Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
ff7a0cc
fix(git): allow anonymous clone and fetch of public repositories
Patel230 Sep 26, 2026
dbaccc6
fix(actions): confine artifact collection to the job workspace
Patel230 Sep 26, 2026
a380ab1
fix(actions): initialize schedule state on a fresh node
Patel230 Sep 26, 2026
5ac64f9
feat(actions)!: let the operator decide which workflows may run
Patel230 Sep 26, 2026
a138ec0
fix(actions): make the macOS sandbox profile start a shell
Patel230 Sep 26, 2026
6e098f6
fix(actions): give jobs a minimal environment instead of the server's
Patel230 Sep 26, 2026
f40759a
fix(actions): forward job variables into Docker and stop whole steps
Patel230 Sep 26, 2026
9d0c14b
perf(actions): keep job logs out of actions.json and prune old runs
Patel230 Sep 26, 2026
0ab11fd
fix(hooks): stop protected-branch patterns from injecting shell code
Patel230 Sep 26, 2026
30bdbc4
fix(hooks): keep configured branch protection across server restarts
Patel230 Sep 26, 2026
8ae3139
fix(ssh): reject pushes to archived repositories
Patel230 Sep 26, 2026
8c3f76d
fix(ssh): run Git services with an explicit minimal environment
Patel230 Sep 26, 2026
00353f4
fix(oidc)!: bind OIDC sign-in to the provider's issuer and subject
Patel230 Sep 26, 2026
619af3a
fix(oidc): verify nonce, issuer, key size, and bound provider requests
Patel230 Sep 26, 2026
ff2924e
fix(api): compare the CSRF header in constant time and require it for…
Patel230 Sep 26, 2026
0953577
fix(raw,pages): check blob size before reading raw and Pages files
Patel230 Sep 26, 2026
33e2073
fix(raw,pages): never mark private repository content as publicly cac…
Patel230 Sep 26, 2026
2415bad
fix(web): sandbox raw and Pages content and drop unsafe-inline scripts
Patel230 Sep 26, 2026
7abb317
fix(ratelimit): throttle per client in memory and support trusted pro…
Patel230 Sep 26, 2026
4ce72d7
fix(scim): refuse passwords and support filters, paging, and member r…
Patel230 Sep 26, 2026
3545d8f
fix(webhooks): refuse internal destinations and redirects on delivery
Patel230 Sep 26, 2026
a55aa42
fix(lfs): store and serve LFS objects per repository
Patel230 Sep 26, 2026
474056d
fix(api): let maintainers run actions and manage secrets and Pages
Patel230 Sep 26, 2026
0db5e1a
fix(totp): reject reused codes and back off repeated failures per acc…
Patel230 Sep 26, 2026
4127b3f
fix(backup): refuse archive paths inside the data directory
Patel230 Sep 26, 2026
bf6c9fb
fix(repo): rename transfer references structurally, atomically, and u…
Patel230 Sep 26, 2026
714c6f5
fix(deps): bump golang.org/x/crypto to v0.56.0
Patel230 Sep 26, 2026
46bf803
ci: add GitHub Actions workflow with pinned Go and job timeouts
Patel230 Sep 26, 2026
c71fe90
fix(lfs): keep serving when a repository cannot be scanned for migration
Patel230 Sep 26, 2026
45d0efa
test: keep repository fixtures independent of a host Git LFS install
Patel230 Sep 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
84 changes: 84 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
name: CI

on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:

permissions:
contents: read

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

env:
# Pinned toolchain, matching the release workflow and sibling repositories.
GO_VERSION: "1.26.6"
# Keep this repository buildable regardless of any go.work file in a
# parent directory of a local multi-repository checkout.
GOWORK: "off"

jobs:
quality:
name: tidy + fmt + build + vet
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: true
- name: Module tidy is clean
run: |
go mod tidy
git diff --exit-code -- go.mod go.sum
- name: gofmt
run: test -z "$(gofmt -l .)"
- run: go build ./...
- run: go vet ./...

vulncheck:
name: govulncheck
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: true
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.1.4 ./...

test:
name: test (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
# macOS exercises the sandbox-exec runner; Linux the Docker path.
os: [ubuntu-latest, macos-latest]
runs-on: ${{ matrix.os }}
timeout-minutes: 30
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: true
# The suite starts real listeners and shells out to git and ssh.
- run: go test -count=1 -timeout=20m ./...

race:
name: race
runs-on: ubuntu-latest
timeout-minutes: 40
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: true
- run: go test -race -count=1 -timeout=30m ./...
6 changes: 3 additions & 3 deletions FEATURES.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,12 +30,12 @@ This is the honest baseline for the current monorepo. “All features from the t
| API repository creation | Implemented for admins | `POST /api/v1/repos` |
| Pull requests, drafts, labels, assignees, requested reviewers, review comments, approvals, code owners, merge queues, and merge strategies | Implemented with recursive CODEOWNERS path matching and an operator-triggered single-node queue | Durable local PR store; API, CLI, and browser review page; draft-to-ready lifecycle; labels/assignees/reviewer requests with inbox notifications; line comments anchor to a text file/line and commit; approval/check/code-owner policies are enforced; serialized queue rechecks policy before merging; merge supports fast-forward, squash, and explicit merge commits; unsupported CODEOWNERS syntax and distributed queue workers are not implemented |
| Issues, labels, milestones, notifications | Issues, labels, milestones, and local inbox implemented; email/push missing | Atomic `issues.json` store, notification inbox, API, CLI, and dedicated issue web page |
| CI runners and workflow files | Implemented, local, bounded queue, with opt-in macOS or Docker sandboxing | `.trace/workflow.json`, automatic push triggers, manual reruns, persisted runs, four-worker local queue, cancellation, logs, artifacts, repository-scoped secrets, opt-in persisted schedules, macOS `sandbox-exec`, and Docker isolation with no network/read-only root/capability drop; unsandboxed workflows remain trusted-only and hosted runners are not implemented |
| CI runners and workflow files | Implemented, local, bounded queue; the operator's `trace serve -actions` policy (default `sandboxed`) decides whether workflows run and whether they must request macOS or Docker sandboxing | `.trace/workflow.json`, automatic push triggers, manual reruns, persisted runs, four-worker local queue, cancellation, logs, artifacts, repository-scoped secrets, opt-in persisted schedules, macOS `sandbox-exec`, and Docker isolation with no network/read-only root/capability drop; unsandboxed workflows run only under `-actions trusted`, and hosted runners are not implemented |
| Webhooks | Implemented, signed delivery with retries/history | Admin API/CLI configuration; HTTPS or loopback HTTP; HMAC-SHA256 signatures; three attempts and persisted delivery records |
| Releases, assets, archive downloads, and Pages | Implemented | Tag-backed releases support bounded 100 MiB asset upload/list/download, gzip archives use `git archive`, and Pages serves committed branch files with public/private access and path validation |
| Packages, registries, Git LFS | Generic artifacts, basic npm/PyPI interoperability, and basic Git LFS implemented | Authenticated package publish/list/download, one-attachment npm publish, basic PyPI multipart upload and simple-index reads, and LFS batch/upload/download; SHA-256 verification and 100 MiB object caps; no wheel metadata or distributed object store |
| SSH Git transport | Implemented, key-authenticated, throttled, discoverable, and rotatable | `trace user key`, persisted host key, `trace ssh host-key`, `trace ssh rotate-host-key`, admin API rotation, `/.well-known/trace/ssh-host-key`, `git-upload-pack`/`git-receive-pack`, and a shared 60-connections/minute per-host limiter; rotation requires a Trace restart to load the new signer; disabled by default |
| SSO, 2FA, SCIM, audit log | Optional OIDC authorization-code login with PKCE; returned RS256 ID tokens are checked against discovered JWKS, while userinfo-only providers remain supported; TOTP 2FA, SCIM users and groups mapped to teams, audit log, and shared file-backed rate limits implemented; SAML remains missing | `trace sso oidc`, `/login/oidc`, `/login/oidc/callback`, `/scim/v2/Users`, `/scim/v2/Groups`, durable team membership, append-only `audit.jsonl`, admin API, and `429` request throttling shared across local processes |
| SSH Git transport | Implemented, key-authenticated, throttled, discoverable, and rotatable | `trace user key`, persisted host key, `trace ssh host-key`, `trace ssh rotate-host-key`, admin API rotation, `/.well-known/trace/ssh-host-key`, `git-upload-pack`/`git-receive-pack`, and a 60-connections/minute per-host limiter; rotation requires a Trace restart to load the new signer; disabled by default |
| SSO, 2FA, SCIM, audit log | Optional OIDC authorization-code login with PKCE; returned RS256 ID tokens are checked against discovered JWKS, while userinfo-only providers remain supported; TOTP 2FA, SCIM users and groups mapped to teams, audit log, and in-memory per-client rate limits (with trusted reverse-proxy support) implemented; SAML remains missing | `trace sso oidc`, `/login/oidc`, `/login/oidc/callback`, `/scim/v2/Users`, `/scim/v2/Groups`, durable team membership, append-only `audit.jsonl`, admin API, and per-client `429` request throttling (`-trusted-proxy` for reverse proxies) |
| Search and code indexing | Implemented, bounded persistent code index with live fallback; literal code, commit, and agent session search | Repository and workspace API/CLI/web queries return code, branch-scoped commit messages, and redacted session/checkpoint matches; commit results open a read-only diff page; each repository scans at most 1,000 recent commits and returns 100 matches; workspace search pages through ten authorized repositories at a time and respects team grants; code index rebuilds via API and refreshes on HTTP pushes; no semantic search |
| Agent session/checkpoint storage | Implemented, structured records with opt-in signed portability and narrow Codex/Claude Code/Gemini CLI/Cursor adapters | API, CLI, and browser page; sessions/checkpoints link to commits, redact common token/password/secret assignments, and can be exported/imported as Ed25519-signed bundles or explicitly published in private Git refs after expected node ID and target commit verification; supported completion notifications can queue metadata until the observed HEAD exists on the server; raw transcripts, automatic Git publication, and authorship verification are not implemented |
| Signed federation identity and peer sync | Implemented, configured peers, with explicit conflict decisions and source identity pinning | Persisted Ed25519 identity, signed full-ref manifests, first-use source node ID pinning with CLI/API/web inspection and explicit forget, exact probe ref comparison before an atomic mirror ref transaction, opt-in scheduling, non-fast-forward and changed-tag conflict detection, durable conflict records, and exact-object-ID source acceptance for branch, tag, or deletion conflicts; first contact still requires out-of-band verification, while network discovery and multi-writer reconciliation remain external |
Expand Down
Loading
Loading