effGen v0.2.10
effGen v0.2.10 Release — Security, Edge & Developer Experience
effGen v0.2.10 ships the Security, Edge & Developer Experience layer — hardening effGen end-to-end with secret scanning, dependency auditing, a SBOM pipeline, supply-chain integrity verification, a sandboxed CodeExecutor, OAuth2/OIDC auth with RBAC and a per-request audit log, Docker + Helm production deployments, AWS Lambda (Mangum adapter), a Cloudflare Worker edge proxy, a VSCode extension with prompt-template completion, Jupyter magics, and a live local dashboard. No breaking API changes; every security and DX feature is additive.
What's Changed
Added
Security — Secret Scanning
.gitleaks.toml— tuned rule set covering OpenAI, Anthropic, Cerebras, Google, HuggingFace, Groq, Slack, Discord, and Bearer-token patterns. Allowlist for test fixtures with obviously fake keys..pre-commit-config.yaml— gitleaks pre-commit hook..github/workflows/secret-scan.yml— CI secret-scan workflow (working-tree + git-history scan). Fails on any detected real secret.tests/security/test_secret_patterns.py— planted-secret detection + repo-history clean assertion.
Security — SBOM (sbom.cdx.json, .github/workflows/sbom.yml)
sbom.cdx.json— CycloneDX 1.5 SBOM; every runtime dependency with name, version, and PURL..github/workflows/sbom.yml— CI SBOM workflow; generates + validates against CycloneDX schema; uploads as release artifact.tests/security/test_sbom.py— asserts every runtime dep frompyproject.tomlappears in the SBOM.
Security — Dependency Pinning (requirements-lock.txt, requirements-all-lock.txt)
requirements-all-lock.txt— hash-verified lock for.[all]extras (uv-generated;google-protobuffloors +fireworks-ai<0.18cap resolve deep-resolution issues).
Security — Vulnerability Audit
.github/workflows/deps-audit.yml—pip-auditCI; fails on HIGH/CRITICAL.- Startup hash verification —
EFFGEN_VERIFY_HASHES=1compares installed-wheel hashes against lockfile; logshash_verification: okordrift. tests/security/test_vuln_audit.py—pip-audit --format json; no HIGH/CRITICAL in env.tests/security/test_supply_chain.py—pyproject.tomlrequired fields; hash-verification startup.docs/security/secrets.md,docs/security/sbom.md,docs/security/supply_chain.md
Security — Sandbox for CodeExecutor (effgen/security/sandbox.py)
SubprocessSandbox— rootless user-namespace isolation (unshare --map-root-user --net --pid --mount). Network blocked, isolated/tmp, noCAP_SYS_ADMINrequired.DockerSandbox—--read-only --network=none --cap-drop=ALL --pids-limit=100 --memory=256m.FirecrackerSandbox— stub interface;NotImplementedErrorwith install instructions.OffSandbox—EFFGEN_SANDBOX_BACKEND=off; loud startup warning; never auto-selected.SandboxConfig— env-driven:EFFGEN_SANDBOX_BACKEND=docker|subprocess|off,EFFGEN_SANDBOX_TIMEOUT=10.CodeExecutor.run(code, language)— dispatches to configured sandbox.tests/security/test_sandbox.py— 35 tests; network-block + filesystem isolation (subprocess); Docker paths skip when daemon unavailable.docs/security/codeexecutor.md— threat model, sandbox architecture, configuration.
Auth — OAuth2/OIDC, RBAC, Audit Log
- OIDC JWT validation (
effgen/server/auth.py) — Bearer JWT validation viaauthlib. Configurable issuer/JWKS. Public endpoints:/health,/metrics. AuthMiddleware— now accepts explicitdev_modeparameter to override env-var read; prevents test-isolation order failures.- RBAC (
effgen/server/rbac.py) —Role(name, allowed_tools, allowed_models, max_cost_per_day).RBACBudgetMiddleware(pure-ASGI) enforcesallowed_tools(403) and daily cost cap (429BudgetExceeded). - Budget tracking (
effgen/server/budget.py) — per-principal daily cost; 429 on cap breach. - Audit log (
effgen/server/audit.py) — every request/response to~/.effgen/audit/<date>.jsonl. Fields:ts, principal, role, endpoint, request_summary, response_summary, outcome. Content redacted. - Dev mode —
EFFGEN_DEV_MODE=1disables auth. Default off. tests/server/test_auth.py— 57 tests.tests/server/test_audit.py— 28 tests.docs/server/auth.md,docs/server/rbac.md,docs/server/audit.md
Deploy — Docker
deploy/docker/Dockerfile— multi-stage, non-root, read-only FS,/healthhealthcheck,EXTRAS=server.prometheus-clientadded toserverextras.tests/deploy/test_dockerfile.py— 19 Dockerfile structure checks; integration paths skip w/o Docker.docs/deploy/docker.md
Deploy — Kubernetes / Helm
deploy/k8s/helm/effgen/— Deployment, Service, Ingress, ConfigMap, Secret, ServiceAccount, NetworkPolicy, PDB, HPA, PVC.kubeconformstrict K8s 1.29 validation.tests/deploy/test_helm_lint.py— 40 tests.docs/deploy/kubernetes.md
Deploy — AWS Lambda
deploy/aws_lambda/handler.py— Mangum adapter,lifespan="off",ProviderRegistrypreloaded at module level (cold start < 3 s, warm < 100 ms), timeout → 504.deploy/aws_lambda/sam-template.yaml— HTTP API + Lambda + CloudWatch + SecretsManager ref.deploy/aws_lambda/_smoke_runner.py— local smoke runner.tests/deploy/test_lambda_handler.py— 41 tests.docs/deploy/lambda.md
Deploy — Cloudflare Worker
deploy/cloudflare/worker.js— CORS, Bearer JWT auth, fixed-window KV rate limiting, upstream forward withduplex:"half", security headers.deploy/cloudflare/wrangler.toml— routes, KVRATE_LIMITbinding, staging/production envs.tests/deploy/test_cloudflare_worker.py— 30 tests: structural + unit + real-fetch round-trip.docs/deploy/cloudflare.md
DX — VSCode Extension
tools/vscode-effgen/— TypeScript extension with prompt-template completion, "Run" code lens, hover docs.npm run compile(TypeScript 5.3 strict, 0 errors).tests/dx/test_vscode_build.py— 20 tests.docs/dx/vscode.md
DX — Jupyter Magics
effgen/jupyter/magics.py—%effgen_chat,%%effgen_agent,%effgen_metrics.effgen[jupyter]extra —ipythondependency added.tests/dx/test_jupyter_magics.py— 31 tests.docs/dx/jupyter.md
DX — Local Dashboard
effgen/dashboard/— SPA served at/dashboard(public). Panels: live spans (SSE), metrics, recent runs, SLO burn rates./dashboard/data.jsonJSON snapshot.- Auth exemption —
/dashboardand/dashboard/*bypassed byAuthMiddleware. tests/dx/test_dashboard.py— 46 tests.docs/dx/dashboard.md
Fixed
AuthMiddleware.dev_mode—AuthMiddlewarenow accepts an explicitdev_modeparameter;create_app(dev_mode=False)correctly pins auth to disabled even whenEFFGEN_DEV_MODE=1is set in the environment by prior tests._normalize_model_idregistry fallback — whenProviderRegistryhas been reset by a test teardown,_normalize_model_idnow falls back to a hardcoded_KNOWN_PROVIDERSset instead of leaving the slash-form intact (which caused the model loader to fall through to the local Transformers path).
Tests Added
| File | Tests | Coverage |
|---|---|---|
tests/security/test_secret_patterns.py |
4 (+ many skipped w/o gitleaks) | gitleaks detection |
tests/security/test_sbom.py |
4 (+ 1 skipped w/o cyclonedx) | SBOM structure + schema |
tests/security/test_vuln_audit.py |
6 | pip-audit, no HIGH/CRITICAL |
tests/security/test_supply_chain.py |
30 | pyproject fields, hash-verification |
tests/security/test_sandbox.py |
35 (+ Docker skips) | SubprocessSandbox net+fs isolation |
tests/server/test_auth.py |
57 | JWT, RBAC, 401, 403, 429 |
tests/server/test_audit.py |
28 | Audit fields, no secrets |
tests/deploy/test_dockerfile.py |
19 (+ Docker skips) | Dockerfile structure |
tests/deploy/test_helm_lint.py |
40 | helm lint + template |
tests/deploy/test_lambda_handler.py |
41 | v1+v2 events, 504, SAM + cfn-lint |
tests/deploy/test_cloudflare_worker.py |
30 | Structural + unit + real-fetch |
tests/dx/test_vscode_build.py |
20 | npm compile, compiled JS |
tests/dx/test_jupyter_magics.py |
31 | Magic loading, chat, agent, metrics |
tests/dx/test_dashboard.py |
46 | /dashboard, data.json, SSE, auth |
Verification Results
| Check | Result |
|---|---|
effgen.__version__ |
0.2.10 ✓ |
| gitleaks pre-commit | Detects planted secrets ✓ |
| gitleaks CI (dir + history) | Exit 0 on clean repo ✓ |
| CycloneDX SBOM | Generates + validates CycloneDX 1.5 ✓ |
| pip-audit | 0 HIGH/CRITICAL ✓ |
EFFGEN_VERIFY_HASHES=1 |
ok/drift logged correctly ✓ |
| SubprocessSandbox network block | OSError on urlopen ✓ |
| SubprocessSandbox filesystem isolation | Host /tmp unchanged ✓ |
| DockerSandbox tests | Skip w/o Docker group (not an error) ✓ |
| API server (unauthenticated, non-dev) | 401 ✓ |
| RBAC deny_tools | 403 ✓ |
| Budget exceeded | 429 BudgetExceeded ✓ |
| Audit log | Fields correct, no secrets ✓ |
| Dockerfile | Builds; /health 200 via uvicorn smoke ✓ |
| Helm chart | helm lint clean; kubeconform strict K8s 1.29 ✓ |
| Lambda handler | 41/41 tests pass; live Cerebras call through handler ✓ |
| Cloudflare Worker | wrangler --dry-run validates; live round-trip ✓ |
| VSCode extension | npm run compile 0 errors ✓ |
| Jupyter magics | Live Cerebras llama3.1-8b smoke ✓ |
| Dashboard | /dashboard 200 + /dashboard/data.json valid JSON ✓ |
AuthMiddleware dev_mode isolation |
test_dashboard_lookalike 401 passes in full suite ✓ |
_normalize_model_id after registry reset |
cerebras:llama3.1-8b ✓ |
| Wheel build | effgen-0.2.10-py3-none-any.whl built cleanly ✓ |
| Wheel smoke | python -c "import effgen; assert effgen.__version__ == '0.2.10'" ✓ |
| Full regression suite | 3721 passed, 0 failed (88 skipped, 14 xfailed) ✓ |
Upgrading from v0.2.9
No breaking API changes. All new modules are additive.
pip install --upgrade effgenSecurity Quick Start
# Install pre-commit secret-scanning hook
pip install pre-commit && pre-commit install
# Run a sandboxed code cell
python -c "
import asyncio
from effgen.security.sandbox import get_sandbox, SandboxConfig
async def main():
config = SandboxConfig(backend='subprocess', timeout=10)
sandbox = await get_sandbox(config)
result = await sandbox.run('print(\"hello, sandbox\")', 'python', config)
print(result.stdout)
asyncio.run(main())
"Auth Quick Start
# Production — OIDC
export EFFGEN_OIDC_ISSUER=https://your-tenant.auth0.com/
export EFFGEN_OIDC_CLIENT_ID=your-client-id
effgen serve --port 8000
# Dev mode (auth disabled — local only)
EFFGEN_DEV_MODE=1 effgen serve --port 8000Deploy Quick Start
# Docker
docker build -f deploy/docker/Dockerfile -t effgen:0.2.10 .
docker run -p 8000:8000 --env-file .env effgen:0.2.10
# Kubernetes
helm install effgen deploy/k8s/helm/effgen/
# AWS Lambda
cd deploy/aws_lambda && sam build && sam deploy
# Cloudflare Worker
cd deploy/cloudflare && wrangler deployDX Quick Start
# Jupyter
%load_ext effgen.jupyter
%effgen_chat "What is 17 * 23?"
%%effgen_agent general
Summarise the top HackerNews stories today.# Dashboard
EFFGEN_DEV_MODE=1 effgen serve --port 8000
open http://localhost:8000/dashboardFull Changelog: CHANGELOG.md [0.2.10]
News & Highlights: NEWS.md
Security Overview: docs/security/
Deployment Guides: docs/deploy/
DX Guides: docs/dx/