Skip to content

Releases: DNYoussef/guardspine-code-action

v2.7.2 - same artifact as v2.7.1, pinned by immutable digest

Choose a tag to compare

@DNYoussef DNYoussef released this 29 Jul 13:57

No behaviour change. Same image bytes as v2.7.1, referenced immutably.

v2.7.1 pinned the runtime image by tag:

image: 'docker://ghcr.io/dnyoussef/guardspine-code-action:2.7.1'

A registry tag is mutable — re-pushing 2.7.1 would silently change what every consumer pinned to @v2.7.1 executes, while the Dockerfile one directory away digest-pins its own base image. Holding our own artifact to a weaker standard than someone else's is an awkward asymmetry for a supply-chain governance product.

v2.7.2 pins by digest:

image: 'docker://ghcr.io/dnyoussef/guardspine-code-action@sha256:4b978fb4...'

action.yml is not copied into the image, so this changes the reference, not the artifact — v2.7.2 runs the exact bytes already built and published for v2.7.1.

Use @v2

A v2 tag now exists and points here. Before this, only v2.7.0 and v2.7.1 existed, so uses: ...@v2 failed to resolve for anyone following the usual major-version convention — and every documented example still said DNYoussef/codeguard-action@v1, which resolves to the genuine v1.0.5 lineage and installs years-old code without erroring.

- uses: DNYoussef/guardspine-code-action@v2

Pin @v2.7.2 instead where you need byte reproducibility.

v2.7.0 remains superseded — it was tagged off main, where action.yml carries image: 'Dockerfile', so it rebuilds the container on every run instead of pulling the published image.

v2.7.1 - nine more packs runnable (use this, not v2.7.0)

Choose a tag to compare

@DNYoussef DNYoussef released this 29 Jul 00:51

Same content as v2.7.0, with one fix that matters for every run.

Use v2.7.1. v2.7.0 was tagged straight off main, where action.yml carries image: 'Dockerfile' so that CI builds from current source. That makes a customer run rebuild the container every time instead of pulling the published, signed image. v2.7.1 pins docker://ghcr.io/dnyoussef/guardspine-code-action:2.7.1, the same way v2.6.0 did. v2.7.0 works, it is just slow and does not use the published artifact.

Nine more packs runnable (13 → 22). None removed.

Six of them the dashboard already sold while this engine could not load them: sox-itgc, eu-ai-act, cfr-part-11, gdpr-privacy-by-design, and cmmc-level1 / cpcsc-level1 (enterprise tier). Selecting one produced a warning in the CI log and then a scan governed by default — five generic rules instead of the regime paid for.

If you had one of these selected, your scans were not enforcing it. After upgrading they will, so expect new findings.

Three are new regulated-finance packs whose rules cite the instrument they come from: dora-ict-requirements, nacha-us-payments-requirements, psd2-sca-requirements (aliases dora, nacha, psd2). They map changes to control themes; they do not certify compliance.

Reviewer models now see the policy in every round

Previously only round 1 was shown the rubric while the last round produced the verdict, so a finding had to survive deliberation without the rule that justified it. Deliberation only runs when round 1 disagrees — so the policy was missing in exactly the contested cases.

One rule contract

  • enabled: false is now honoured; such rules were previously still enforced
  • pattern-less semantic rules now reach the models instead of being dropped
  • an invalid pattern fails loudly instead of being laundered into "the model will handle it"

Supply chain

Renderer and catalogue are now one published artifact (guardspine-prompts 0.2.0), exact-pinned and hashed, shared with the dashboard. Shipped packs live in an installed distribution, so a pull request cannot plant a file that passes as a shipped pack.

- uses: DNYoussef/guardspine-code-action@v2.7.1

v2.7.0 - the engine runs what the dashboard sells

Choose a tag to compare

@DNYoussef DNYoussef released this 29 Jul 00:47
500128a

Nine more packs runnable (13 → 22). None removed.

Six packs the dashboard already sold but the engine could not load

sox-itgc, eu-ai-act, cfr-part-11, gdpr-privacy-by-design, and cmmc-level1 / cpcsc-level1 (enterprise tier).

Selecting one of these produced a warning in the CI log and then a scan governed by default — five generic rules instead of the regime the customer paid for. All six now load. If you selected one of these packs before, your scans were not enforcing it; after upgrading they will, so expect new findings.

Three new regulated-finance packs

dora-ict-requirements (DORA ICT), nacha-us-payments-requirements (US ACH), psd2-sca-requirements (PSD2 SCA) — each rule cites the instrument it comes from, so a finding names the control an examiner asks about. Short aliases dora, nacha, psd2 work.

These map changes to control themes. They do not certify compliance.

Reviewer models now see the policy in every round

Previously only round 1 was shown the rubric, while the last round produced the verdict — so a finding had to survive deliberation without the rule that justified it, against peers who could not see it either. Deliberation only runs when round 1 disagrees, so the policy was missing in exactly the contested cases.

One rule contract

  • enabled: false is now honoured (it was previously ignored, and such rules were still enforced)
  • semantic, pattern-less rules now reach the models instead of being dropped — a control regex cannot express is exactly what a reviewer model is for
  • an invalid pattern now fails loudly instead of being quietly laundered into "the model will handle it"

Supply chain

The prompt renderer and the rubric catalogue are now one published artifact — guardspine-prompts 0.2.0 — exact-pinned and hashed, shared with the dashboard. No vendored copies remain. Shipped packs live in an installed distribution, so a pull request cannot plant a file that passes as a shipped pack.

Upgrading

- uses: DNYoussef/guardspine-code-action@v2.7.0

Image: ghcr.io/dnyoussef/guardspine-code-action:2.7.0

v2.1.0 - Evidence anti-forgery + whole-bundle seal

Choose a tag to compare

@DNYoussef DNYoussef released this 25 Jun 11:23

v2.1.0

Evidence bundles go from tamper-evident to tamper-proof, plus a compliance-receipt fix. (PR #33)

Anti-forgery (opt-in)

  • _sign_bundle embeds the signer public key (self-contained bundles).
  • verify_bundle_chain(trusted_fingerprints=, trusted_keys=, require_signature=) verifies asymmetric signatures over canonical_json(bundle - signatures), trusting only a fingerprint recomputed from the key bytes (or a key_id in a caller's trusted set). HMAC never counts. New attestation_key action input.

Integrity

  • Whole-bundle keyless bundle_hash seal (covers summary/analysis/context); downgrade guard requires the seal for any sealed-class bundle; seal_bundle won't silently drop signatures.

Compliance

  • SOC 2 / HIPAA / PCI control category + name now rendered in the receipt (not "general").

Verified: full suite 290 green; cross-verified against guardspine-kernel-py; crucible (4 Codex rounds CLEAN + 6-lens red-team, no forgery). Backward-compatible.

🤖 Generated with Claude Code

v2.0.0 - GuardSpine Code

Choose a tag to compare

@DNYoussef DNYoussef released this 14 Jun 00:39

v2.0.0 relicenses this project from Apache-2.0 to the Business Source License 1.1.

The source stays readable, auditable, and self-hostable. Free for non-commercial use, evaluation, and organizations under USD 1,000,000 annual revenue. Other production use needs a commercial license (legal@guardspine.ai). Each version converts to Apache-2.0 four years after release. v1.x and earlier remain Apache-2.0 forever.

This action is renamed from CodeGuard to GuardSpine Code; the repository moved to DNYoussef/guardspine-code-action (old URLs and uses: references redirect automatically). Point new workflows at uses: DNYoussef/guardspine-code-action@v2.

v1.0.5 — unified decision gate + verdict/bundle_id aliases

Choose a tag to compare

@DNYoussef DNYoussef released this 19 Apr 03:06
9147821

PR #18 unified the L3/L4 review-gate code paths (R1/R2). PR #19 emits verdict + bundle_id as stable reviewer-style output aliases for downstream workflows (R3).

What changed

  • L3/L4 decision card now respects requires_approval via a single DecisionPacket.effective_decision source of truth; L4 special-case override deleted (#18)
  • File-pattern risk drivers populated on L3/L4 when tier came from file scoring (#18)
  • New outputs.verdict: APPROVE / CONDITIONS / BLOCK mapped from decision (#19)
  • New outputs.bundle_id: bundle identifier string when generate_bundle is enabled (#19)

Compat

  • All previous outputs (decision, requires_approval, bundle_path) unchanged
  • @v1 now resolves to this release (moved forward from 1296cb3 to 9147821)
  • ghcr.io/dnyoussef/codeguard-action:main rebuilt with these changes

Validation

  • 71/71 unit + regression tests pass
  • 5-PR rehearsal matrix (L0-L4) runs green with live AI provider (all models_failed=0)

fix(docker): pass all inputs as env vars so Docker container receives them

Choose a tag to compare

@m1el m1el released this 16 Mar 18:57
Docker actions do not auto-set INPUT_* env vars — only composite and
JavaScript actions do. The entrypoint reads every input via
get_env("INPUT_..."), so they were all empty inside the container.

Replace the unused positional `args` with an explicit `env` block
mapping every declared input to its INPUT_* env var.

v1.0.1 - Private repo diff fix

Choose a tag to compare

@DNYoussef DNYoussef released this 13 Feb 14:14

Fix

  • Use GitHub API URL (pr.url) instead of web URL (pr.diff_url) for fetching PR diffs
  • Fixes 404 error when CodeGuard runs on private repositories
  • No behavior change for public repos

Upgrade

If using @v1, the fix is automatic (tag updated).

v1.0.0 - Initial Marketplace Release

Choose a tag to compare

@DNYoussef DNYoussef released this 20 Jan 04:24

GuardSpine CodeGuard v1.0.0

AI-aware code governance with cryptographically verifiable evidence bundles.

Features

  • Risk Classification (L0-L4): Automatic risk tier assignment based on file patterns and content analysis
    • Evidence Bundles: Hash-chained JSON bundles for audit trails
    • Diff Postcard: PR comments showing risk tier, drivers, and findings
    • Evidence Mappings: Pre-built rule sets for SOC 2, HIPAA, and PCI-DSS audit support
    • SARIF Integration: Export findings to GitHub Security tab

AI Provider Support

  • OpenRouter (100+ models): Claude, GPT-4, Gemini, Llama
    • Anthropic Direct: Claude API
    • OpenAI Direct: GPT API
    • Ollama: Local/on-prem AI for air-gapped environments

Quick Start

- uses: DNYoussef/codeguard-action@v1
-   with:
-     github_token: ${{ secrets.GITHUB_TOKEN }}
- ```
See [README](https://github.com/DNYoussef/codeguard-action#readme) for full documentation.