Skip to content

PKG-Defender v1.0.6

Choose a tag to compare

@github-actions github-actions released this 23 Jul 19:00
· 45 commits to main since this release
v1.0.6
1f76465
PKG-Defender Logo

PKG-Defender v1.0.6

Released July 23, 2026


What's Changed

Added

  • ClusterFuzzLite fuzzing integration — .clusterfuzzlite/Dockerfile and .clusterfuzzlite/build.sh for OSS-Fuzz compatible continuous fuzzing infrastructure
  • Atheris fuzz test for lock file parsing — fuzz/parse_lockfiles_fuzz.py with atheris>=2.3.0 under [fuzz] optional dependencies
  • GOVERNANCE.md — project governance document defining roles, decision-making, and conflict resolution processes
  • Secure design principles statement in docs/explanation/security-model.md
  • Property-based fuzzing tests using hypothesis — 6 invariants verified
    for threat scoring logic (tests/unit/core/test_scoring_properties.py)
  • hypothesis>=6.0 dependency added to test profile
  • Trigger improvements: Both sync workflows now support workflow_dispatch (manual trigger from GitHub UI) and a weekly schedule (Monday 6am UTC) as safety nets, in addition to the push-based path trigger. This ensures changes are synced even when the push path filter misses them (e.g., when changes span multiple commits and only the HEAD commit matches the path filter, or diff timeouts/limits are hit).
  • Explicit content-based sync detection: Both sync workflows now use diff -q / diff -rq for file comparison instead of git status --porcelain. This provides:
  • Clear per-file match/mismatch logging in workflow output
  • True content comparison (not timestamp-based) with no reliance on git commit history
  • Two-phase detection-then-apply: files are compared before any are copied
  • A safety-net verification step after apply to catch any discrepancies
  • sync-brew-formula.py now supports --output flag for two-phase formula detection, enabling the merge result to be inspected before overwriting the target.
  • Cross-repo sync workflows: Two new GitHub Actions workflows and a Python merge script that automatically sync the homebrew-tap/ and github-action/ source-of-truth directories to their respective subsidiary repos (divisionseven/homebrew-pkg-defender and divisionseven/pkg-defender-action) whenever files in those directories change on main.
  • .github/workflows/sync-homebrew-tap.yml — Syncs homebrew-tap/ → homebrew-pkg-defender via PR. Uses a smart-merge script to preserve version/url/sha256 from the target formula (set by the release pipeline) while applying all other structural changes (desc, caveats, test block, etc.) from source.
  • .github/workflows/sync-github-action.yml — Syncs github-action/ → pkg-defender-action via full directory rsync, excluding node_modules/, plans/, and internal_documentation/.
  • .github/scripts/sync-brew-formula.py — Standalone Python script for section-aware Homebrew formula merging, preserving only version/URL/SHA256 from the target.
  • CodeQL SAST scanning workflow (.github/workflows/codeql.yml) — runs on push/PR to main/develop and weekly schedule for Python code analysis
  • OpenSSF Scorecard analysis workflow (.github/workflows/scorecard.yml) — evaluates repository security posture, pushes results to Scorecard API and uploads SARIF to code scanning
  • SLSA Build Level 3 provenance generation in release pipeline via slsa-github-generator — provides verifiable build integrity attestations for all release artifacts
  • Binary artifact attestations via actions/attest-build-provenance — cryptographically links release binaries to their build workflow
  • Docker image provenance attestation with push-to-registry in release pipeline
  • SPDX license and copyright headers (# Copyright (c) 2026 DIVISION 7 | MI-7 (@divisionseven) and # SPDX-License-Identifier: Apache-2.0) added to all 113 source files under src/pkg_defender/
  • scripts/add_spdx_headers.py — automated script for managing SPDX and copyright headers across the codebase

Changed

  • tests/fixtures/lock_files/osv-scanner.toml added with [[PackageOverrides]] ignore = true to suppress 20 OSV-Scanner false positives from test fixture lock files — fixes OpenSSF Scorecard Vulnerabilities check scoring 0/10
  • idna>=3.15 constraint added to [project.dependencies] — resolves PYSEC-2026-215 (idna 3.11 vulnerable); uv.lock upgraded idna from 3.11 to 3.18
  • github-action/ dev dependencies refreshed via npm audit fix: @babel/core 7.29.0→7.29.7 (GHSA-4x5r-pxfx-6jf8), js-yaml 3.14.2→3.15.0 (GHSA-h67p-54hq-rp68)
  • aiohttp dependency updated from >=3.9,<3.14 to >=3.14.1,<4.0 — resolves 21 CVEs in the HTTP client
  • github-action/ dependencies refreshed: @actions/core bumped to 2.x, undici overridden to 6.27.0 — fixes 3 HIGH severity CVEs
  • SLSA provenance job now sets upload-assets: true so *.intoto.jsonl attestation artifacts appear in GitHub Release assets
  • Replaced all pip install commands with SHA256-pinned uv equivalents in CI workflows (ci.yml, release.yml, github-action/ci.yml) for reproducible dependency installation
  • python:3.11-alpine Docker image base pinned to SHA256 digest for immutable builds
  • CONTRIBUTING.md — added Developer Certificate of Origin (DCO) requirement with sign-off instructions
  • docs/explanation/security-model.md — added Secure Design Principles section covering fail-closed, least privilege, defense in depth, secure defaults, and input validation
  • README.md — added OpenSSF Scorecard and OpenSSF Best Practices (placeholder) badges to header
  • Downstream workflow commits (release.yml, sync-homebrew-tap.yml, sync-github-action.yml) now authored as Division 7 with Co-authored-by: github-actions[bot] instead of pure bot authorship for traceability
  • .github/workflows/release.yml token permissions scoped from contents: write to contents: read with per-job overrides, following the least-privilege principle

Fixed

  • PyPI publish rejected with "400 File too large. Limit is 100 MB" — root
    cause: Hatchling's default VCS mode bundled all git-tracked files into the
    sdist, including 3 demo GIFs (152 MB total) in docs/assets/demo/. Added
    [tool.hatch.build.targets.sdist] with exclude patterns for 12 dev-only
    directories. sdist reduced from ~150 MB to 1.9 MB.
  • Release pipeline: PyPI publish job no longer fails with uv: command not found — added astral-sh/setup-uv step and switched to uv publish dist/* (replacing twine-based publish). Binary build no longer crashes with ModuleNotFoundError: No module named 'click' in Homebrew — switched from uv tool run pyinstaller to uv run pyinstaller so PyInstaller can see all project dependencies. Added pyinstaller>=6.21.0 as a dev dependency.
  • Release pipeline build-docker job failed with "Resource not accessible by integration" when calling the GitHub Attestations API — root cause: the job's permissions block was missing attestations: write and artifact-metadata: write, so the GITHUB_TOKEN could not authorize the attestation call. Added both permissions to the build-docker job (release.yml). Verified by the full test suite passing (4,481 tests).
  • SLSA provenance generator failed with a ref-format error when release.yml is pinned to a commit SHA — root cause: slsa-github-generator's builder-fetch.sh requires a refs/tags/vX.Y.Z ref but received a bare SHA, so the script could not resolve the generator source. Added compile-generator: true to the provenance job, which bypasses builder-fetch.sh and compiles the generator from source instead. This keeps the workflow SHA-pinned and maintains OpenSSF Scorecard Pinned-Dependencies compliance (release.yml). Verified by the full test suite passing (4,481 tests).
  • actions/attest-build-provenance was pinned to v2.4.0, which internally uses Node.js 20 — root cause: Node.js 20 reached end-of-life on the GitHub Actions runners, causing the attestation step to fail with a Node.js deprecation error. Updated actions/attest-build-provenance to v4.1.1 (SHA 0f67c3f4856b2e3261c31976d6725780e5e4c373), which uses Node.js 24. Also updated docker/build-push-action from v7.0.0 to v7.3.0 (SHA 53b7df96c91f9c12dcc8a07bcb9ccacbed38856a) to pick up bugfixes in the Docker build step (release.yml).
  • Docker build failure: replace unsupported uv pip install --user with uv pip install --system to fix compatibility with newer uv versions
  • Update GitHub Actions to Node.js 24-compatible versions to prevent deprecation failures across 10 workflow files
  • Downstream repo checkout in release.yml, sync-homebrew-tap.yml, and sync-github-action.yml failed because actions/checkout rejects /tmp/ paths outside the workspace. Replaced actions/checkout with git clone using the GitHub App token for all downstream repo checkouts
  • Sync workflow commits to downstream repos were unsigned, triggering GitHub's "unsigned commit" security alerts on homebrew-pkg-defender and pkg-defender-action. Replaced manual git commit/git push operations with peter-evans/create-pull-request@v8 and actions/create-github-app-token@v3 in sync-homebrew-tap.yml, sync-github-action.yml, and release.yml — all downstream commits are now signed by the GitHub App identity
  • GitHub Action CI failed on Ubuntu 24.04 runners due to PEP 668 blocking system-wide Python package installs (externally-managed-environment). Replaced python3 -c "import yaml..." YAML validation in validate.sh with Node.js require('yaml') and removed the now-unnecessary setup-uv + uv pip install --system pyyaml steps from the action's CI and release workflows
  • aiohttp>=3.14.1,<4.0 constraint — the requirement was
    incorrectly constrained to aiohttp<3.14 during aiohttp 3.14/aioresponses
    0.7.9 compatibility investigation. Added a temporary patching fixture in
    tests/conftest.py that defaults ClientResponse.__init__'s required
    stream_writer argument to Mock(output_size=0) when omitted by
    aioresponses._build_response(). The fixture is session-scoped and
    autouse; it auto-disables on aiohttp < 3.14. To be removed when
    aioresponses >= 0.8.0 ships upstream PR #288.
  • sync-github-action workflow no longer destroys the target downstream repo's .git/ directory during rsync sync

Security

  • Update actions/checkout from v4 to v7.0.1
  • Update actions/setup-python from v5 to v6.3.0
  • Update actions/upload-artifact from v4 to v7.0.1
  • Update actions/download-artifact from v4 to v8.0.1
  • Update github/codeql-action from v3 to v4
  • Update docker/build-push-action from v6 to v7
  • Update codecov/codecov-action from v5 to v6.0.0
  • Update actions/stale from v9 to v10.4.0
  • Update softprops/action-gh-release from v2 to v3.0.2
  • Update EndBug/label-sync to v2.3.3
  • Token-Permissions: All 7 workflow files (ci.yml, snapshot.yml, dependency-review.yml, stale.yml, label-sync.yml, scorecard.yml, release.yml) scoped to contents: read at top level with job-level write overrides where required
  • Pinned-Dependencies: Docker base image pinned to SHA256 digest; all CI pip install replaced with SHA256-pinned uv commands for reproducible dependency resolution
  • Signed-Releases: SLSA provenance job now publishes *.intoto.jsonl attestation artifacts to GitHub Release assets via upload-assets: true
  • Vulnerabilities: aiohttp bumped from >=3.9,<3.14 to >=3.14.1,<4.0 (21 CVEs fixed); github-action/ dependencies updated (@actions/core to 2.x, undici overridden to 6.27.0 — 3 HIGH CVEs fixed)
  • Fuzzing: ClusterFuzzLite integration with Atheris-based lock file parser fuzz test (fuzz/parse_lockfiles_fuzz.py)
  • Hypothesis property-based fuzzing tests added for threat scoring invariants
  • CodeQL SAST scanning workflow (.github/workflows/codeql.yml) — runs on push/PR to main/develop and weekly schedule for Python code analysis
  • OpenSSF Scorecard analysis workflow (.github/workflows/scorecard.yml) — evaluates repository security posture, pushes results to Scorecard API and uploads SARIF to code scanning
  • SLSA Build Level 3 provenance generation in release pipeline via slsa-github-generator — provides verifiable build integrity attestations for all release artifacts
  • Binary artifact attestations via actions/attest-build-provenance — cryptographically links release binaries to their build workflow
  • Docker image provenance attestation with push-to-registry in release pipeline
  • SPDX license and copyright headers (# Copyright (c) 2026 DIVISION 7 | MI-7 (@divisionseven) and # SPDX-License-Identifier: Apache-2.0) added to all 113 source files under src/pkg_defender/
  • scripts/add_spdx_headers.py — automated script for managing SPDX and copyright headers across the codebase

📖 41 Commits since v1.0.5
Commit Description Author
e1215a6 fix(build): prevent oversized sdist from blocking PyPI publish Division 7
d96ca57 fix(deps): update dependency review to include MIT-0 and GPL-2.0-or-later licenses Division 7
b5ae9c0 fix(ci): resolve pypi and binary build failure in release pipeline Division 7
a26a41e fix(ci): resolve release pipeline attestation and provenance failures Division 7
ae9a6c5 fix(ci): update Docker build and GitHub Actions for Node.js 24 compatibility Division 7
ba3d8df fix(coverage): add additional coverage for __init__.py Division 7
36ca1c0 chore(release): prepare release v1.0.6 Division 7
774bda8 chore(ossf): update OSSF Best Practices badge on root README with correct project ID and project page link Division 7
5c1c57d fix(ci): use git clone instead of actions/checkout for downstream repos Division 7
71e31ec fix(ci): use create-pull-request for signed downstream commits Division 7
5bc9f03 fix(pkgd-action): replace Python YAML validation with Node.js for Ubuntu 24.04 Division 7
20ae482 fix(security): resolve 27 OSSF Scorecard vulnerabilities findings Division 7
b8a16d9 fix(ci): prefix lint and test commands with uv run Division 7
a5d2aee feat(security): achieve OpenSSF Scorecard 10/10 on code-fixable checks Division 7
b11319d fix(ci): remove python_executable to fix mypy in CI Division 7
4b077c5 chore(ossf): add openSSF badges to readme badge bar to comply with best practices certification Division 7
81fa458 fix: final workflow / md lint fixes Division 7
8ba6cdd feat: add governance, DCO, secure design docs, and OpenSSF badges Division 7
844eee7 feat(test): add hypothesis property-based fuzzing tests for threat scoring Division 7
59c5c0b feat(ci,license): add CodeQL, Scorecard, SLSA provenance, attestations, and SPDX headers Division 7
c8f5d8f docs: improve contributor documentation Division 7
895cbf3 fix(downstream-ci): change author of downstream PR commits to Division 7 with gh-actions-bot as co-author Division 7
f23812e fix(downstream-ci): exclude .git/ from rsync --delete in action sync workflow Division 7
210d18f feat(downstream-ci): replace implicit git status with explicit diff-based sync detection in cross-repo workflows Division 7
7034130 ci(downstream-repo): pin remaining action SHAs in downstream repo workflow Division 7
6f290bb chore(downstream-repo): update README for homebrew-tap and github-action repos; pin action SHAs in downstream repo workflows; test new downstream repo auto-sync workflows Division 7
469d4c5 feat(ci): add cross-repo sync workflows for homebrew-tap and github-action directories Division 7
5cc768b chore(assets): replace light-mode brand assets Division 7
31d223f chore(docs): add demo usage clips Division 7
75f9b95 chore(release): bump version for v1.0.5 release Division 7
06cacd6 fix(core): cache PRAGMA quick_check per process to fix 30s timeout; remove dead connection; reduce busy_timeout 30s to 5s; update docs Division 7
dfaf264 fix(db-snapshot): query correct GitHub release tag for database snapshots; fix snapshot-body.md doc links Division 7
940a6c3 fix(intel-sync): fix error handling, stack traces, DB contention, stale OSSF feed delay warnings, docs update Division 7
3d09528 chore(release): bump version for v1.0.4 release Division 7
ff07a8b fix(downstream-ci): exclude .git/ from rsync --delete in action sync workflow Division 7
5bc549e feat(downstream-ci): replace implicit git status with explicit diff-based sync detection in cross-repo workflows Division 7
99f3f0d ci(downstream-repo): pin remaining action SHAs in downstream repo workflow Division 7
6ace766 chore(downstream-repo): update README for homebrew-tap and github-action repos; pin action SHAs in downstream repo workflows; test new downstream repo auto-sync workflows Division 7
b64c407 feat(ci): add cross-repo sync workflows for homebrew-tap and github-action directories Division 7
2e33346 chore(assets): replace light-mode brand assets Division 7
dda29d8 chore(docs): add demo usage clips Division 7

View Complete Changelog →