Repository navigation
berth v0.1.2
The plugin release. berth becomes a Claude Code plugin (hooks, MCP server, two skills) installable from the repository's own marketplace; the CLI configures itself (berth init, berth project add); human-only commands are fenced off from agent sessions; the repository is hardened and every code-scanning finding is resolved.
Added
berth initwrites a generic starting policy;berth project add [path]registers a repository with the next free permanent number, its scanneddeclaredports and Compose-derivedextras, additively and idempotently;berth project list(ADR-006).- Claude Code plugin in the repository and the npm package: SessionStart/SessionEnd hooks, the MCP server and two skills,
berth-ports(day-to-day) andberth-onboard(register the repo you are in), installable from the repo's own marketplace (ADR-007). - README quick start: install,
init,project add .,check; the example policy is now a worked example rather than the onboarding path.
Security
- Repository hardening:
mainruleset (pull request required, six required checks, linear history, squash only, no force-push or deletion, no bypass), private vulnerability reporting, read-only default Actions token, Dependabot security updates and secret-scanning push protection; CodeQL findings resolved (TOCTOU reads, view dispatch, exception text in the dashboard API) and workflow installs pinned. - Agent guardrail (ADR-008):
free, any--force,hooks install|uninstall,worktrees prune,init --forceandadopt --owner humanrun only for a human at an interactive terminal with no Claude marker in the environment, or withBERTH_ALLOW_DESTRUCTIVE=1set deliberately; refusals and overrides are logged to~/.local/state/berth/audit.log; shipped skills never name those commands and the MCP server exposes only self-scoped tools. - Writers of
policy.toml(project add,scan --write) serialise on a lock;project addrequires a git repository root unless--allow-non-git. - The plugin's hooks and MCP server start through
hooks/run.sh, which finds Node in common version-manager locations and never fails a session when it cannot.