Conversation
Commit the previously untracked CI workflow with the review fixes: - pin Go 1.26.6 once through env.GO_VERSION instead of floating '1.26'; - add timeout-minutes to every job (15/30/40) instead of the 360-minute default, and give the race run a 30-minute go test timeout; - run the test job on ubuntu-latest and macos-latest (the macOS job exercises the sandbox-exec runner); - add a pinned govulncheck job and workflow_dispatch. Action SHAs stay pinned (checkout v6.0.2, setup-go v6.4.0). gofmt is kept as the formatter check; see the PR for why gofumpt is not adopted yet. Finding: F100
The module was named `trace`, which is not fetchable and would clash with any other module of that name. Trace lives at github.com/GrayCodeAI/trace; the only package is cmd/trace (package main), so no import paths change. Finding: F099
govulncheck v1.1.4 reports two vulnerabilities reachable from Trace's SSH server in golang.org/x/crypto v0.55.0, both fixed in v0.56.0: - GO-2026-6355: DoS on a deadlocked established channel in x/crypto/ssh - GO-2026-6354: DoS on a deadlocked undecided channel in x/crypto/ssh This is the same change as in the security-hardening PR, included here so the new govulncheck CI job passes on this branch too; the identical edits merge cleanly in either order. `go get` also normalizes the go directive from 1.26 to 1.26.0, which x/crypto v0.56.0 requires.
- VERSION holds the release version (0.0.1), like the sibling repos. - `trace version` prints the version, commit, and build date, which release builds set through -ldflags; plain builds report "dev". - Makefile targets: build, install, test, race, vet, fmt, fmt-check, tidy-check, vulncheck, and check (fmt-check, vet, build, race). All run with GOWORK=off. - .gitignore also ignores bin/ and dist/. Finding: F099
- SECURITY.md: private reporting through GitHub private vulnerability reporting or security@graycodeai.com, supported versions (latest only while pre-1.0), scope, and safe-operation pointers. - CONTRIBUTING.md: setup, `make check`, Conventional Commits, tests and docs with every behaviour change. - CODE_OF_CONDUCT.md: Contributor Covenant 2.1, reports to hello@graycodeai.com. Finding: F099
Start CHANGELOG.md (Keep a Changelog) with the unreleased 0.0.1 entry for the first public version. Finding: F099
On a pushed v* tag, the release workflow checks that the tag equals v$(cat VERSION), runs go vet and the tests, and runs GoReleaser v2.17.0 (action pinned by SHA) to build trace for linux and darwin on amd64 and arm64 with -trimpath and version ldflags. It publishes tar.gz archives (binary, README, LICENSE, CHANGELOG, SECURITY) and a SHA-256 checksums.txt on the GitHub release. Nothing is signed, and the release notes say so. Windows is not built: Trace relies on POSIX file locking. Verified locally with `goreleaser check` and a snapshot build: four archives were produced and `shasum -a 256 -c checksums.txt` passed. Finding: F099
Describe the layout, the make targets, the JSON-store and subprocess conventions, secret handling, and the evidence rules for changes. AGENTS.md is the only agent-instruction file; tool-specific files such as CLAUDE.md are not used.
- README: state what Trace is (a self-hosted Git forge for small teams with signed agent history, part of GrayCode), its pre-1.0 alpha status, that 0.0.1 is not released yet, that it builds for Linux and macOS only, and how to build from a clone; point to SECURITY.md, CONTRIBUTING.md, AGENTS.md, and the release workflow. - README and ARCHITECTURE: pull requests are merged in the browser by admins or maintainers (fast-forward, squash, or merge commit) under the repository's approval, check, and CODEOWNERS policy, not only fast-forwarded by an admin; protected branches are configurable. - README: the package paragraph no longer denies the basic npm and PyPI endpoints that the same README documents. - ARCHITECTURE: the operations milestone lists what now exists (backup verification, basic LFS, release builds) and what is still missing. - `trace user grant` usage lists the maintain role it already accepts. The rate-limit and sandboxing statements are corrected in the security-hardening PR, which changes that behaviour. Findings: F097, F099
- Rename stale entries: Gitness is now Harness Open Source; Sourcegraph Cody is Enterprise-only and Sourcegraph's agent is Amp. - Add a dated table (sources checked 2026-09-26) of 2026 forge agent features: GitHub's Agents tab and agent control plane with an actor_is_agent audit field, the GitLab Duo Agent Platform, Forgejo's prohibition of AI-generated contributions, Gitea 1.26, Graphite's cloud agents in pull requests. Each row states what Trace lacks; agent attribution in the audit log and a per-repository AI-contribution policy join the remaining work. - Entire comparison: add adapter coverage (Trace 4, Entire 8, with the missing agents named), checkpoint ref layout (refs/entire/checkpoints vs Trace's refs/trace/agent-bundles, no import path), and the regional mirror preview. Facts and links come from the campaign's research refresh, whose pages were fetched on 2026-09-26. Findings: F299, F300
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prepares Trace for life as the public repository
GrayCodeAI/trace: the module path, version, build and release tooling, CI, project policies, and documentation that matches the code. Behaviour changes are limited to a newtrace versioncommand and thetrace user grantusage text; all security fixes are in the separate security-hardening PR, #2.mainwas pushed unchanged (16ea592).Findings addressed
github.com/GrayCodeAI/trace;VERSION0.0.1;trace version(ldflagsmain.Version/Commit/BuildDate); Makefile (build install test race vet fmt fmt-check tidy-check vulncheck check); tag-triggered GoReleaser release for linux and darwin, amd64 and arm64, with SHA-256checksums.txtand no signing, and the release notes say so; the release job fails unless the tag equalsv$(cat VERSION); SECURITY.md (GitHub private vulnerability reporting plussecurity@graycodeai.com), CONTRIBUTING.md, CODE_OF_CONDUCT.md (Contributor Covenant 2.1,hello@graycodeai.com), CHANGELOG.md, AGENTS.md (AGENTS.md-only, conventions, evidence rules); README status (pre-1.0 alpha, 0.0.1 not released, Linux and macOS only, build from source)env.GO_VERSION;timeout-minuteson every job; tests on ubuntu and macOS; race job; pinnedgovulncheck;workflow_dispatch; action SHAs pinned and verified against their tagstrace user grantusage now listsmaintainactor_is_agent, the GitLab Duo Agent Platform, Forgejo's AI policy, Gitea 1.26, Graphite), each with the Trace gaprefs/entire/checkpoints/<shard>/<id>vsrefs/trace/agent-bundles/, no import path), regional mirror previewAlso included: 885a186 bumps
golang.org/x/cryptoto v0.56.0 (GO-2026-6354, GO-2026-6355), the same change as in #2, so the new govulncheck job passes on this branch. The identical edits merge cleanly.Not reproduced / deferred
gofumpt@v0.10.0 -l .lists about 70 files, and reformatting them here would conflict with nearly every file fix: harden Trace against the September 2026 security audit findings #2 touches. The follow-up is a formatting-only PR after both merge. CI keepsgofmt.audit.jsonland the per-repository AI-contribution policy are features. They are recorded as gaps in FEATURES.md, not implemented here.ecosystem.yamlentry for Trace belongs to the rho workstream.Verification
Gates run from this worktree (Go 1.26.5 darwin/arm64,
GOWORK=off):git log -p --all, 25,900 lines): no private-key blocks, no GitHub/AWS/Slack/OpenAI/hwc_token prefixes, and no 43-character base64url strings (the admin-token format) other than test function names and a go.sum hash. The only emails areexample.invalidfixtures and the author identity. No path underdata/was ever committed.goreleaser check: 1 configuration file validated.goreleaser release --snapshot --clean --skip=publish(v2.17.0) built four archives, each containingtrace, README, LICENSE, CHANGELOG and SECURITY;shasum -a 256 -c checksums.txtreturned OK for all four; the linux/amd64 binary is a static, stripped ELF. The output was deleted afterwards.actionlintv1.7.7 on ci.yml and release.yml: 0 errors.make build && ./bin/trace version:trace 0.0.1 (commit 885a186, built ...).govulncheck@v1.1.4: no module findings after the x/crypto bump. The standard-library findings are fixed in Go 1.26.6, which CI and the release pin.git merge-tree --write-tree fix/security-hardening chore/release-readiness: clean. A local merge of c71fe90 + 1f9ac1b (never pushed) also passes gofmt, vet, build, andgo test -race(ok, 85.882s).merge-treeis also clean against fix: harden Trace against the September 2026 security audit findings #2's current head, 45d0efa, which only adds a test-fixture fix.Follow-ups
v*tag ruleset to GrayCodeAI/trace (restrict creation, deletion and updates of release tags) before the first tag.v0.0.1only after both PRs merge, and add fix: harden Trace against the September 2026 security audit findings #2's changes to CHANGELOG.md first.ecosystem.yaml(rho workstream).🤖 Generated with Claude Code