Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 43 additions & 0 deletions .github/ISSUE_TEMPLATE/bug.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
name: Bug report
description: Report a reproducible defect
title: "bug: "
labels:
- bug

body:
- type: markdown
attributes:
value: |
**Do not disclose suspected vulnerabilities here.**
Use the repository's private vulnerability reporting link instead.

- type: textarea
id: summary
attributes:
label: Summary
description: What is wrong?
validations:
required: true

- type: textarea
id: reproduction
attributes:
label: Reproduction
description: Minimal steps or code needed to reproduce the problem.
validations:
required: true

- type: textarea
id: expected
attributes:
label: Expected behavior
validations:
required: true

- type: textarea
id: environment
attributes:
label: Environment
description: Rust version, OS, target, crate version, enabled features, and relevant dependencies.
validations:
required: true
6 changes: 6 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
blank_issues_enabled: false

contact_links:
- name: Security vulnerability
url: https://github.com/LATTIX-IO/fheflow/security/advisories/new
about: Report suspected vulnerabilities privately. Do not disclose vulnerabilities in a public issue.
29 changes: 29 additions & 0 deletions .github/ISSUE_TEMPLATE/feature.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
name: Feature request
description: Propose a capability or API improvement
title: "feat: "
labels:
- enhancement
body:
- type: textarea
id: problem
attributes:
label: Problem
description: What user, interoperability, security, or engineering problem needs to be solved?
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed solution
description: Describe the desired behavior and API shape.
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: Alternatives considered
- type: textarea
id: compatibility
attributes:
label: Compatibility and security impact
description: Note API compatibility, ecosystem interoperability, cryptographic, performance, or security implications.
26 changes: 26 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
## Summary

Describe the change and the problem it solves.

## Scope

- [ ] Change is focused and intentionally scoped.
- [ ] Public API changes are documented.
- [ ] Security implications have been considered.

## Validation

- [ ] `cargo fmt --all -- --check`
- [ ] `cargo check --workspace --all-targets --all-features`
- [ ] `cargo clippy --workspace --all-targets --all-features -- -D warnings`
- [ ] `cargo test --workspace --all-features`
- [ ] `cargo doc --workspace --all-features --no-deps`
- [ ] Supply-chain / SemVer checks pass where applicable.

## Compatibility

Describe any API, behavior, wire-format, storage-format, cryptographic, or interoperability impact.

## Security

Describe new trust boundaries, unsafe behavior, cryptographic changes, input-handling changes, or security-relevant dependencies. Write `None` if not applicable.
50 changes: 38 additions & 12 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,39 +1,65 @@
name: ci
name: Rust CI

on:
push:
branches:
- main
pull_request:
branches:
- main
workflow_dispatch:

permissions:
contents: read

jobs:
rust:
rust-checks:
name: Rust checks
runs-on: ubuntu-latest

steps:
- name: Checkout
uses: actions/checkout@v7
- name: Checkout repository
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803
with:
fetch-depth: 0
Comment thread
jmsbooth marked this conversation as resolved.
persist-credentials: false

- name: Install stable Rust
uses: dtolnay/rust-toolchain@stable
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d
with:
components: rustfmt, clippy

- name: Check formatting
- name: Cache Cargo
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6

- name: Format
run: cargo fmt --all -- --check

- name: Check workspace
run: cargo check --workspace --all-targets --all-features
- name: Check
run: cargo check --workspace --all-targets --all-features --locked

- name: Clippy
run: cargo clippy --workspace --all-targets --all-features -- -D warnings
run: cargo clippy --workspace --all-targets --all-features --locked -- -D warnings

- name: Test
run: cargo test --workspace --all-features
run: cargo test --workspace --all-features --locked

- name: Documentation
run: cargo doc --workspace --all-features --no-deps
env:
RUSTDOCFLAGS: -D warnings
run: cargo doc --workspace --all-features --no-deps --locked

- name: Install supply-chain tools
run: |
cargo install --locked cargo-audit
cargo install --locked cargo-deny
cargo install --locked cargo-semver-checks

- name: RustSec audit
run: cargo audit

- name: Dependency policy
run: cargo deny check

- name: SemVer compatibility
run: cargo semver-checks check-release --workspace --all-features
42 changes: 42 additions & 0 deletions .github/workflows/release-plz.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
name: Release-plz

on:
workflow_dispatch:

permissions:
contents: read

jobs:
release-plz-pr:
name: Release-plz PR
runs-on: ubuntu-latest

if: >-
${{ github.repository_owner == 'LATTIX-IO' &&
github.ref == 'refs/heads/main' }}

permissions:
contents: write
pull-requests: write

concurrency:
group: release-plz-${{ github.ref }}
cancel-in-progress: false

steps:
- name: Checkout repository
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803
with:
fetch-depth: 0
persist-credentials: false

- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d

- name: Prepare release PR
uses: release-plz/action@18641b6c63063cc5ff8786ebf69cd57e8541bae1
with:
command: release-pr
env:
GITHUB_TOKEN: ${{ secrets.RELEASE_PLZ_TOKEN }}
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
15 changes: 15 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Changelog

All notable changes to this project will be documented in this file.

The project follows Semantic Versioning once its public API reaches a stable contract. Pre-1.0 releases may evolve more rapidly, with breaking changes documented here.

## [Unreleased]

### Added

### Changed

### Fixed

### Security
21 changes: 21 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Code of Conduct

Lattix open-source projects are technical communities built around professional, good-faith collaboration.

## Expected behavior

- Discuss ideas, implementations, and tradeoffs on their technical merits.
- Be precise, constructive, and respectful in reviews and issue discussions.
- Give contributors reasonable opportunity to explain or correct mistakes.
- Respect security embargoes, responsible-disclosure processes, and project confidentiality requirements.
- Do not harass, threaten, discriminate against, or deliberately disrupt other participants.

## Unacceptable behavior

Harassment, threats, discriminatory conduct, doxxing, deliberate disruption, malicious submissions, unauthorized disclosure of security-sensitive information, and repeated bad-faith behavior are not permitted.

## Enforcement

Project maintainers may edit or remove contributions, comments, issues, pull requests, or other participation that violates these expectations. Serious or repeated violations may result in temporary or permanent removal from Lattix project spaces.

For private conduct reports, email secops@lattix.io. For suspected vulnerabilities, use the private reporting mechanisms documented in SECURITY.md.
7 changes: 6 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,4 +12,9 @@ Include enough information to reproduce and assess the issue, including:
- expected and observed behavior;
- potential security impact.

Do not publicly disclose an unresolved vulnerability before coordinated disclosure.
Do not publicly disclose an unresolved vulnerability before coordinated disclosure.
## Private reporting fallback

If GitHub Private Vulnerability Reporting is unavailable, email security reports to secops@lattix.io.

Do not disclose suspected vulnerabilities through public GitHub issues, discussions, or pull requests.
15 changes: 15 additions & 0 deletions SUPPORT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Support

## Bugs and feature requests

Use GitHub Issues for reproducible defects, feature proposals, documentation gaps, and implementation questions that are appropriate for public discussion.

## Security issues

Do not open a public issue for a suspected vulnerability.

Use GitHub Private Vulnerability Reporting from the repository Security tab. If Private Vulnerability Reporting is unavailable, email secops@lattix.io.

## Commercial support

These repositories are open-source projects. Public issue trackers do not create a commercial support obligation or response-time commitment.
31 changes: 31 additions & 0 deletions deny.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
[graph]
all-features = true

[advisories]
yanked = "warn"
unmaintained = "workspace"
unsound = "workspace"

[licenses]
confidence-threshold = 0.8
allow = [
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"MIT",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Zlib",
"Unicode-3.0",
"MPL-2.0",
]

[bans]
multiple-versions = "warn"
wildcards = "deny"
highlight = "all"

[sources]
unknown-registry = "deny"
unknown-git = "deny"
allow-git = []
14 changes: 14 additions & 0 deletions release-plz.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
[workspace]
changelog_update = true
changelog_path = "./CHANGELOG.md"
dependencies_update = true
git_release_enable = true
git_tag_enable = true
semver_check = true
release_always = false
pr_branch_prefix = "release-plz-"
pr_labels = ["release"]

[changelog]
protect_breaking_commits = true
sort_commits = "newest"
Loading