Skip to content

chore: prepare Trace for public release - #1

Open
Patel230 wants to merge 10 commits into
mainfrom
chore/release-readiness
Open

Patel230 wants to merge 10 commits into
mainfrom
chore/release-readiness

Conversation

@Patel230

@Patel230 Patel230 commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Prepares Trace for life as the public repository GrayCodeAI/trace: the module path, version, build and release tooling, CI, project policies, and documentation that matches the code. Behaviour changes are limited to a new trace version command and the trace user grant usage text; all security fixes are in the separate security-hardening PR, #2.

  • The repository was created public, with the wiki disabled and GitHub private vulnerability reporting enabled; main was pushed unchanged (16ea592).
  • A secret scan of the full history found nothing sensitive (details below).

Findings addressed

ID Change Commits
F099 Module path github.com/GrayCodeAI/trace; VERSION 0.0.1; trace version (ldflags main.Version/Commit/BuildDate); Makefile (build install test race vet fmt fmt-check tidy-check vulncheck check); tag-triggered GoReleaser release for linux and darwin, amd64 and arm64, with SHA-256 checksums.txt and no signing, and the release notes say so; the release job fails unless the tag equals v$(cat VERSION); SECURITY.md (GitHub private vulnerability reporting plus security@graycodeai.com), CONTRIBUTING.md, CODE_OF_CONDUCT.md (Contributor Covenant 2.1, hello@graycodeai.com), CHANGELOG.md, AGENTS.md (AGENTS.md-only, conventions, evidence rules); README status (pre-1.0 alpha, 0.0.1 not released, Linux and macOS only, build from source) d03cd47, 4fa9081, d465a01, 1dfd707, 5649b0d, 6276f0b, 9cb5a1d
F100 Committed the untracked CI workflow: Go pinned to 1.26.6 through env.GO_VERSION; timeout-minutes on every job; tests on ubuntu and macOS; race job; pinned govulncheck; workflow_dispatch; action SHAs pinned and verified against their tags e520d44
F097 README and ARCHITECTURE: merges happen in the browser by admins or maintainers (fast-forward, squash, or merge commit), not only by an admin running Git commands; protected branches are configurable; the package paragraph no longer denies the documented npm and PyPI endpoints; the operations milestone is current; the trace user grant usage now lists maintain 9cb5a1d
F299 FEATURES: Gitness is now Harness Open Source; Cody is Enterprise-only and Sourcegraph's agent is Amp; a dated, sourced table of 2026 forge agent features (GitHub's Agents tab and actor_is_agent, the GitLab Duo Agent Platform, Forgejo's AI policy, Gitea 1.26, Graphite), each with the Trace gap 1f9ac1b
F300 FEATURES Entire comparison: adapter coverage (Trace 4 vs Entire 8, missing agents named), checkpoint ref layout (refs/entire/checkpoints/<shard>/<id> vs refs/trace/agent-bundles/, no import path), regional mirror preview 1f9ac1b

Also included: 885a186 bumps golang.org/x/crypto to v0.56.0 (GO-2026-6354, GO-2026-6355), the same change as in #2, so the new govulncheck job passes on this branch. The identical edits merge cleanly.

Not reproduced / deferred

Verification

Gates run from this worktree (Go 1.26.5 darwin/arm64, GOWORK=off):

$ test -z "$(gofmt -l .)"                              # rc=0 (no files)
$ GOWORK=off go vet ./...                              # rc=0
$ GOWORK=off go build ./...                            # rc=0
$ GOWORK=off go test -race -count=1 -timeout 20m ./... # ok github.com/GrayCodeAI/trace/cmd/trace 56.240s, rc=0
  • History secret scan (git log -p --all, 25,900 lines): no private-key blocks, no GitHub/AWS/Slack/OpenAI/hwc_ token prefixes, and no 43-character base64url strings (the admin-token format) other than test function names and a go.sum hash. The only emails are example.invalid fixtures and the author identity. No path under data/ was ever committed.
  • goreleaser check: 1 configuration file validated. goreleaser release --snapshot --clean --skip=publish (v2.17.0) built four archives, each containing trace, README, LICENSE, CHANGELOG and SECURITY; shasum -a 256 -c checksums.txt returned OK for all four; the linux/amd64 binary is a static, stripped ELF. The output was deleted afterwards.
  • actionlint v1.7.7 on ci.yml and release.yml: 0 errors.
  • make build && ./bin/trace version: trace 0.0.1 (commit 885a186, built ...).
  • govulncheck@v1.1.4: no module findings after the x/crypto bump. The standard-library findings are fixed in Go 1.26.6, which CI and the release pin.
  • git merge-tree --write-tree fix/security-hardening chore/release-readiness: clean. A local merge of c71fe90 + 1f9ac1b (never pushed) also passes gofmt, vet, build, and go test -race (ok, 85.882s). merge-tree is also clean against fix: harden Trace against the September 2026 security audit findings #2's current head, 45d0efa, which only adds a test-fixture fix.
  • CI on this PR (1f9ac1b): quality, govulncheck, race, and tests on ubuntu and macOS all passed.

Follow-ups

  • The orchestrator or owner must add a v* tag ruleset to GrayCodeAI/trace (restrict creation, deletion and updates of release tags) before the first tag.
  • Tag v0.0.1 only after both PRs merge, and add fix: harden Trace against the September 2026 security audit findings #2's changes to CHANGELOG.md first.
  • Add Trace to rho's ecosystem.yaml (rho workstream).
  • Do the gofumpt v0.10.0 formatting-only PR, then switch the CI formatter check.

🤖 Generated with Claude Code

Commit the previously untracked CI workflow with the review fixes:
- pin Go 1.26.6 once through env.GO_VERSION instead of floating '1.26';
- add timeout-minutes to every job (15/30/40) instead of the 360-minute
  default, and give the race run a 30-minute go test timeout;
- run the test job on ubuntu-latest and macos-latest (the macOS job
  exercises the sandbox-exec runner);
- add a pinned govulncheck job and workflow_dispatch.
Action SHAs stay pinned (checkout v6.0.2, setup-go v6.4.0). gofmt is kept
as the formatter check; see the PR for why gofumpt is not adopted yet.

Finding: F100
The module was named `trace`, which is not fetchable and would clash with
any other module of that name. Trace lives at github.com/GrayCodeAI/trace;
the only package is cmd/trace (package main), so no import paths change.

Finding: F099
govulncheck v1.1.4 reports two vulnerabilities reachable from Trace's SSH
server in golang.org/x/crypto v0.55.0, both fixed in v0.56.0:
- GO-2026-6355: DoS on a deadlocked established channel in x/crypto/ssh
- GO-2026-6354: DoS on a deadlocked undecided channel in x/crypto/ssh

This is the same change as in the security-hardening PR, included here so
the new govulncheck CI job passes on this branch too; the identical
edits merge cleanly in either order. `go get` also normalizes the go
directive from 1.26 to 1.26.0, which x/crypto v0.56.0 requires.
- VERSION holds the release version (0.0.1), like the sibling repos.
- `trace version` prints the version, commit, and build date, which
  release builds set through -ldflags; plain builds report "dev".
- Makefile targets: build, install, test, race, vet, fmt, fmt-check,
  tidy-check, vulncheck, and check (fmt-check, vet, build, race). All
  run with GOWORK=off.
- .gitignore also ignores bin/ and dist/.

Finding: F099
- SECURITY.md: private reporting through GitHub private vulnerability
  reporting or security@graycodeai.com, supported versions (latest only
  while pre-1.0), scope, and safe-operation pointers.
- CONTRIBUTING.md: setup, `make check`, Conventional Commits, tests and
  docs with every behaviour change.
- CODE_OF_CONDUCT.md: Contributor Covenant 2.1, reports to
  hello@graycodeai.com.

Finding: F099
Start CHANGELOG.md (Keep a Changelog) with the unreleased 0.0.1 entry for
the first public version.

Finding: F099
On a pushed v* tag, the release workflow checks that the tag equals
v$(cat VERSION), runs go vet and the tests, and runs GoReleaser v2.17.0
(action pinned by SHA) to build trace for linux and darwin on amd64 and
arm64 with -trimpath and version ldflags. It publishes tar.gz archives
(binary, README, LICENSE, CHANGELOG, SECURITY) and a SHA-256
checksums.txt on the GitHub release. Nothing is signed, and the release
notes say so. Windows is not built: Trace relies on POSIX file locking.

Verified locally with `goreleaser check` and a snapshot build: four
archives were produced and `shasum -a 256 -c checksums.txt` passed.

Finding: F099
Describe the layout, the make targets, the JSON-store and subprocess
conventions, secret handling, and the evidence rules for changes. AGENTS.md
is the only agent-instruction file; tool-specific files such as CLAUDE.md
are not used.
- README: state what Trace is (a self-hosted Git forge for small teams
  with signed agent history, part of GrayCode), its pre-1.0 alpha status,
  that 0.0.1 is not released yet, that it builds for Linux and macOS
  only, and how to build from a clone; point to SECURITY.md,
  CONTRIBUTING.md, AGENTS.md, and the release workflow.
- README and ARCHITECTURE: pull requests are merged in the browser by
  admins or maintainers (fast-forward, squash, or merge commit) under
  the repository's approval, check, and CODEOWNERS policy, not only
  fast-forwarded by an admin; protected branches are configurable.
- README: the package paragraph no longer denies the basic npm and PyPI
  endpoints that the same README documents.
- ARCHITECTURE: the operations milestone lists what now exists (backup
  verification, basic LFS, release builds) and what is still missing.
- `trace user grant` usage lists the maintain role it already accepts.

The rate-limit and sandboxing statements are corrected in the
security-hardening PR, which changes that behaviour.

Findings: F097, F099
- Rename stale entries: Gitness is now Harness Open Source; Sourcegraph
  Cody is Enterprise-only and Sourcegraph's agent is Amp.
- Add a dated table (sources checked 2026-09-26) of 2026 forge agent
  features: GitHub's Agents tab and agent control plane with an
  actor_is_agent audit field, the GitLab Duo Agent Platform, Forgejo's
  prohibition of AI-generated contributions, Gitea 1.26, Graphite's cloud
  agents in pull requests. Each row states what Trace lacks; agent
  attribution in the audit log and a per-repository AI-contribution
  policy join the remaining work.
- Entire comparison: add adapter coverage (Trace 4, Entire 8, with the
  missing agents named), checkpoint ref layout (refs/entire/checkpoints
  vs Trace's refs/trace/agent-bundles, no import path), and the regional
  mirror preview.

Facts and links come from the campaign's research refresh, whose pages
were fetched on 2026-09-26.

Findings: F299, F300
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant