v0.5.0
ForgeGuard 0.5.0
Multi-Forge release: read-only security posture checks for self-hosted Gitea or Forgejo, offline configuration review of an explicitly supplied snapshot, and JSON/Markdown/SARIF exports.
Added since 0.2.2
- Separate Gitea and Forgejo providers with operator-declared product identity (one target per invocation,
--product giteaor--product forgejo). - Finite, hashed, provider-specific advisory catalogs (Gitea retains CVE-2026-27771, adds CVE-2026-78433; Forgejo covers its 2026-09-10 template-initialization security change for the proven fixed releases).
- Offline configuration review of an explicitly supplied anonymized snapshot (
forgeguard config review), with minimal/standard/extended scopes and public/private/unspecified policy intent. - SARIF 2.1.0 export alongside Markdown and JSON.
- Deterministic completeness semantics: a normal A-F grade appears only when every core check is assessed; missing or ambiguous evidence produces N/A, never a fabricated PASS.
Qualification (this exact release)
- Source:
2eee87960d325ad2cb755bb0ffcf3637d6b0335a(tagv0.5.0), qualified on trusted push run 34605494277, attempt 1. This commit's only change over the tested5bd1dc9is a CI step that uploads the qualification-evidence artifact for the release preflight; noforgeguard/package content changed. - 356 tests pass on Python 3.11.16 and 3.12.14; coverage 95.09% (>= 91.28% required). Ruff lint/format, compile, pip check green.
- 16/16 real upstream container variants (Gitea 1.26.4/1.27.3, Forgejo 15.0.8/16.0.4, public/private, registration on/off) with 16 enforced configuration read-backs.
- 2/2 TLS/subpath/local-CA cases with verified cleanup.
- Reproducible wheel and sdist; CycloneDX 1.6 SBOM; runtime/dev/build dependency audits reconciled by set, 0 vulnerabilities.
- Attestation independently verified against the exact published files, including a negative byte-mutation refusal test.
Wheel SHA-256: feabb017c402a81294edc6a3340f6dc126730c262b22dd64167257f5923788b3
sdist SHA-256: ea89f2078253361d165d9f2c8d2a2e01bc65100bf657f3477b1bfa04293fc88c
Install
python -m pip install forgeguardScope and boundaries
Qualification targets are Gitea 1.26.4/1.27.3 and Forgejo 15.0.8/16.0.4 - these are the exact tested targets, not a universal support promise for every release in either branch. ForgeGuard remains read-only, single-target, GET-only, and limited to instances the operator owns or is explicitly authorized to assess. No exploit proof, no mass scanning, no security certification, no compromise determination, and no complete-security guarantee.
See CHANGELOG.md for full history and README.md for usage.