Repository navigation
PKG-Defender v1.0.6
PKG-Defender v1.0.6
Released July 23, 2026
What's Changed
Added
- ClusterFuzzLite fuzzing integration —
.clusterfuzzlite/Dockerfileand.clusterfuzzlite/build.shfor OSS-Fuzz compatible continuous fuzzing infrastructure - Atheris fuzz test for lock file parsing —
fuzz/parse_lockfiles_fuzz.pywithatheris>=2.3.0under[fuzz]optional dependencies GOVERNANCE.md— project governance document defining roles, decision-making, and conflict resolution processes- Secure design principles statement in
docs/explanation/security-model.md - Property-based fuzzing tests using hypothesis — 6 invariants verified
for threat scoring logic (tests/unit/core/test_scoring_properties.py) - hypothesis>=6.0 dependency added to test profile
- Trigger improvements: Both sync workflows now support
workflow_dispatch(manual trigger from GitHub UI) and a weeklyschedule(Monday 6am UTC) as safety nets, in addition to the push-based path trigger. This ensures changes are synced even when the push path filter misses them (e.g., when changes span multiple commits and only the HEAD commit matches the path filter, or diff timeouts/limits are hit). - Explicit content-based sync detection: Both sync workflows now use
diff -q/diff -rqfor file comparison instead ofgit status --porcelain. This provides: - Clear per-file match/mismatch logging in workflow output
- True content comparison (not timestamp-based) with no reliance on git commit history
- Two-phase detection-then-apply: files are compared before any are copied
- A safety-net verification step after apply to catch any discrepancies
sync-brew-formula.pynow supports--outputflag for two-phase formula detection, enabling the merge result to be inspected before overwriting the target.- Cross-repo sync workflows: Two new GitHub Actions workflows and a Python merge script that automatically sync the
homebrew-tap/andgithub-action/source-of-truth directories to their respective subsidiary repos (divisionseven/homebrew-pkg-defenderanddivisionseven/pkg-defender-action) whenever files in those directories change onmain. .github/workflows/sync-homebrew-tap.yml— Syncshomebrew-tap/→homebrew-pkg-defendervia PR. Uses a smart-merge script to preserveversion/url/sha256from the target formula (set by the release pipeline) while applying all other structural changes (desc, caveats, test block, etc.) from source..github/workflows/sync-github-action.yml— Syncsgithub-action/→pkg-defender-actionvia full directory rsync, excludingnode_modules/,plans/, andinternal_documentation/..github/scripts/sync-brew-formula.py— Standalone Python script for section-aware Homebrew formula merging, preserving only version/URL/SHA256 from the target.- CodeQL SAST scanning workflow (
.github/workflows/codeql.yml) — runs on push/PR to main/develop and weekly schedule for Python code analysis - OpenSSF Scorecard analysis workflow (
.github/workflows/scorecard.yml) — evaluates repository security posture, pushes results to Scorecard API and uploads SARIF to code scanning - SLSA Build Level 3 provenance generation in release pipeline via
slsa-github-generator— provides verifiable build integrity attestations for all release artifacts - Binary artifact attestations via
actions/attest-build-provenance— cryptographically links release binaries to their build workflow - Docker image provenance attestation with push-to-registry in release pipeline
- SPDX license and copyright headers (
# Copyright (c) 2026 DIVISION 7 | MI-7 (@divisionseven)and# SPDX-License-Identifier: Apache-2.0) added to all 113 source files undersrc/pkg_defender/ scripts/add_spdx_headers.py— automated script for managing SPDX and copyright headers across the codebase
Changed
tests/fixtures/lock_files/osv-scanner.tomladded with[[PackageOverrides]] ignore = trueto suppress 20 OSV-Scanner false positives from test fixture lock files — fixes OpenSSF Scorecard Vulnerabilities check scoring 0/10idna>=3.15constraint added to[project.dependencies]— resolves PYSEC-2026-215 (idna 3.11 vulnerable);uv.lockupgraded idna from 3.11 to 3.18github-action/dev dependencies refreshed vianpm audit fix:@babel/core7.29.0→7.29.7 (GHSA-4x5r-pxfx-6jf8),js-yaml3.14.2→3.15.0 (GHSA-h67p-54hq-rp68)aiohttpdependency updated from>=3.9,<3.14to>=3.14.1,<4.0— resolves 21 CVEs in the HTTP clientgithub-action/dependencies refreshed:@actions/corebumped to 2.x,undicioverridden to 6.27.0 — fixes 3 HIGH severity CVEs- SLSA provenance job now sets
upload-assets: trueso*.intoto.jsonlattestation artifacts appear in GitHub Release assets - Replaced all
pip installcommands with SHA256-pinneduvequivalents in CI workflows (ci.yml, release.yml, github-action/ci.yml) for reproducible dependency installation python:3.11-alpineDocker image base pinned to SHA256 digest for immutable buildsCONTRIBUTING.md— added Developer Certificate of Origin (DCO) requirement with sign-off instructionsdocs/explanation/security-model.md— added Secure Design Principles section covering fail-closed, least privilege, defense in depth, secure defaults, and input validationREADME.md— added OpenSSF Scorecard and OpenSSF Best Practices (placeholder) badges to header- Downstream workflow commits (
release.yml,sync-homebrew-tap.yml,sync-github-action.yml) now authored asDivision 7withCo-authored-by: github-actions[bot]instead of pure bot authorship for traceability .github/workflows/release.ymltoken permissions scoped fromcontents: writetocontents: readwith per-job overrides, following the least-privilege principle
Fixed
- PyPI publish rejected with "400 File too large. Limit is 100 MB" — root
cause: Hatchling's default VCS mode bundled all git-tracked files into the
sdist, including 3 demo GIFs (152 MB total) indocs/assets/demo/. Added
[tool.hatch.build.targets.sdist]withexcludepatterns for 12 dev-only
directories. sdist reduced from ~150 MB to 1.9 MB. - Release pipeline: PyPI publish job no longer fails with
uv: command not found— addedastral-sh/setup-uvstep and switched touv publish dist/*(replacing twine-based publish). Binary build no longer crashes withModuleNotFoundError: No module named 'click'in Homebrew — switched fromuv tool run pyinstallertouv run pyinstallerso PyInstaller can see all project dependencies. Addedpyinstaller>=6.21.0as a dev dependency. - Release pipeline
build-dockerjob failed with "Resource not accessible by integration" when calling the GitHub Attestations API — root cause: the job'spermissionsblock was missingattestations: writeandartifact-metadata: write, so theGITHUB_TOKENcould not authorize the attestation call. Added both permissions to thebuild-dockerjob (release.yml). Verified by the full test suite passing (4,481 tests). - SLSA provenance generator failed with a ref-format error when
release.ymlis pinned to a commit SHA — root cause:slsa-github-generator'sbuilder-fetch.shrequires arefs/tags/vX.Y.Zref but received a bare SHA, so the script could not resolve the generator source. Addedcompile-generator: trueto theprovenancejob, which bypassesbuilder-fetch.shand compiles the generator from source instead. This keeps the workflow SHA-pinned and maintains OpenSSF Scorecard Pinned-Dependencies compliance (release.yml). Verified by the full test suite passing (4,481 tests). actions/attest-build-provenancewas pinned to v2.4.0, which internally uses Node.js 20 — root cause: Node.js 20 reached end-of-life on the GitHub Actions runners, causing the attestation step to fail with a Node.js deprecation error. Updatedactions/attest-build-provenanceto v4.1.1 (SHA0f67c3f4856b2e3261c31976d6725780e5e4c373), which uses Node.js 24. Also updateddocker/build-push-actionfrom v7.0.0 to v7.3.0 (SHA53b7df96c91f9c12dcc8a07bcb9ccacbed38856a) to pick up bugfixes in the Docker build step (release.yml).- Docker build failure: replace unsupported
uv pip install --userwithuv pip install --systemto fix compatibility with newer uv versions - Update GitHub Actions to Node.js 24-compatible versions to prevent deprecation failures across 10 workflow files
- Downstream repo checkout in
release.yml,sync-homebrew-tap.yml, andsync-github-action.ymlfailed becauseactions/checkoutrejects/tmp/paths outside the workspace. Replacedactions/checkoutwithgit cloneusing the GitHub App token for all downstream repo checkouts - Sync workflow commits to downstream repos were unsigned, triggering GitHub's "unsigned commit" security alerts on
homebrew-pkg-defenderandpkg-defender-action. Replaced manualgit commit/git pushoperations withpeter-evans/create-pull-request@v8andactions/create-github-app-token@v3insync-homebrew-tap.yml,sync-github-action.yml, andrelease.yml— all downstream commits are now signed by the GitHub App identity - GitHub Action CI failed on Ubuntu 24.04 runners due to PEP 668 blocking system-wide Python package installs (
externally-managed-environment). Replacedpython3 -c "import yaml..."YAML validation invalidate.shwith Node.jsrequire('yaml')and removed the now-unnecessarysetup-uv+uv pip install --system pyyamlsteps from the action's CI and release workflows aiohttp>=3.14.1,<4.0constraint — the requirement was
incorrectly constrained toaiohttp<3.14during aiohttp 3.14/aioresponses
0.7.9 compatibility investigation. Added a temporary patching fixture in
tests/conftest.pythat defaultsClientResponse.__init__'s required
stream_writerargument toMock(output_size=0)when omitted by
aioresponses._build_response(). The fixture is session-scoped and
autouse; it auto-disables on aiohttp < 3.14. To be removed when
aioresponses >= 0.8.0ships upstream PR #288.sync-github-actionworkflow no longer destroys the target downstream repo's.git/directory during rsync sync
Security
- Update
actions/checkoutfrom v4 to v7.0.1 - Update
actions/setup-pythonfrom v5 to v6.3.0 - Update
actions/upload-artifactfrom v4 to v7.0.1 - Update
actions/download-artifactfrom v4 to v8.0.1 - Update
github/codeql-actionfrom v3 to v4 - Update
docker/build-push-actionfrom v6 to v7 - Update
codecov/codecov-actionfrom v5 to v6.0.0 - Update
actions/stalefrom v9 to v10.4.0 - Update
softprops/action-gh-releasefrom v2 to v3.0.2 - Update
EndBug/label-syncto v2.3.3 - Token-Permissions: All 7 workflow files (ci.yml, snapshot.yml, dependency-review.yml, stale.yml, label-sync.yml, scorecard.yml, release.yml) scoped to
contents: readat top level with job-level write overrides where required - Pinned-Dependencies: Docker base image pinned to SHA256 digest; all CI
pip installreplaced with SHA256-pinneduvcommands for reproducible dependency resolution - Signed-Releases: SLSA provenance job now publishes
*.intoto.jsonlattestation artifacts to GitHub Release assets viaupload-assets: true - Vulnerabilities:
aiohttpbumped from>=3.9,<3.14to>=3.14.1,<4.0(21 CVEs fixed);github-action/dependencies updated (@actions/coreto 2.x,undicioverridden to 6.27.0 — 3 HIGH CVEs fixed) - Fuzzing: ClusterFuzzLite integration with Atheris-based lock file parser fuzz test (
fuzz/parse_lockfiles_fuzz.py) - Hypothesis property-based fuzzing tests added for threat scoring invariants
- CodeQL SAST scanning workflow (
.github/workflows/codeql.yml) — runs on push/PR to main/develop and weekly schedule for Python code analysis - OpenSSF Scorecard analysis workflow (
.github/workflows/scorecard.yml) — evaluates repository security posture, pushes results to Scorecard API and uploads SARIF to code scanning - SLSA Build Level 3 provenance generation in release pipeline via
slsa-github-generator— provides verifiable build integrity attestations for all release artifacts - Binary artifact attestations via
actions/attest-build-provenance— cryptographically links release binaries to their build workflow - Docker image provenance attestation with push-to-registry in release pipeline
- SPDX license and copyright headers (
# Copyright (c) 2026 DIVISION 7 | MI-7 (@divisionseven)and# SPDX-License-Identifier: Apache-2.0) added to all 113 source files undersrc/pkg_defender/ scripts/add_spdx_headers.py— automated script for managing SPDX and copyright headers across the codebase
📖 41 Commits since v1.0.5
| Commit | Description | Author |
|---|---|---|
e1215a6 |
fix(build): prevent oversized sdist from blocking PyPI publish | Division 7 |
d96ca57 |
fix(deps): update dependency review to include MIT-0 and GPL-2.0-or-later licenses | Division 7 |
b5ae9c0 |
fix(ci): resolve pypi and binary build failure in release pipeline | Division 7 |
a26a41e |
fix(ci): resolve release pipeline attestation and provenance failures | Division 7 |
ae9a6c5 |
fix(ci): update Docker build and GitHub Actions for Node.js 24 compatibility | Division 7 |
ba3d8df |
fix(coverage): add additional coverage for __init__.py |
Division 7 |
36ca1c0 |
chore(release): prepare release v1.0.6 | Division 7 |
774bda8 |
chore(ossf): update OSSF Best Practices badge on root README with correct project ID and project page link | Division 7 |
5c1c57d |
fix(ci): use git clone instead of actions/checkout for downstream repos | Division 7 |
71e31ec |
fix(ci): use create-pull-request for signed downstream commits | Division 7 |
5bc9f03 |
fix(pkgd-action): replace Python YAML validation with Node.js for Ubuntu 24.04 | Division 7 |
20ae482 |
fix(security): resolve 27 OSSF Scorecard vulnerabilities findings | Division 7 |
b8a16d9 |
fix(ci): prefix lint and test commands with uv run | Division 7 |
a5d2aee |
feat(security): achieve OpenSSF Scorecard 10/10 on code-fixable checks | Division 7 |
b11319d |
fix(ci): remove python_executable to fix mypy in CI | Division 7 |
4b077c5 |
chore(ossf): add openSSF badges to readme badge bar to comply with best practices certification | Division 7 |
81fa458 |
fix: final workflow / md lint fixes | Division 7 |
8ba6cdd |
feat: add governance, DCO, secure design docs, and OpenSSF badges | Division 7 |
844eee7 |
feat(test): add hypothesis property-based fuzzing tests for threat scoring | Division 7 |
59c5c0b |
feat(ci,license): add CodeQL, Scorecard, SLSA provenance, attestations, and SPDX headers | Division 7 |
c8f5d8f |
docs: improve contributor documentation | Division 7 |
895cbf3 |
fix(downstream-ci): change author of downstream PR commits to Division 7 with gh-actions-bot as co-author | Division 7 |
f23812e |
fix(downstream-ci): exclude .git/ from rsync --delete in action sync workflow | Division 7 |
210d18f |
feat(downstream-ci): replace implicit git status with explicit diff-based sync detection in cross-repo workflows | Division 7 |
7034130 |
ci(downstream-repo): pin remaining action SHAs in downstream repo workflow | Division 7 |
6f290bb |
chore(downstream-repo): update README for homebrew-tap and github-action repos; pin action SHAs in downstream repo workflows; test new downstream repo auto-sync workflows | Division 7 |
469d4c5 |
feat(ci): add cross-repo sync workflows for homebrew-tap and github-action directories | Division 7 |
5cc768b |
chore(assets): replace light-mode brand assets | Division 7 |
31d223f |
chore(docs): add demo usage clips | Division 7 |
75f9b95 |
chore(release): bump version for v1.0.5 release | Division 7 |
06cacd6 |
fix(core): cache PRAGMA quick_check per process to fix 30s timeout; remove dead connection; reduce busy_timeout 30s to 5s; update docs |
Division 7 |
dfaf264 |
fix(db-snapshot): query correct GitHub release tag for database snapshots; fix snapshot-body.md doc links |
Division 7 |
940a6c3 |
fix(intel-sync): fix error handling, stack traces, DB contention, stale OSSF feed delay warnings, docs update | Division 7 |
3d09528 |
chore(release): bump version for v1.0.4 release | Division 7 |
ff07a8b |
fix(downstream-ci): exclude .git/ from rsync --delete in action sync workflow | Division 7 |
5bc549e |
feat(downstream-ci): replace implicit git status with explicit diff-based sync detection in cross-repo workflows | Division 7 |
99f3f0d |
ci(downstream-repo): pin remaining action SHAs in downstream repo workflow | Division 7 |
6ace766 |
chore(downstream-repo): update README for homebrew-tap and github-action repos; pin action SHAs in downstream repo workflows; test new downstream repo auto-sync workflows | Division 7 |
b64c407 |
feat(ci): add cross-repo sync workflows for homebrew-tap and github-action directories | Division 7 |
2e33346 |
chore(assets): replace light-mode brand assets | Division 7 |
dda29d8 |
chore(docs): add demo usage clips | Division 7 |