Skip to content

effGen v0.2.10

Choose a tag to compare

@ctrl-gaurav ctrl-gaurav released this 28 May 01:24
· 960 commits to main since this release

effGen v0.2.10 Release — Security, Edge & Developer Experience

effGen v0.2.10 ships the Security, Edge & Developer Experience layer — hardening effGen end-to-end with secret scanning, dependency auditing, a SBOM pipeline, supply-chain integrity verification, a sandboxed CodeExecutor, OAuth2/OIDC auth with RBAC and a per-request audit log, Docker + Helm production deployments, AWS Lambda (Mangum adapter), a Cloudflare Worker edge proxy, a VSCode extension with prompt-template completion, Jupyter magics, and a live local dashboard. No breaking API changes; every security and DX feature is additive.


What's Changed

Added

Security — Secret Scanning

  • .gitleaks.toml — tuned rule set covering OpenAI, Anthropic, Cerebras, Google, HuggingFace, Groq, Slack, Discord, and Bearer-token patterns. Allowlist for test fixtures with obviously fake keys.
  • .pre-commit-config.yaml — gitleaks pre-commit hook.
  • .github/workflows/secret-scan.yml — CI secret-scan workflow (working-tree + git-history scan). Fails on any detected real secret.
  • tests/security/test_secret_patterns.py — planted-secret detection + repo-history clean assertion.

Security — SBOM (sbom.cdx.json, .github/workflows/sbom.yml)

  • sbom.cdx.json — CycloneDX 1.5 SBOM; every runtime dependency with name, version, and PURL.
  • .github/workflows/sbom.yml — CI SBOM workflow; generates + validates against CycloneDX schema; uploads as release artifact.
  • tests/security/test_sbom.py — asserts every runtime dep from pyproject.toml appears in the SBOM.

Security — Dependency Pinning (requirements-lock.txt, requirements-all-lock.txt)

  • requirements-all-lock.txt — hash-verified lock for .[all] extras (uv-generated; google-protobuf floors + fireworks-ai<0.18 cap resolve deep-resolution issues).

Security — Vulnerability Audit

  • .github/workflows/deps-audit.yml — pip-audit CI; fails on HIGH/CRITICAL.
  • Startup hash verification — EFFGEN_VERIFY_HASHES=1 compares installed-wheel hashes against lockfile; logs hash_verification: ok or drift.
  • tests/security/test_vuln_audit.py — pip-audit --format json; no HIGH/CRITICAL in env.
  • tests/security/test_supply_chain.py — pyproject.toml required fields; hash-verification startup.
  • docs/security/secrets.md, docs/security/sbom.md, docs/security/supply_chain.md

Security — Sandbox for CodeExecutor (effgen/security/sandbox.py)

  • SubprocessSandbox — rootless user-namespace isolation (unshare --map-root-user --net --pid --mount). Network blocked, isolated /tmp, no CAP_SYS_ADMIN required.
  • DockerSandbox — --read-only --network=none --cap-drop=ALL --pids-limit=100 --memory=256m.
  • FirecrackerSandbox — stub interface; NotImplementedError with install instructions.
  • OffSandbox — EFFGEN_SANDBOX_BACKEND=off; loud startup warning; never auto-selected.
  • SandboxConfig — env-driven: EFFGEN_SANDBOX_BACKEND=docker|subprocess|off, EFFGEN_SANDBOX_TIMEOUT=10.
  • CodeExecutor.run(code, language) — dispatches to configured sandbox.
  • tests/security/test_sandbox.py — 35 tests; network-block + filesystem isolation (subprocess); Docker paths skip when daemon unavailable.
  • docs/security/codeexecutor.md — threat model, sandbox architecture, configuration.

Auth — OAuth2/OIDC, RBAC, Audit Log

  • OIDC JWT validation (effgen/server/auth.py) — Bearer JWT validation via authlib. Configurable issuer/JWKS. Public endpoints: /health, /metrics.
  • AuthMiddleware — now accepts explicit dev_mode parameter to override env-var read; prevents test-isolation order failures.
  • RBAC (effgen/server/rbac.py) — Role(name, allowed_tools, allowed_models, max_cost_per_day). RBACBudgetMiddleware (pure-ASGI) enforces allowed_tools (403) and daily cost cap (429 BudgetExceeded).
  • Budget tracking (effgen/server/budget.py) — per-principal daily cost; 429 on cap breach.
  • Audit log (effgen/server/audit.py) — every request/response to ~/.effgen/audit/<date>.jsonl. Fields: ts, principal, role, endpoint, request_summary, response_summary, outcome. Content redacted.
  • Dev mode — EFFGEN_DEV_MODE=1 disables auth. Default off.
  • tests/server/test_auth.py — 57 tests.
  • tests/server/test_audit.py — 28 tests.
  • docs/server/auth.md, docs/server/rbac.md, docs/server/audit.md

Deploy — Docker

  • deploy/docker/Dockerfile — multi-stage, non-root, read-only FS, /health healthcheck, EXTRAS=server.
  • prometheus-client added to server extras.
  • tests/deploy/test_dockerfile.py — 19 Dockerfile structure checks; integration paths skip w/o Docker.
  • docs/deploy/docker.md

Deploy — Kubernetes / Helm

  • deploy/k8s/helm/effgen/ — Deployment, Service, Ingress, ConfigMap, Secret, ServiceAccount, NetworkPolicy, PDB, HPA, PVC. kubeconform strict K8s 1.29 validation.
  • tests/deploy/test_helm_lint.py — 40 tests.
  • docs/deploy/kubernetes.md

Deploy — AWS Lambda

  • deploy/aws_lambda/handler.py — Mangum adapter, lifespan="off", ProviderRegistry preloaded at module level (cold start < 3 s, warm < 100 ms), timeout → 504.
  • deploy/aws_lambda/sam-template.yaml — HTTP API + Lambda + CloudWatch + SecretsManager ref.
  • deploy/aws_lambda/_smoke_runner.py — local smoke runner.
  • tests/deploy/test_lambda_handler.py — 41 tests.
  • docs/deploy/lambda.md

Deploy — Cloudflare Worker

  • deploy/cloudflare/worker.js — CORS, Bearer JWT auth, fixed-window KV rate limiting, upstream forward with duplex:"half", security headers.
  • deploy/cloudflare/wrangler.toml — routes, KV RATE_LIMIT binding, staging/production envs.
  • tests/deploy/test_cloudflare_worker.py — 30 tests: structural + unit + real-fetch round-trip.
  • docs/deploy/cloudflare.md

DX — VSCode Extension

  • tools/vscode-effgen/ — TypeScript extension with prompt-template completion, "Run" code lens, hover docs. npm run compile (TypeScript 5.3 strict, 0 errors).
  • tests/dx/test_vscode_build.py — 20 tests.
  • docs/dx/vscode.md

DX — Jupyter Magics

  • effgen/jupyter/magics.py — %effgen_chat, %%effgen_agent, %effgen_metrics.
  • effgen[jupyter] extra — ipython dependency added.
  • tests/dx/test_jupyter_magics.py — 31 tests.
  • docs/dx/jupyter.md

DX — Local Dashboard

  • effgen/dashboard/ — SPA served at /dashboard (public). Panels: live spans (SSE), metrics, recent runs, SLO burn rates. /dashboard/data.json JSON snapshot.
  • Auth exemption — /dashboard and /dashboard/* bypassed by AuthMiddleware.
  • tests/dx/test_dashboard.py — 46 tests.
  • docs/dx/dashboard.md

Fixed

  • AuthMiddleware.dev_mode — AuthMiddleware now accepts an explicit dev_mode parameter; create_app(dev_mode=False) correctly pins auth to disabled even when EFFGEN_DEV_MODE=1 is set in the environment by prior tests.
  • _normalize_model_id registry fallback — when ProviderRegistry has been reset by a test teardown, _normalize_model_id now falls back to a hardcoded _KNOWN_PROVIDERS set instead of leaving the slash-form intact (which caused the model loader to fall through to the local Transformers path).

Tests Added

File Tests Coverage
tests/security/test_secret_patterns.py 4 (+ many skipped w/o gitleaks) gitleaks detection
tests/security/test_sbom.py 4 (+ 1 skipped w/o cyclonedx) SBOM structure + schema
tests/security/test_vuln_audit.py 6 pip-audit, no HIGH/CRITICAL
tests/security/test_supply_chain.py 30 pyproject fields, hash-verification
tests/security/test_sandbox.py 35 (+ Docker skips) SubprocessSandbox net+fs isolation
tests/server/test_auth.py 57 JWT, RBAC, 401, 403, 429
tests/server/test_audit.py 28 Audit fields, no secrets
tests/deploy/test_dockerfile.py 19 (+ Docker skips) Dockerfile structure
tests/deploy/test_helm_lint.py 40 helm lint + template
tests/deploy/test_lambda_handler.py 41 v1+v2 events, 504, SAM + cfn-lint
tests/deploy/test_cloudflare_worker.py 30 Structural + unit + real-fetch
tests/dx/test_vscode_build.py 20 npm compile, compiled JS
tests/dx/test_jupyter_magics.py 31 Magic loading, chat, agent, metrics
tests/dx/test_dashboard.py 46 /dashboard, data.json, SSE, auth

Verification Results

Check Result
effgen.__version__ 0.2.10 ✓
gitleaks pre-commit Detects planted secrets ✓
gitleaks CI (dir + history) Exit 0 on clean repo ✓
CycloneDX SBOM Generates + validates CycloneDX 1.5 ✓
pip-audit 0 HIGH/CRITICAL ✓
EFFGEN_VERIFY_HASHES=1 ok/drift logged correctly ✓
SubprocessSandbox network block OSError on urlopen ✓
SubprocessSandbox filesystem isolation Host /tmp unchanged ✓
DockerSandbox tests Skip w/o Docker group (not an error) ✓
API server (unauthenticated, non-dev) 401 ✓
RBAC deny_tools 403 ✓
Budget exceeded 429 BudgetExceeded ✓
Audit log Fields correct, no secrets ✓
Dockerfile Builds; /health 200 via uvicorn smoke ✓
Helm chart helm lint clean; kubeconform strict K8s 1.29 ✓
Lambda handler 41/41 tests pass; live Cerebras call through handler ✓
Cloudflare Worker wrangler --dry-run validates; live round-trip ✓
VSCode extension npm run compile 0 errors ✓
Jupyter magics Live Cerebras llama3.1-8b smoke ✓
Dashboard /dashboard 200 + /dashboard/data.json valid JSON ✓
AuthMiddleware dev_mode isolation test_dashboard_lookalike 401 passes in full suite ✓
_normalize_model_id after registry reset cerebras:llama3.1-8b ✓
Wheel build effgen-0.2.10-py3-none-any.whl built cleanly ✓
Wheel smoke python -c "import effgen; assert effgen.__version__ == '0.2.10'" ✓
Full regression suite 3721 passed, 0 failed (88 skipped, 14 xfailed) ✓

Upgrading from v0.2.9

No breaking API changes. All new modules are additive.

pip install --upgrade effgen

Security Quick Start

# Install pre-commit secret-scanning hook
pip install pre-commit && pre-commit install

# Run a sandboxed code cell
python -c "
import asyncio
from effgen.security.sandbox import get_sandbox, SandboxConfig
async def main():
    config = SandboxConfig(backend='subprocess', timeout=10)
    sandbox = await get_sandbox(config)
    result = await sandbox.run('print(\"hello, sandbox\")', 'python', config)
    print(result.stdout)
asyncio.run(main())
"

Auth Quick Start

# Production — OIDC
export EFFGEN_OIDC_ISSUER=https://your-tenant.auth0.com/
export EFFGEN_OIDC_CLIENT_ID=your-client-id
effgen serve --port 8000

# Dev mode (auth disabled — local only)
EFFGEN_DEV_MODE=1 effgen serve --port 8000

Deploy Quick Start

# Docker
docker build -f deploy/docker/Dockerfile -t effgen:0.2.10 .
docker run -p 8000:8000 --env-file .env effgen:0.2.10

# Kubernetes
helm install effgen deploy/k8s/helm/effgen/

# AWS Lambda
cd deploy/aws_lambda && sam build && sam deploy

# Cloudflare Worker
cd deploy/cloudflare && wrangler deploy

DX Quick Start

# Jupyter
%load_ext effgen.jupyter
%effgen_chat "What is 17 * 23?"
%%effgen_agent general
Summarise the top HackerNews stories today.
# Dashboard
EFFGEN_DEV_MODE=1 effgen serve --port 8000
open http://localhost:8000/dashboard

Full Changelog: CHANGELOG.md [0.2.10]
News & Highlights: NEWS.md
Security Overview: docs/security/
Deployment Guides: docs/deploy/
DX Guides: docs/dx/