Skip to content

v0.5.0

Choose a tag to compare

@dzeusking-dev dzeusking-dev released this 11 Sep 13:31

ForgeGuard 0.5.0

Multi-Forge release: read-only security posture checks for self-hosted Gitea or Forgejo, offline configuration review of an explicitly supplied snapshot, and JSON/Markdown/SARIF exports.

Added since 0.2.2

  • Separate Gitea and Forgejo providers with operator-declared product identity (one target per invocation, --product gitea or --product forgejo).
  • Finite, hashed, provider-specific advisory catalogs (Gitea retains CVE-2026-27771, adds CVE-2026-78433; Forgejo covers its 2026-09-10 template-initialization security change for the proven fixed releases).
  • Offline configuration review of an explicitly supplied anonymized snapshot (forgeguard config review), with minimal/standard/extended scopes and public/private/unspecified policy intent.
  • SARIF 2.1.0 export alongside Markdown and JSON.
  • Deterministic completeness semantics: a normal A-F grade appears only when every core check is assessed; missing or ambiguous evidence produces N/A, never a fabricated PASS.

Qualification (this exact release)

  • Source: 2eee87960d325ad2cb755bb0ffcf3637d6b0335a (tag v0.5.0), qualified on trusted push run 34605494277, attempt 1. This commit's only change over the tested 5bd1dc9 is a CI step that uploads the qualification-evidence artifact for the release preflight; no forgeguard/ package content changed.
  • 356 tests pass on Python 3.11.16 and 3.12.14; coverage 95.09% (>= 91.28% required). Ruff lint/format, compile, pip check green.
  • 16/16 real upstream container variants (Gitea 1.26.4/1.27.3, Forgejo 15.0.8/16.0.4, public/private, registration on/off) with 16 enforced configuration read-backs.
  • 2/2 TLS/subpath/local-CA cases with verified cleanup.
  • Reproducible wheel and sdist; CycloneDX 1.6 SBOM; runtime/dev/build dependency audits reconciled by set, 0 vulnerabilities.
  • Attestation independently verified against the exact published files, including a negative byte-mutation refusal test.

Wheel SHA-256: feabb017c402a81294edc6a3340f6dc126730c262b22dd64167257f5923788b3
sdist SHA-256: ea89f2078253361d165d9f2c8d2a2e01bc65100bf657f3477b1bfa04293fc88c

Install

python -m pip install forgeguard

Scope and boundaries

Qualification targets are Gitea 1.26.4/1.27.3 and Forgejo 15.0.8/16.0.4 - these are the exact tested targets, not a universal support promise for every release in either branch. ForgeGuard remains read-only, single-target, GET-only, and limited to instances the operator owns or is explicitly authorized to assess. No exploit proof, no mass scanning, no security certification, no compromise determination, and no complete-security guarantee.

See CHANGELOG.md for full history and README.md for usage.