feat(security): license gate, CVE patch bot, maintainer key KRL engine, OSS sustainability reserve (#586 #587 #599 #619) - #640
Merged
Mikey-222 merged 3 commits intoSep 29, 2026
Conversation
Commits b075f64, f3b56f5, ed2f588, ba09fff and 4fb06c9 replaced these files with a single "// Implementation added" line, which broke npm installs, the Cargo workspace and the docs. Restore each file to the version immediately before it was overwritten so the security and sustainability work in this branch has a working base.
…e and OSS sustainability reserve Hel-Phone#586 license compliance & copyleft gate - scripts/license-compliance.js scans npm (package-lock + installed package.json) and Cargo (`cargo metadata`) licenses, evaluates full SPDX expressions and fails CI on GPL/AGPL/SSPL/strong copyleft outside the reviewed exception list. - licenses.json attribution manifest (deterministic), built into dist/ by `npm run build:release` in the signed release pipeline. - docs/legal-compliance.md, CI supply-chain gate, npm scripts. Hel-Phone#599 automated CVE patch bot - scripts/auto-patch-cve.js parses GitHub Security Advisories (npm audit or the GitHub REST advisories API), plans the minimum non-vulnerable version per vulnerable name@version, bumps direct ranges / writes root overrides, re-verifies the lockfile + audit, runs the regression suite (rolling back on failure) and can open a security PR. - cve-patch-bot.yml (weekly) and a report-only CI step. - Applied it to this tree: 11 advisories fixed (all 9 high) with no new test failures; major-bump and unfixable items left for review. Hel-Phone#619 maintainer key revocation & web-of-trust verification - scripts/security/verify_maintainer_keys.js: in-process RFC 4880 parser and RSA/EdDSA/ECDSA verification of commit, tag and artifact signatures against live keyserver revocation data (cached), with RFC 4880 revocation-reason semantics (compromise invalidates earlier signatures) and web-of-trust certification checks. - config/maintainer-keys.json, verify-keys.yml (nightly KRL sweep of release tags), release-pipeline and CI integration. Hel-Phone#587 Soroban open source sustainability reserve - contracts/helphone_dao/src/sustainability.rs: 1% protocol fee into a SAC-token reserve, DAO-voted maintainer grants paid on proposal execution (retryable when the reserve is short), funding stats. - Fix helphone_dao compile errors (invalid event fields, Vec alias, missing SEP-41 total_supply -> admin-set voting supply) and replace its non-running tests; add it to CI. - contract.ts client, VaultDashboard sustainability panel, types, docs. Closes Hel-Phone#586 Closes Hel-Phone#587 Closes Hel-Phone#599 Closes Hel-Phone#619
Merges upstream additions (egress monitor, API drift guard, e2e layout matrix, security guardians in helphone_dao, ProposalQueuedEvent, oracle price feed, emergency_vault, WebTransport spike, WASM reader) with the feature branch supply-chain security additions (Hel-Phone#586 Hel-Phone#587 Hel-Phone#591 Hel-Phone#599 Hel-Phone#619): license gate, CVE patch bot, maintainer key KRL engine, sustainability reserve. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
@KingFRANKHOOD Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #586
Closes #587
Closes #599
Closes #619
mainhas been overwritten with placeholder contentCommits b075f64, f3b56f5, ed2f588, ba09fff, 4fb06c9 and about 20 others replaced files with a single
// Implementation addedline, includingpackage.json,Cargo.toml,README.md,soroban-contract.md,src/types/index.ts, severalserver/andtest/files, and theaegis_vault/helphone-contractlib.rs. Because of this,npm ciand the Cargo workspace are broken onmain.The first commit (
db042dd) restores only the five files this PR builds on, each to the version immediately before it was overwritten. The other overwritten files are out of scope here and still need restoring. They are the cause of the 245 test failures that already exist onmain.#586: License compliance & copyleft gate
scripts/license-compliance.js(no dependencies):package-lock.json, falling back to the installedpackage.json, the same source license-checker uses.cargo metadata --lockedforcontracts/*andcontract/.ORtakes the most permissive branch,ANDthe most restrictive, andWITHexceptions are handled.--strict.licenses.json: a deterministic attribution manifest (1,466 packages: 1,181 npm, 285 cargo).npm run build:releasewrites it intodist/inside the SLSA-signed release.docs/legal-compliance.md, a CIsupply-chainstep, and npm scripts.#599: Automated CVE patch bot
scripts/auto-patch-cve.jsreads GitHub Security Advisories, either throughnpm auditor the GitHub REST/advisories?affects=API. For every vulnerablename@versionit plans the minimum fixed version: the lowest published, non-deprecated version that no advisory matches, on the same major.overrides. Major bumps are left for a human unless--allow-majoris passed.--apply:npm install.npm auditno longer report the patched advisories.--verifycommand.--open-prcommits the change, pushes it, and opens a PR with an advisory table, verification results and a follow-up list.cve-patch-bot.ymlruns it weekly. The CI step is report-only and fails only on critical advisories.npm auditwent from 24 to 9 findings, with 0 high. The existing test suite has no new failures. Still needing manual work:uuidandstream-json(major bumps) andelliptic(no fix released).#619: Maintainer key revocation & web-of-trust engine
scripts/security/verify_maintainer_keys.jsincludes an RFC 4880 packet parser and verifies RSA, EdDSA/Ed25519 and ECDSA signatures withnode:crypto, so no gpg is needed. It covers commits (--range), tags (--tags) and release artifacts (--artifact/--signature)..cache/maintainer-keyswith a TTL. Revocation certificates are verified cryptographically.config/maintainer-keys.json(currently the GitHub web-flow keys) or is certified by one.dependencies[]pins upstream maintainer fingerprints for revocation checks.supply-chain), inverify-keys.yml(pushes, release tags, and a nightly--refreshsweep of everyv*tag), and before the release build inslsa-provenance.yml. SetREQUIRE_SIGNED_RELEASES=trueto make release tags strict.#587: Soroban OSS sustainability reserve
contracts/helphone_dao/src/sustainability.rs:collect_sustainability_fee) into a reserve held in a SAC token.propose_maintainer_grantopens a DAOFundAllocationproposal. When it passes and executes after the timelock, the grant is paid automatically.Pendingand can be retried withdisburse_grant.helphone_daodid not compile onmain: invalid&weight:event fields, an unsupportedVecalias, and a call tototal_supply(), which SEP-41 tokens don't have (replaced with an admin-set voting supply). Its tests also called contract functions outside a contract context. This PR fixes all of that, replaces the tests with 7 client-based tests covering the full grant lifecycle, and adds the crate to CI.src/lib/contract.tsclient, a live sustainability panel onVaultDashboard.jsx, types, and asoroban-contract.mdsection.[profile.release]to the workspace root, because Cargo ignores member profiles.Testing
cargo test(helphone_dao): 7/7 pass. Thewasm32v1-nonerelease build succeeds.license-compliance,cve-patch,maintainer-keys,sustainability-pool). The key-engine tests use gpg-generated fixtures: Ed25519 and RSA keys, a real "compromised" revocation and a "superseded" one, a web-of-trust certification, and a detached artifact signature.main(from the overwritten files) are unchanged, with no new failures.