin main

# Check codeql.yml has SHA-pinned actions
grep -n "actions/checkout@" .github/workflows/codeql.yml
grep -n "codeql-action@" .github/workflows/codeql.yml

# Check persist-credentials: false exists
grep -A1 "actions/checkout@" .github/workflows/codeql.yml | grep "persist-credentials: false"

# Check governance.yml has current SHA
grep "governance-reusable.yml@" .github/workflows/governance.yml
```

## Verification Checklist

- [ ] All codeql.yml files use SHA-pinned actions
- [ ] All checkout actions have persist-credentials: false
- [ ] All governance.yml files use current standards SHA
- [ ] All scorecard.yml files use current standards SHA
- [ ] All hypatia-scan.yml files use current standards SHA
- [ ] CI workflows pass with new configuration
- [ ] No merge conflicts remain

## Monitoring Commands

### Check all PRs for a repo:
```bash
cd /path/to/repo
gh pr list --state open
```

### Check CI status for a PR:
```bash
cd /path/to/repo
gh pr checks <PR_NUMBER>
```

### Check workflow runs:
```bash
cd /path/to/repo
gh run list --limit 10
```

## Scripts Available

- `scripts/apply-fixes-with-pr.sh` - Apply fixes to a single repo
- `scripts/monitor-ci-and-verify.sh` - Monitor CI status
- `scripts/apply-fixes-clean.sh` - Batch processor
- `dev-notes/cicd/gpg-signing-for-ai-identities.md` - GPG guide

## References

- PR #40: https://github.com/hyperpolymath/knot-rider/pull/40
- PR #46: https://github.com/hyperpolymath/knot-rider/pull/46 (MERGED)
- PR #47: https://github.com/hyperpolymath/knot-rider/pull/47 (MERGED)
- Standards Repo: https://github.com/hyperpolymath/standards
- Hypatia Repo: https://github.com/hyperpolymath/hypatia

## Expected Outcome

Once all PRs are merged:
- βœ… CodeQL Security Analysis will use SHA-pinned actions
- βœ… Hypatia neurosymbolic scan will have persist-credentials: false
- βœ… Scorecard will have proper permissions
- βœ… Governance checks will use current rules
- βœ… No more tag-based action references in CI/CD workflows
- βœ… Improved security posture across the estate
Loading
Loading