Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .bestpractices.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
{
"osps_do_01_01": "Met",
"osps_do_01_01_justification": "Installation and CLI usage are documented in https://github.com/gexiro-global/csaf-check#install",
"osps_do_02_01": "Met",
"osps_do_02_01_justification": "Defects use repository issue templates and https://github.com/gexiro-global/csaf-check/blob/main/SUPPORT.md",
"osps_gv_02_01": "Met",
"osps_gv_02_01_justification": "Public issues and pull requests are enabled.",
"osps_gv_03_01": "Met",
"osps_gv_03_01_justification": "See https://github.com/gexiro-global/csaf-check/blob/main/CONTRIBUTING.md",
"osps_le_02_01": "Met",
"osps_le_02_01_justification": "Apache-2.0 source license.",
"osps_le_02_02": "Met",
"osps_le_02_02_justification": "Release packaging includes the Apache-2.0 license.",
"osps_le_03_01": "Met",
"osps_le_03_01_justification": "See https://github.com/gexiro-global/csaf-check/blob/main/LICENSE",
"osps_le_03_02": "Met",
"osps_le_03_02_justification": "The license is included in source distributions and wheels.",
"osps_qa_01_01": "Met",
"osps_qa_01_01_justification": "Canonical public source: https://github.com/gexiro-global/csaf-check",
"osps_qa_01_02": "Met",
"osps_qa_01_02_justification": "GitHub publishes the repository commit history.",
"osps_qa_02_01": "Met",
"osps_qa_02_01_justification": "Direct dependencies are declared in pyproject.toml.",
"osps_qa_04_01": "N/A",
"osps_qa_04_01_justification": "csaf-check is a single-repository project.",
"osps_qa_05_01": "Met",
"osps_qa_05_01_justification": "Generated executables are built in CI and not committed.",
"osps_qa_05_02": "Met",
"osps_qa_05_02_justification": "The repository contains source and reviewable data files, not executable binaries.",
"osps_vm_02_01": "Met",
"osps_vm_02_01_justification": "See https://github.com/gexiro-global/csaf-check/blob/main/SECURITY.md"
}
28 changes: 28 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
name: CodeQL

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: "17 4 * * 1"

permissions:
contents: read
security-events: write

jobs:
analyze:
name: Analyze Python
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Initialize CodeQL
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: python
- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
19 changes: 19 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
name: Dependency review

on:
pull_request:

permissions:
contents: read

jobs:
review:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Review dependency changes
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: high
42 changes: 42 additions & 0 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
name: OpenSSF Scorecard

on:
branch_protection_rule:
schedule:
- cron: "31 5 * * 3"
push:
branches: [main]

permissions: read-all

jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
security-events: write
id-token: write
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Run OpenSSF Scorecard
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: results.sarif
results_format: sarif
publish_results: true
- name: Preserve SARIF result
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: openssf-scorecard-sarif
path: results.sarif
retention-days: 5
if-no-files-found: error
- name: Upload SARIF to code scanning
uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
sarif_file: results.sarif
5 changes: 5 additions & 0 deletions GOVERNANCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Governance

csaf-check is maintained by Gexiro Global Enterprises Ltd. The maintainer reviews issues and pull requests, decides scope and releases, and may reject changes that weaken the read-only, authorization-scoped or fail-explicit design.

Changes are proposed through GitHub pull requests and must pass CI. The current single-maintainer structure is disclosed in [MAINTAINERS.md](MAINTAINERS.md); no independent review, response-time guarantee or certification is claimed.
7 changes: 7 additions & 0 deletions MAINTAINERS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Maintainers

| Maintainer | Role | Contact |
|---|---|---|
| `@dzeusking-dev` | Project owner and release maintainer | [GitHub](https://github.com/dzeusking-dev) |

Security reports must use [SECURITY.md](SECURITY.md), not public issues.
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@
[![Python](https://img.shields.io/pypi/pyversions/csaf-check.svg)](https://pypi.org/project/csaf-check/)
[![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE)

[Security and trust evidence](docs/SECURITY-TRUST.md) documents the project's policies and automated checks. No certification or badge level is claimed.

Validate CSAF 2.0 advisories from Python, using the same validator Secvisogram runs — and get an
honest answer when that validator is not installed.

Expand Down
5 changes: 5 additions & 0 deletions SUPPORT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Support

Use [GitHub Issues](https://github.com/gexiro-global/csaf-check/issues) for reproducible defects and usage questions. Include the package, Python and Node.js versions and a minimal synthetic CSAF document. Do not publish embargoed advisories, credentials or third-party confidential data.

Security vulnerabilities belong in a private report under the process in [SECURITY.md](SECURITY.md).
7 changes: 7 additions & 0 deletions THREAT_MODEL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Threat model

csaf-check parses attacker-controlled JSON and invokes a local Node.js validator. The primary risks are resource exhaustion, malformed validator output, executing an attacker-selected `node` from `PATH`, accidental disclosure of unpublished advisories and a misleading conclusive verdict when the validator is unavailable.

The implementation passes the temporary path as a process argument without shell interpolation, bounds validator runtime, removes the temporary directory and represents validator absence explicitly. Operators must use a trusted runtime and dependencies, apply their own input-size limit, avoid untrusted or embargoed documents in shared CI logs and use `--require-validator` where an inconclusive result must fail.

The project performs no network discovery and makes no claim that schema validity proves advisory correctness.
11 changes: 11 additions & 0 deletions docs/SECURITY-TRUST.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Security and trust evidence

This page is an evidence index, not a certification. The evidence does not prove the project is vulnerability-free, does not establish a SLSA level, and does not imply OpenSSF affiliation or endorsement. Tool output describes observed posture; it is not proof of compromise or absence of compromise.

- [Security policy](../SECURITY.md) and [threat model](../THREAT_MODEL.md)
- [Contribution process](../CONTRIBUTING.md), [governance](../GOVERNANCE.md), [maintainers](../MAINTAINERS.md) and [support](../SUPPORT.md)
- CI tests both the no-validator degradation path and the packaged wheel with the real JavaScript validator.
- CodeQL, dependency review, Dependabot and OpenSSF Scorecard are configured in `.github/`.
- Third-party actions are pinned to immutable commit SHAs with version comments.

The Scorecard badge is intentionally withheld until a successful default-branch run has produced a public API result. `.bestpractices.json` contains evidence-backed automation proposals only; it is not an OpenSSF Best Practices or OSPS Baseline claim. A human must review any badge submission.
57 changes: 57 additions & 0 deletions security-insights.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
header:
schema-version: 2.2.0
last-updated: '2026-09-04'
last-reviewed: '2026-09-04'
url: https://raw.githubusercontent.com/gexiro-global/csaf-check/main/security-insights.yml
comment: This single-repository file reports current practices and makes no certification claim.
project:
name: csaf-check
homepage: https://github.com/gexiro-global/csaf-check
administrators:
- name: dzeusking-dev
affiliation: Gexiro Global Enterprises Ltd.
social: https://github.com/dzeusking-dev
primary: true
documentation:
quickstart-guide: https://github.com/gexiro-global/csaf-check#install
detailed-guide: https://github.com/gexiro-global/csaf-check/blob/main/docs/PIPELINE.md
code-of-conduct: https://github.com/gexiro-global/csaf-check/blob/main/CODE_OF_CONDUCT.md
support-policy: https://github.com/gexiro-global/csaf-check/blob/main/SUPPORT.md
repositories:
- name: csaf-check
url: https://github.com/gexiro-global/csaf-check
comment: Canonical source and release repository.
vulnerability-reporting:
reports-accepted: true
bug-bounty-available: false
policy: https://github.com/gexiro-global/csaf-check/blob/main/SECURITY.md
repository:
url: https://github.com/gexiro-global/csaf-check
status: active
accepts-change-request: true
accepts-automated-change-request: true
no-third-party-packages: false
core-team:
- name: dzeusking-dev
affiliation: Gexiro Global Enterprises Ltd.
social: https://github.com/dzeusking-dev
primary: true
documentation:
contributing-guide: https://github.com/gexiro-global/csaf-check/blob/main/CONTRIBUTING.md
review-policy: https://github.com/gexiro-global/csaf-check/blob/main/GOVERNANCE.md
security-policy: https://github.com/gexiro-global/csaf-check/blob/main/SECURITY.md
governance: https://github.com/gexiro-global/csaf-check/blob/main/GOVERNANCE.md
dependency-management-policy: https://github.com/gexiro-global/csaf-check/blob/main/docs/SECURITY-TRUST.md
license:
url: https://github.com/gexiro-global/csaf-check/blob/main/LICENSE
expression: Apache-2.0
release:
changelog: https://github.com/gexiro-global/csaf-check/blob/main/CHANGELOG.md
automated-pipeline: true
distribution-points:
- uri: https://pypi.org/project/csaf-check/
comment: Published Python package.
security:
assessments:
self:
comment: Maintainer self-assessment only; no independent audit is claimed.
Loading