v0.6.0
ForgeGuard 0.6.0 -- Control Plane Hardening
Adds forgeguard runner review: an offline, zero-network assessment of one operator-declared Gitea or Forgejo Actions runner's security posture, validated against a new closed schema forgeguard.runner-snapshot.v1. It never reads runner credentials, .runner files, Docker/registry secrets, or repository secrets.
Added since 0.5.0
- Eight provider-aware checks:
FG-RUNNER-VERSION,-EXECUTION,-PRIVILEGED,-VOLUMES,-DOCKER,-NETWORK,-EPHEMERAL,-PLUGIN. Severity depends on the declaredworkload_trust(trusted-onlyvsmixed-untrusted), never on runner version alone. - When
execution_engine=host, the four container-specific checks correctly reportnot_applicableinstead of re-penalizing one root cause five times. - Runner qualification: Gitea Runner 3.4.2 and Forgejo Runner 13.0.0 / 13.1.0, each independently verified via the exact, checksum-verified official release binary's own
--versionandgenerate-configoutput. Full upstream citations with retrieval dates and hashes indocs/UPSTREAM.md, includinggitea/runner#1058(host-escapecontainer.optionshardening) and the Forgejo Runner 13.0.0 registry-credential-leak and workflow-command-injection fixes.
Compatibility
forgeguard.config-snapshot.v1 is unchanged; 0.5.0 config-review snapshots remain valid.
Qualification (this exact release)
- Source:
f11aa72a18a5648e90ed605bab729561a7315afe(tagv0.6.0), qualified on trusted push run 34621416236, attempt 1. - 383 tests pass on Python 3.11.16 and 3.12.14; coverage 95.58% (>= 91.28% required). Ruff lint/format, compile, pip check green.
- 16/16 real upstream container variants (Gitea 1.26.4/1.27.3, Forgejo 15.0.8/16.0.4, public/private, registration on/off) with 16 enforced configuration read-backs.
- 2/2 TLS/subpath/local-CA cases with verified cleanup.
- Fresh SBOM and dependency audits across runtime(19)/dev(52)/build(2) environments -- 0 vulnerabilities.
- Attestation independently verified against the exact published files.
Wheel SHA-256: 3bc1d34edff1ca77076b8593c26b242589a44a93c6a7f8acc0aafa6acf4e8ca3
sdist SHA-256: f93e0b02a6e3892cf57fe2b3159d5eaa5eb491fe71df50172e38fb8cc4431ad6
Install
python -m pip install forgeguard==0.6.0Scope and boundaries
ForgeGuard remains read-only, single-target, GET-only (for scan) or fully offline zero-network (for config review and runner review), and limited to instances/runners the operator owns or is explicitly authorized to assess. No exploit proof, no mass scanning, no security certification, no compromise determination, and no complete-security guarantee.
See CHANGELOG.md for full history, README.md and docs/RUNNER_REVIEW.md for usage.