diff --git a/DEFENSE_IN_DEPTH.md b/DEFENSE_IN_DEPTH.md index eb152cfa..f1808e4c 100644 --- a/DEFENSE_IN_DEPTH.md +++ b/DEFENSE_IN_DEPTH.md @@ -9,7 +9,7 @@ Profile: npm library · public - [x] `DEFENSE_IN_DEPTH.md` present (this file) — PR #1698 ## 2. CODEOWNERS and cloud bootstrap -- [ ] `.github/CODEOWNERS` covers `/.github/`, `/.cursor/`, `/.devcontainer/`, `/scripts/` with owners the maintainer names (PR #1704 pending) +- [x] `.github/CODEOWNERS` covers `/.github/`, `/.cursor/`, `/.devcontainer/`, `/scripts/` with owners the maintainer names — PR #1704 - [x] Codespaces and Cursor Cloud Agents bootstrap Aikido Safe Chain via scripts/setup-cloud-environment.sh (--ci shims, frozen lockfile) — PR #1699 ## 3. Dependencies (pnpm) @@ -49,4 +49,4 @@ Profile: npm library · public ## 7. Repository lockdown - [ ] Phishing-resistant 2FA (passkeys / hardware keys) on the GitHub and npm accounts (manual) - [ ] Recovery codes stored offline in a password manager (manual) -- [ ] `lockdown-repo.sh` applied by a repo admin (never committed to this repo); `--check` with `--required-checks` and `--allowed-actions` passes (PRs required on the default branch, merges blocked unless required status checks pass, tag ruleset, immutable releases, fork-PR approval (public repos), read-only workflow tokens, Actions allowlist, secret scanning, Dependabot disabled, private vulnerability reporting (public repos)) +- [x] `lockdown-repo.sh` applied by a repo admin (never committed to this repo); `--check` with `--required-checks` and `--allowed-actions` passes (PRs required on the default branch, merges blocked unless required status checks pass, tag ruleset, immutable releases, fork-PR approval (public repos), read-only workflow tokens, Actions allowlist, secret scanning, Dependabot disabled, private vulnerability reporting (public repos)) — PR #1705 diff --git a/SECURITY.md b/SECURITY.md index 19cd3d1b..79ac219b 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -23,6 +23,9 @@ We will acknowledge receipt, work with you on a coordinated disclosure timeline, This repository follows the [defense-in-depth](https://github.com/jaredwray/agentic/blob/main/skills/security/defense-in-depth-nodejs/SKILL.md) hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_DEPTH.md). Measures currently in place: +- All changes land through pull requests — direct pushes to `main` are blocked, and merging requires passing status checks. +- Tags can only be created by repository admins; published GitHub Releases are immutable (assets and tags cannot be changed after publish). +- Workflow runs from outside collaborators always require maintainer approval, and only allowlisted GitHub Actions can run. - CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI; every action is pinned to a full commit SHA; Socket Firewall (`sfw`) wraps `pnpm install`; workflows are security-linted with zizmor on every PR. - npm publishing authenticates with OIDC trusted publishing; there are no npm tokens in Actions secrets. CI packs tarballs and stages them with `pnpm stage publish`; a maintainer promotes the staged version. The release job `needs` a passing Aikido `scan-release`. - pnpm is pinned via `packageManager` (`pnpm@11.5.1`), and the lockfile is committed. @@ -30,3 +33,4 @@ hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_D - There is no `.github/dependabot.yml`. - Codespaces and Cursor Cloud Agents install through Aikido Safe Chain; package-manager shims must not be bypassed. - Socket reviews every dependency change; Aikido scans every build. +- `.github/CODEOWNERS` names owners for `/.github/`, `/.cursor/`, `/.devcontainer/`, and `/scripts/`.