diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 778cee9..b03ebf0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,11 +1,10 @@ name: release -# Dormant by choice: releases are currently published manually by the -# maintainer, and no automation token capable of publishing this package -# exists. This workflow becomes the release path once npm Trusted Publishing -# is configured for the package and the publish step below is switched to -# OIDC (needs npm >= 11.5.1). Until then a pushed tag fails closed at -# authentication: the publish step carries no credentials at all. +# The release path: a pushed v* tag publishes via npm Trusted Publishing +# (OIDC, needs npm >= 11.5.1) with provenance attestation. No long-lived npm +# token exists anywhere; until the Trusted Publisher is configured on the +# npm side, a pushed tag fails closed at authentication because the publish +# step carries no credentials at all. on: push: tags: ["v*"] @@ -42,6 +41,8 @@ jobs: fi done < <(git ls-files -- src bin test build.mjs .github) exit "$bad" + - name: npm with OIDC trusted publishing support + run: npm install -g npm@^11.5.1 - run: npm ci - run: npm run typecheck - run: npm test diff --git a/SECURITY.md b/SECURITY.md index 3f5db84..8d64e8a 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -12,4 +12,4 @@ These constraints govern the design. A build that violates one is a bug, and a r 2. Secrets never enter a bundle. MCP server entries carry names and portability classes only. 3. The tool makes no network calls. There is no telemetry, no update check and no upload target. 4. `apply` verifies every file against its manifest hash before writing, rejects paths and symlinks that escape the target directory, and writes a backup before the first change. -5. The published package has zero runtime dependencies and is built from this repository by the release maintainer. Publishing runs through the maintainer's npm account with two-factor authentication; no automation token capable of publishing this package exists. CI-based publishing with provenance attestation is the planned next step and will supersede this line when it lands. +5. The published package has zero runtime dependencies and is built from this repository in CI. As of the first tag published after Trusted Publishing was configured, releases publish through npm Trusted Publishing (OIDC) from a pinned GitHub Actions workflow with provenance attestation; no long-lived npm token capable of publishing this package exists anywhere. (Releases through 0.2.4 were published manually under the maintainer's two-factor authentication.) diff --git a/docs/THREAT-MODEL.md b/docs/THREAT-MODEL.md index fc02098..aaa325c 100644 --- a/docs/THREAT-MODEL.md +++ b/docs/THREAT-MODEL.md @@ -45,7 +45,7 @@ These are deliberate v1 edges, kept here so they are decisions rather than surpr ## Out of scope -agent-sync does not defend against a compromised source machine, and it does not judge the content of what you sync: a skill is data to this tool, and a malicious skill synced faithfully is still malicious on arrival. Review what lives in your setup before carrying it anywhere. Supply-chain trust in the published package itself rests today on two things: a zero-dependency runtime and a deterministic build. Releases are currently published by the maintainer under two-factor authentication, and no automation token capable of publishing this package exists. npm provenance attestation and pinned-CI publishing arrive together when releases move into CI (`.github/workflows/release.yml` is that path, dormant until then). Until provenance lands, verify a release by unpacking the registry tarball and comparing per-file hashes against a local `npm pack` of the same tagged commit: the build is deterministic, so the contents must match even though the compressed tarballs may differ by a gzip header byte. +agent-sync does not defend against a compromised source machine, and it does not judge the content of what you sync: a skill is data to this tool, and a malicious skill synced faithfully is still malicious on arrival. Review what lives in your setup before carrying it anywhere. Supply-chain trust in the published package rests on three things: a zero-dependency runtime, a deterministic build, and npm Trusted Publishing — releases publish from the pinned CI workflow (`.github/workflows/release.yml`) via OIDC with provenance attestation, and no long-lived npm token capable of publishing this package exists anywhere (releases through 0.2.4 were published manually under two-factor authentication). Verify a release either through its provenance attestation or by unpacking the registry tarball and comparing per-file hashes against a local `npm pack` of the same tagged commit: the build is deterministic, so the contents must match even though the compressed tarballs may differ by a gzip header byte. ## Reporting