From d19776eb458636ba7ec60ed5bde152752fa1d335 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 7 Oct 2026 11:01:48 +0100 Subject: [PATCH] ci: refuse patch-fragment source files; security policy timelines Rescue of the D37 phase-zero recovery commit 632b54a (2026-08-24), rebuilt on main. main had independently superseded everything else in it (pins, actions.lock, permissions, the fixer.rs restoration, the hypatia.rs refactor, the 6a2 -> descriptiles move). What remains: - repo-integrity-guard: fail when a tracked source file begins with patch syntax (@@, *** Begin Patch, diff --git), the way fixer.rs was once a 14-line patch fragment. - .gitignore: ignore .claude/worktrees/ so an agent worktree cannot be committed as a gitlink again. - SECURITY.md: reporting timelines, supported versions, safe harbour; keeps the pointer to SECURITY.adoc. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_014BxjiTAaTZCHVWn2U5NWhL --- .github/workflows/repo-integrity-guard.yml | 15 ++++++++++ .gitignore | 1 + SECURITY.md | 35 +++++++++++++++------- 3 files changed, 41 insertions(+), 10 deletions(-) diff --git a/.github/workflows/repo-integrity-guard.yml b/.github/workflows/repo-integrity-guard.yml index b0fc5733..d10f2246 100644 --- a/.github/workflows/repo-integrity-guard.yml +++ b/.github/workflows/repo-integrity-guard.yml @@ -63,6 +63,21 @@ jobs: done exit $status + - name: Source files must not be patch fragments + run: | + set -euo pipefail + status=0 + while IFS= read -r -d '' file; do + first_content=$(sed -n '/[^[:space:]]/{p;q;}' "$file") + case "$first_content" in + '@@ '*|'*** Begin Patch'*|'diff --git '*) + echo "::error file=${file}::Source file begins with patch syntax: ${first_content}" + status=1 + ;; + esac + done < <(git ls-files -z -- '*.rs' '*.ex' '*.exs' '*.res' '*.js' '*.ts' '*.py' '*.sh') + exit "$status" + - name: Mass-deletion tripwire env: EVENT: ${{ github.event_name }} diff --git a/.gitignore b/.gitignore index 2c1f4a41..ab5733ef 100644 --- a/.gitignore +++ b/.gitignore @@ -15,6 +15,7 @@ # IDE .idea/ .vscode/ +.claude/worktrees/ *.swp *.swo *~ diff --git a/SECURITY.md b/SECURITY.md index 3a101396..af80df73 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,21 +1,36 @@ -# Security Policy +# Security policy -## Supported versions +## Reporting a vulnerability -The `main` branch is the supported version of this project. +Please report suspected vulnerabilities privately through +[GitHub private vulnerability reporting](https://github.com/hyperpolymath/gitbot-fleet/security/advisories/new). +Do not disclose a vulnerability in a public issue, pull request, discussion, or +social-media post before a coordinated fix is available. -## Reporting a vulnerability +Include the affected component and revision, the expected impact, reproduction +steps, and a minimal proof of concept where possible. Please avoid accessing, +modifying, or deleting data beyond what is necessary to demonstrate the issue, +and do not perform denial-of-service testing. + +We aim to acknowledge a report within 48 hours, provide an initial assessment +within seven days, and send status updates at least weekly while remediation is +in progress. Disclosure timing will be coordinated with the reporter; the +default target is within 90 days of the initial report. + +## Supported versions + +Security fixes are made on the default branch. Tagged releases are supported +only when explicitly identified as maintained in their release notes. -Please report security vulnerabilities through GitHub's private vulnerability -reporting feature: +## Safe harbour -1. Open the repository's **Security** tab. -2. Select **Report a vulnerability**. -3. Provide enough detail for the maintainers to reproduce and assess the issue. +We will not pursue legal action against researchers who act in good faith, +follow this policy, avoid privacy and service disruption, and allow reasonable +time for remediation before disclosure. -Do not open a public issue for a security vulnerability. +## Security measures The project's detailed security measures and cryptographic standards are documented in [SECURITY.adoc](SECURITY.adoc).