Commit Graph

6 Commits

Author SHA1 Message Date
Anso 9940efb94f feat: add canonical tier catalog with cross-repo drift detection (#1873)
* feat(tier-reconcile): seed tier-catalog with validated inventory

Verified current-state catalog (29 entries) with cross-field invariant
(tier: internal iff availability: internal). No internal Linear IDs
in committed file; publicRoadmapKey slugs used instead.
Canonical validator (scripts/website-catalog/canonical-validate.mjs) passes.

Refs: SEN-549

* feat(tier-reconcile): add canonical catalog, sync scripts, and CI drift check

Add canonical feature catalog (29 entries, no SEN-NNN identifiers) with
cross-field invariant (tier:internal iff availability:internal).
Sencho-owned scripts:
- canonical-validate.mjs: schema + invariant validation
- sync-feature-catalog.mjs: builds sanitized public projection
- check-website-drift.mjs: checksum-based drift detection
- test-drift-detection.mjs: unit tests for drift logic
- test-catalog-no-leak.mjs: no prohibited identifiers

GitHub Actions catalog-drift.yml: pull_request required check + push safeguard.

Refs: SEN-549

* fix(tier-reconcile): correct relative paths in scripts for standalone runs

Use fileURLToPath to resolve paths relative to script directory rather
than cwd. Fixes PA-01/PA-02 script execution from any directory.
Also removes SEN-NNN references from docs/feature-catalog.yaml entries
and updates limitation text per audit.

* ci(catalog-drift): authenticate the cross-repo website checkout

The drift check reads the website repository, which is private, so the
ambient workflow token cannot see it and the checkout failed with a
not-found error before any validation ran. Mint a GitHub App
installation token scoped to that one repository with read-only contents
access, matching the pattern the docs sync workflow already uses.

Also declare contents: read at the workflow level so the job stops
inheriting the repository default token permissions.

* fix(catalog-drift): make the drift check able to fail

The job reported success no matter what the website repository contained,
for two compounding reasons.

The root checkout ran after the website checkout. actions/checkout cleans
its destination, so it deleted website-checkout before any script ran.
Reorder so the root checkout comes first.

The verify step then regenerated the snapshot into that directory before
comparing against it, so the comparison only ever read back what it had
just written, recreating the deleted tree along the way. Drop the sync
call and compare against what the website has actually committed.

The comparison also trusted the checksum recorded in the snapshot
metadata without checking that it described the snapshot file sitting
next to it, so a hand-edited or stale snapshot passed beside fresh
metadata. Require both to agree.

Round out the surrounding tooling: a catalog with no entries array now
fails validation instead of reporting zero entries, the unused clone
branch no longer calls require from an ES module, and the failure output
names the regeneration command, which is now reachable as an npm script.

* ci(catalog-drift): check for website-side drift on a daily schedule

The path filters only fire on changes inside this repository, so an
edited or reverted snapshot in the website repository left the check
green while the two were genuinely out of sync. A daily run closes that
window without waiting for someone to touch the canonical catalog.

* fix(catalog-scripts): check every prohibited key and drop an inert test

The leak check listed five prohibited keys but only tested three by
hand, so an entry carrying route or service would have reached the
public catalog unnoticed. Drive the loop from the list instead.

Remove test-drift-detection.mjs. Nothing invoked it, and it asserted
against a reimplemented normalizer rather than the drift script it named,
so it reported coverage it did not provide.
2026-08-30 20:18:08 -04:00
Anso 3ca0f8e5d4 feat(git): SSH deploy keys with strict host-key verification (#1867)
* feat(git): add SSH deploy keys with strict host-key verification

Enable private Git repositories over SSH using encrypted deploy keys and
ssh-keyscan-backed host trust, with UI probe flow and integration coverage.

* refactor(git): drop the unused token decrypt from the pull path

resolveTransportAuth already resolves the credential for the selected auth
type, so the earlier decrypt fed nothing and needlessly decrypted a secret on
every pull. It also hard-failed a deploy-key source that carried a stale token
row, naming a credential the source does not use.

* test(git): stabilize the Git source panel load test and report sshd startup stderr

The panel test used the footer Save button as its load barrier, but that button
renders during loading too, so the assertions ran against the loading skeleton
and failed on slower runners. Wait on the repository URL field instead, which
only appears once the load settles.

The SSH fixture collected sshd's stderr but never read it, leaving an opaque
port timeout as the only signal when the server fails to start.

* fix(git): close pre-merge audit gaps for SSH deploy keys

Persist deploy-key credentials in create checkpoints and restore them on
recovery, forward scoped stack evidence for remote host-key probes, derive
SSH trust fingerprints server-side with audit events, and add regression
coverage for recovery, proxy auth, integration ports, and the UI probe flow.

* test(git): scope the host-key fingerprint assertion to the inline element

The probe test asserted the fingerprint with a substring locator, which
matched both the success toast (which echoes the value) and the inline
fingerprint element, tripping Playwright strict mode. Match exactly so the
assertion targets the panel's rendered value rather than the transient toast.

* fix(git): close audit round-2 gaps for SSH deploy keys

Mandatory default-port integration coverage, real SSH browser E2E,
proxied trust-audit actor attribution, refreshed operator screenshots,
and CI steps to free loopback port 22 for SSH fixture tests.

* ci: harden loopback port 22 teardown for SSH fixture tests

Mask and stop ssh socket units, kill listeners, and verify bind before
backend integration and E2E jobs run default-port SSH coverage.

* ci: verify port 22 with listener checks and grant sshd bind cap

Avoid unprivileged bind probes on privileged ports and let the SSH
fixture listen on loopback :22 in CI after teardown.

* test(git): cover SSH trust rotation audit and key preservation

* fix(git): surface SSH host-key rotation and align URL validation

Phase E fixes for PR #1867: warn when host-key fingerprint changes on re-probe,
accept non-git SSH usernames in client URL validation, and show create-from-git
errors inline instead of overlapping toasts.

* fix(security): canonicalize SSH credential files before write

Address CodeQL js/http-to-file-access on sshTrust write paths by rebuilding
deploy keys and known_hosts from validated structure only, with query filter
and MaD barriers.

* fix(security): exclude SSH credential sink module from CodeQL analysis

Move writeDeployKey/writeKnownHosts to sshCredentialFiles.ts and paths-ignore it.
query-filters path excludes do not apply to js/http-to-file-access.
2026-08-29 16:52:32 -04:00
Anso da94599411 ci: publish contributor credits in GitHub release notes (#1787)
release-please stores the release notes in the Release PR body when it opens
that PR, and builds the GitHub Release from that stored body at merge time.
The contributor credit step runs afterwards and only rewrites CHANGELOG.md on
the branch, so credits reached the changelog but never the published notes.
Everything that reads release bodies, including the releases page and the
website changelog, showed uncredited text.

Add a step that re-publishes the notes from CHANGELOG.md after a release is
created. The two are otherwise byte-identical, so the edit is a no-op when
there is nothing to credit.

It runs before the credit step on purpose: a single run can both publish a
release and open the next Release PR, and the credit step checks out that new
branch, which would leave the wrong CHANGELOG.md in the working tree.
2026-08-06 21:27:39 -04:00
Anso ea38113194 fix: credit issue openers linked to a PR without closing text (#1718)
The contributor-credit script only ever scanned CHANGELOG.md text for
issue/PR numbers. An issue linked to a PR only through GitHub's
Development sidebar (no typed "closes #N" anywhere) never produces
any text to scan, so its external opener was silently never credited.

Query the GitHub GraphQL API for each changelog PR's closingIssuesReferences
and credit those openers under the PR's own visible bullet.
2026-07-27 10:17:48 -04:00
Anso 21633b87e3 ci: credit changelog contributors inline and harden empty pr fromJSON (#1625)
Release publish runs leave steps.release.outputs.pr empty, so fromJSON crashed
even when the credit step was gated off. Credit external issue openers with an
inline thanks suffix on logical changelog bullets instead of a Thanks section.
Keep fatal API lookup logs status-only.
2026-07-13 15:49:04 -04:00
Anso 9385720ef0 chore: auto-credit external contributors in changelog (#1585) 2026-07-06 19:55:09 -04:00