Skip to content

berth v0.1.2

Choose a tag to compare

@github-actions github-actions released this 14 Sep 07:36
· 29 commits to main since this release
884c06f

The plugin release. berth becomes a Claude Code plugin (hooks, MCP server, two skills) installable from the repository's own marketplace; the CLI configures itself (berth init, berth project add); human-only commands are fenced off from agent sessions; the repository is hardened and every code-scanning finding is resolved.

Added

  • berth init writes a generic starting policy; berth project add [path] registers a repository with the next free permanent number, its scanned declared ports and Compose-derived extras, additively and idempotently; berth project list (ADR-006).
  • Claude Code plugin in the repository and the npm package: SessionStart/SessionEnd hooks, the MCP server and two skills, berth-ports (day-to-day) and berth-onboard (register the repo you are in), installable from the repo's own marketplace (ADR-007).
  • README quick start: install, init, project add ., check; the example policy is now a worked example rather than the onboarding path.

Security

  • Repository hardening: main ruleset (pull request required, six required checks, linear history, squash only, no force-push or deletion, no bypass), private vulnerability reporting, read-only default Actions token, Dependabot security updates and secret-scanning push protection; CodeQL findings resolved (TOCTOU reads, view dispatch, exception text in the dashboard API) and workflow installs pinned.
  • Agent guardrail (ADR-008): free, any --force, hooks install|uninstall, worktrees prune, init --force and adopt --owner human run only for a human at an interactive terminal with no Claude marker in the environment, or with BERTH_ALLOW_DESTRUCTIVE=1 set deliberately; refusals and overrides are logged to ~/.local/state/berth/audit.log; shipped skills never name those commands and the MCP server exposes only self-scoped tools.
  • Writers of policy.toml (project add, scan --write) serialise on a lock; project add requires a git repository root unless --allow-non-git.
  • The plugin's hooks and MCP server start through hooks/run.sh, which finds Node in common version-manager locations and never fails a session when it cannot.