Skip to content

v0.6.0

Choose a tag to compare

@dzeusking-dev dzeusking-dev released this 11 Sep 16:26

ForgeGuard 0.6.0 -- Control Plane Hardening

Adds forgeguard runner review: an offline, zero-network assessment of one operator-declared Gitea or Forgejo Actions runner's security posture, validated against a new closed schema forgeguard.runner-snapshot.v1. It never reads runner credentials, .runner files, Docker/registry secrets, or repository secrets.

Added since 0.5.0

  • Eight provider-aware checks: FG-RUNNER-VERSION, -EXECUTION, -PRIVILEGED, -VOLUMES, -DOCKER, -NETWORK, -EPHEMERAL, -PLUGIN. Severity depends on the declared workload_trust (trusted-only vs mixed-untrusted), never on runner version alone.
  • When execution_engine=host, the four container-specific checks correctly report not_applicable instead of re-penalizing one root cause five times.
  • Runner qualification: Gitea Runner 3.4.2 and Forgejo Runner 13.0.0 / 13.1.0, each independently verified via the exact, checksum-verified official release binary's own --version and generate-config output. Full upstream citations with retrieval dates and hashes in docs/UPSTREAM.md, including gitea/runner#1058 (host-escape container.options hardening) and the Forgejo Runner 13.0.0 registry-credential-leak and workflow-command-injection fixes.

Compatibility

forgeguard.config-snapshot.v1 is unchanged; 0.5.0 config-review snapshots remain valid.

Qualification (this exact release)

  • Source: f11aa72a18a5648e90ed605bab729561a7315afe (tag v0.6.0), qualified on trusted push run 34621416236, attempt 1.
  • 383 tests pass on Python 3.11.16 and 3.12.14; coverage 95.58% (>= 91.28% required). Ruff lint/format, compile, pip check green.
  • 16/16 real upstream container variants (Gitea 1.26.4/1.27.3, Forgejo 15.0.8/16.0.4, public/private, registration on/off) with 16 enforced configuration read-backs.
  • 2/2 TLS/subpath/local-CA cases with verified cleanup.
  • Fresh SBOM and dependency audits across runtime(19)/dev(52)/build(2) environments -- 0 vulnerabilities.
  • Attestation independently verified against the exact published files.

Wheel SHA-256: 3bc1d34edff1ca77076b8593c26b242589a44a93c6a7f8acc0aafa6acf4e8ca3
sdist SHA-256: f93e0b02a6e3892cf57fe2b3159d5eaa5eb491fe71df50172e38fb8cc4431ad6

Install

python -m pip install forgeguard==0.6.0

Scope and boundaries

ForgeGuard remains read-only, single-target, GET-only (for scan) or fully offline zero-network (for config review and runner review), and limited to instances/runners the operator owns or is explicitly authorized to assess. No exploit proof, no mass scanning, no security certification, no compromise determination, and no complete-security guarantee.

See CHANGELOG.md for full history, README.md and docs/RUNNER_REVIEW.md for usage.