Repository navigation
chore: harden FOSS supply chain and release process #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| name: Bug report | ||
| description: Report a reproducible defect | ||
| title: "bug: " | ||
| labels: | ||
| - bug | ||
|
|
||
| body: | ||
| - type: markdown | ||
| attributes: | ||
| value: | | ||
| **Do not disclose suspected vulnerabilities here.** | ||
| Use the repository's private vulnerability reporting link instead. | ||
|
|
||
| - type: textarea | ||
| id: summary | ||
| attributes: | ||
| label: Summary | ||
| description: What is wrong? | ||
| validations: | ||
| required: true | ||
|
|
||
| - type: textarea | ||
| id: reproduction | ||
| attributes: | ||
| label: Reproduction | ||
| description: Minimal steps or code needed to reproduce the problem. | ||
| validations: | ||
| required: true | ||
|
|
||
| - type: textarea | ||
| id: expected | ||
| attributes: | ||
| label: Expected behavior | ||
| validations: | ||
| required: true | ||
|
|
||
| - type: textarea | ||
| id: environment | ||
| attributes: | ||
| label: Environment | ||
| description: Rust version, OS, target, crate version, enabled features, and relevant dependencies. | ||
| validations: | ||
| required: true |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| blank_issues_enabled: false | ||
|
|
||
| contact_links: | ||
| - name: Security vulnerability | ||
| url: https://github.com/LATTIX-IO/fhewasm/security/advisories/new | ||
| about: Report suspected vulnerabilities privately. Do not disclose vulnerabilities in a public issue. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,29 @@ | ||
| name: Feature request | ||
| description: Propose a capability or API improvement | ||
| title: "feat: " | ||
| labels: | ||
| - enhancement | ||
| body: | ||
| - type: textarea | ||
| id: problem | ||
| attributes: | ||
| label: Problem | ||
| description: What user, interoperability, security, or engineering problem needs to be solved? | ||
| validations: | ||
| required: true | ||
| - type: textarea | ||
| id: proposal | ||
| attributes: | ||
| label: Proposed solution | ||
| description: Describe the desired behavior and API shape. | ||
| validations: | ||
| required: true | ||
| - type: textarea | ||
| id: alternatives | ||
| attributes: | ||
| label: Alternatives considered | ||
| - type: textarea | ||
| id: compatibility | ||
| attributes: | ||
| label: Compatibility and security impact | ||
| description: Note API compatibility, ecosystem interoperability, cryptographic, performance, or security implications. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,26 @@ | ||
| ## Summary | ||
|
|
||
| Describe the change and the problem it solves. | ||
|
|
||
| ## Scope | ||
|
|
||
| - [ ] Change is focused and intentionally scoped. | ||
| - [ ] Public API changes are documented. | ||
| - [ ] Security implications have been considered. | ||
|
|
||
| ## Validation | ||
|
|
||
| - [ ] `cargo fmt --all -- --check` | ||
| - [ ] `cargo check --workspace --all-targets --all-features` | ||
| - [ ] `cargo clippy --workspace --all-targets --all-features -- -D warnings` | ||
| - [ ] `cargo test --workspace --all-features` | ||
| - [ ] `cargo doc --workspace --all-features --no-deps` | ||
| - [ ] Supply-chain / SemVer checks pass where applicable. | ||
|
|
||
| ## Compatibility | ||
|
|
||
| Describe any API, behavior, wire-format, storage-format, cryptographic, or interoperability impact. | ||
|
|
||
| ## Security | ||
|
|
||
| Describe new trust boundaries, unsafe behavior, cryptographic changes, input-handling changes, or security-relevant dependencies. Write `None` if not applicable. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,39 +1,65 @@ | ||
| name: ci | ||
| name: Rust CI | ||
|
|
||
| on: | ||
| push: | ||
| branches: | ||
| - main | ||
| pull_request: | ||
| branches: | ||
| - main | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| rust: | ||
| rust-checks: | ||
| name: Rust checks | ||
| runs-on: ubuntu-latest | ||
|
|
||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v7 | ||
| - name: Checkout repository | ||
| uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 | ||
| with: | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
|
|
||
| - name: Install stable Rust | ||
| uses: dtolnay/rust-toolchain@stable | ||
| - name: Install Rust toolchain | ||
| uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d | ||
| with: | ||
| components: rustfmt, clippy | ||
|
|
||
| - name: Check formatting | ||
| - name: Cache Cargo | ||
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 | ||
|
|
||
| - name: Format | ||
| run: cargo fmt --all -- --check | ||
|
|
||
| - name: Check workspace | ||
| run: cargo check --workspace --all-targets --all-features | ||
| - name: Check | ||
| run: cargo check --workspace --all-targets --all-features --locked | ||
|
|
||
| - name: Clippy | ||
| run: cargo clippy --workspace --all-targets --all-features -- -D warnings | ||
| run: cargo clippy --workspace --all-targets --all-features --locked -- -D warnings | ||
|
|
||
| - name: Test | ||
| run: cargo test --workspace --all-features | ||
| run: cargo test --workspace --all-features --locked | ||
|
|
||
| - name: Documentation | ||
| run: cargo doc --workspace --all-features --no-deps | ||
| env: | ||
| RUSTDOCFLAGS: -D warnings | ||
| run: cargo doc --workspace --all-features --no-deps --locked | ||
|
|
||
| - name: Install supply-chain tools | ||
| run: | | ||
| cargo install --locked cargo-audit | ||
| cargo install --locked cargo-deny | ||
| cargo install --locked cargo-semver-checks | ||
|
|
||
| - name: RustSec audit | ||
| run: cargo audit | ||
|
|
||
| - name: Dependency policy | ||
| run: cargo deny check | ||
|
|
||
| - name: SemVer compatibility | ||
| run: cargo semver-checks check-release --workspace --all-features | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,42 @@ | ||
| name: Release-plz | ||
|
|
||
| on: | ||
| workflow_dispatch: | ||
|
jmsbooth marked this conversation as resolved.
|
||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| release-plz-pr: | ||
| name: Release-plz PR | ||
| runs-on: ubuntu-latest | ||
|
|
||
| if: >- | ||
| ${{ github.repository_owner == 'LATTIX-IO' && | ||
| github.ref == 'refs/heads/main' }} | ||
|
|
||
| permissions: | ||
| contents: write | ||
| pull-requests: write | ||
|
|
||
| concurrency: | ||
| group: release-plz-${{ github.ref }} | ||
| cancel-in-progress: false | ||
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 | ||
| with: | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
|
|
||
| - name: Install Rust toolchain | ||
| uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d | ||
|
|
||
| - name: Prepare release PR | ||
| uses: release-plz/action@18641b6c63063cc5ff8786ebf69cd57e8541bae1 | ||
| with: | ||
| command: release-pr | ||
| env: | ||
| GITHUB_TOKEN: ${{ secrets.RELEASE_PLZ_TOKEN }} | ||
| CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }} | ||
|
jmsbooth marked this conversation as resolved.
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,15 @@ | ||
| # Changelog | ||
|
|
||
| All notable changes to this project will be documented in this file. | ||
|
|
||
| The project follows Semantic Versioning once its public API reaches a stable contract. Pre-1.0 releases may evolve more rapidly, with breaking changes documented here. | ||
|
|
||
| ## [Unreleased] | ||
|
|
||
| ### Added | ||
|
|
||
| ### Changed | ||
|
|
||
| ### Fixed | ||
|
|
||
| ### Security |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,21 @@ | ||
| # Code of Conduct | ||
|
|
||
| Lattix open-source projects are technical communities built around professional, good-faith collaboration. | ||
|
|
||
| ## Expected behavior | ||
|
|
||
| - Discuss ideas, implementations, and tradeoffs on their technical merits. | ||
| - Be precise, constructive, and respectful in reviews and issue discussions. | ||
| - Give contributors reasonable opportunity to explain or correct mistakes. | ||
| - Respect security embargoes, responsible-disclosure processes, and project confidentiality requirements. | ||
| - Do not harass, threaten, discriminate against, or deliberately disrupt other participants. | ||
|
|
||
| ## Unacceptable behavior | ||
|
|
||
| Harassment, threats, discriminatory conduct, doxxing, deliberate disruption, malicious submissions, unauthorized disclosure of security-sensitive information, and repeated bad-faith behavior are not permitted. | ||
|
|
||
| ## Enforcement | ||
|
|
||
| Project maintainers may edit or remove contributions, comments, issues, pull requests, or other participation that violates these expectations. Serious or repeated violations may result in temporary or permanent removal from Lattix project spaces. | ||
|
|
||
| For private conduct reports, email secops@lattix.io. For suspected vulnerabilities, use the private reporting mechanisms documented in SECURITY.md. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,15 @@ | ||
| # Support | ||
|
|
||
| ## Bugs and feature requests | ||
|
|
||
| Use GitHub Issues for reproducible defects, feature proposals, documentation gaps, and implementation questions that are appropriate for public discussion. | ||
|
|
||
| ## Security issues | ||
|
|
||
| Do not open a public issue for a suspected vulnerability. | ||
|
|
||
| Use GitHub Private Vulnerability Reporting from the repository Security tab. If Private Vulnerability Reporting is unavailable, email secops@lattix.io. | ||
|
|
||
| ## Commercial support | ||
|
|
||
| These repositories are open-source projects. Public issue trackers do not create a commercial support obligation or response-time commitment. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,31 @@ | ||
| [graph] | ||
| all-features = true | ||
|
|
||
| [advisories] | ||
| yanked = "warn" | ||
| unmaintained = "workspace" | ||
| unsound = "workspace" | ||
|
|
||
| [licenses] | ||
| confidence-threshold = 0.8 | ||
| allow = [ | ||
| "Apache-2.0", | ||
| "Apache-2.0 WITH LLVM-exception", | ||
| "MIT", | ||
| "BSD-2-Clause", | ||
| "BSD-3-Clause", | ||
| "ISC", | ||
| "Zlib", | ||
| "Unicode-3.0", | ||
| "MPL-2.0", | ||
| ] | ||
|
|
||
| [bans] | ||
| multiple-versions = "warn" | ||
| wildcards = "deny" | ||
| highlight = "all" | ||
|
|
||
| [sources] | ||
| unknown-registry = "deny" | ||
| unknown-git = "deny" | ||
| allow-git = [] |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,14 @@ | ||
| [workspace] | ||
| changelog_update = true | ||
| changelog_path = "./CHANGELOG.md" | ||
|
jmsbooth marked this conversation as resolved.
|
||
| dependencies_update = true | ||
| git_release_enable = true | ||
| git_tag_enable = true | ||
| semver_check = true | ||
| release_always = false | ||
| pr_branch_prefix = "release-plz-" | ||
| pr_labels = ["release"] | ||
|
|
||
| [changelog] | ||
| protect_breaking_commits = true | ||
| sort_commits = "newest" | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.