Skip to content

feat(security): license gate, CVE patch bot, maintainer key KRL engine, OSS sustainability reserve (#586 #587 #599 #619) - #640

Merged
Mikey-222 merged 3 commits into
Hel-Phone:mainfrom
KingFRANKHOOD:feat/supply-chain-security-619-586-587-599
Sep 29, 2026
Merged

Mikey-222 merged 3 commits into
Hel-Phone:mainfrom
KingFRANKHOOD:feat/supply-chain-security-619-586-587-599

Conversation

@KingFRANKHOOD

Copy link
Copy Markdown
Contributor

Closes #586
Closes #587
Closes #599
Closes #619

⚠️ Note: main has been overwritten with placeholder content

Commits b075f64, f3b56f5, ed2f588, ba09fff, 4fb06c9 and about 20 others replaced files with a single // Implementation added line, including package.json, Cargo.toml, README.md, soroban-contract.md, src/types/index.ts, several server/ and test/ files, and the aegis_vault / helphone-contract lib.rs. Because of this, npm ci and the Cargo workspace are broken on main.

The first commit (db042dd) restores only the five files this PR builds on, each to the version immediately before it was overwritten. The other overwritten files are out of scope here and still need restoring. They are the cause of the 245 test failures that already exist on main.

#586: License compliance & copyleft gate

  • scripts/license-compliance.js (no dependencies):
    • Reads npm licenses from package-lock.json, falling back to the installed package.json, the same source license-checker uses.
    • Reads Cargo licenses via cargo metadata --locked for contracts/* and contract/.
    • Evaluates full SPDX expressions: OR takes the most permissive branch, AND the most restrictive, and WITH exceptions are handled.
  • Gate: CI fails on GPL/AGPL/SSPL/EUPL/strong copyleft unless the package is on the reviewed exception list. Weak copyleft or unknown licenses produce a warning, and fail under --strict.
  • licenses.json: a deterministic attribution manifest (1,466 packages: 1,181 npm, 285 cargo). npm run build:release writes it into dist/ inside the SLSA-signed release.
  • Added docs/legal-compliance.md, a CI supply-chain step, and npm scripts.

#599: Automated CVE patch bot

  • scripts/auto-patch-cve.js reads GitHub Security Advisories, either through npm audit or the GitHub REST /advisories?affects= API. For every vulnerable name@version it plans the minimum fixed version: the lowest published, non-deprecated version that no advisory matches, on the same major.
  • It fixes direct dependencies by bumping their range and transitive ones through root overrides. Major bumps are left for a human unless --allow-major is passed.
  • --apply:
    1. Runs npm install.
    2. Checks that the lockfile and npm audit no longer report the patched advisories.
    3. Runs every --verify command.
    4. Rolls back all manifests if any step fails.
  • --open-pr commits the change, pushes it, and opens a PR with an advisory table, verification results and a follow-up list.
  • cve-patch-bot.yml runs it weekly. The CI step is report-only and fails only on critical advisories.
  • Run on this tree: it fixed 11 vulnerable versions (all 9 high: axios, ws, react-router, postcss, js-yaml, nanoid, smol-toml…). npm audit went from 24 to 9 findings, with 0 high. The existing test suite has no new failures. Still needing manual work: uuid and stream-json (major bumps) and elliptic (no fix released).

#619: Maintainer key revocation & web-of-trust engine

  • scripts/security/verify_maintainer_keys.js includes an RFC 4880 packet parser and verifies RSA, EdDSA/Ed25519 and ECDSA signatures with node:crypto, so no gpg is needed. It covers commits (--range), tags (--tags) and release artifacts (--artifact/--signature).
  • It fetches live revocation data from keys.openpgp.org and keyserver.ubuntu.com and caches it in .cache/maintainer-keys with a TTL. Revocation certificates are verified cryptographically.
  • It applies the RFC 4880 §5.2.3.23 revocation reasons. Compromised / no reason invalidates every signature by the key, including ones made before the revocation. Superseded / retired keeps earlier signatures valid.
  • Web of trust: a signer is trusted if it is a root in config/maintainer-keys.json (currently the GitHub web-flow keys) or is certified by one. dependencies[] pins upstream maintainer fingerprints for revocation checks.
  • It runs in CI (supply-chain), in verify-keys.yml (pushes, release tags, and a nightly --refresh sweep of every v* tag), and before the release build in slsa-provenance.yml. Set REQUIRE_SIGNED_RELEASES=true to make release tags strict.

#587: Soroban OSS sustainability reserve

  • contracts/helphone_dao/src/sustainability.rs:
    • Routes 1% of protocol transactions (collect_sustainability_fee) into a reserve held in a SAC token.
    • propose_maintainer_grant opens a DAO FundAllocation proposal. When it passes and executes after the timelock, the grant is paid automatically.
    • If the reserve is short at execution, the grant stays Pending and can be retried with disburse_grant.
    • Adds read endpoints for stats, grants and per-maintainer totals.
  • helphone_dao did not compile on main: invalid &weight: event fields, an unsupported Vec alias, and a call to total_supply(), which SEP-41 tokens don't have (replaced with an admin-set voting supply). Its tests also called contract functions outside a contract context. This PR fixes all of that, replaces the tests with 7 client-based tests covering the full grant lifecycle, and adds the crate to CI.
  • src/lib/contract.ts client, a live sustainability panel on VaultDashboard.jsx, types, and a soroban-contract.md section.
  • Moved [profile.release] to the workspace root, because Cargo ignores member profiles.

Testing

  • cargo test (helphone_dao): 7/7 pass. The wasm32v1-none release build succeeds.
  • New vitest files: 56 tests pass (license-compliance, cve-patch, maintainer-keys, sustainability-pool). The key-engine tests use gpg-generated fixtures: Ed25519 and RSA keys, a real "compromised" revocation and a "superseded" one, a web-of-trust certification, and a detached artifact signature.
  • Full suite: 406 passed. The 245 failures already on main (from the overwritten files) are unchanged, with no new failures.
  • The key verifier also ran against real history: it verified GitHub's RSA web-flow signature on the latest merge and flagged the unsigned commits that overwrote the files.

KingFRANKHOOD and others added 3 commits September 24, 2026 10:40
Commits b075f64, f3b56f5, ed2f588, ba09fff and 4fb06c9 replaced these
files with a single "// Implementation added" line, which broke npm
installs, the Cargo workspace and the docs. Restore each file to the
version immediately before it was overwritten so the security and
sustainability work in this branch has a working base.
…e and OSS sustainability reserve

Hel-Phone#586 license compliance & copyleft gate
- scripts/license-compliance.js scans npm (package-lock + installed
  package.json) and Cargo (`cargo metadata`) licenses, evaluates full SPDX
  expressions and fails CI on GPL/AGPL/SSPL/strong copyleft outside the
  reviewed exception list.
- licenses.json attribution manifest (deterministic), built into
  dist/ by `npm run build:release` in the signed release pipeline.
- docs/legal-compliance.md, CI supply-chain gate, npm scripts.

Hel-Phone#599 automated CVE patch bot
- scripts/auto-patch-cve.js parses GitHub Security Advisories (npm audit
  or the GitHub REST advisories API), plans the minimum non-vulnerable
  version per vulnerable name@version, bumps direct ranges / writes root
  overrides, re-verifies the lockfile + audit, runs the regression suite
  (rolling back on failure) and can open a security PR.
- cve-patch-bot.yml (weekly) and a report-only CI step.
- Applied it to this tree: 11 advisories fixed (all 9 high) with no
  new test failures; major-bump and unfixable items left for review.

Hel-Phone#619 maintainer key revocation & web-of-trust verification
- scripts/security/verify_maintainer_keys.js: in-process RFC 4880 parser
  and RSA/EdDSA/ECDSA verification of commit, tag and artifact
  signatures against live keyserver revocation data (cached), with
  RFC 4880 revocation-reason semantics (compromise invalidates earlier
  signatures) and web-of-trust certification checks.
- config/maintainer-keys.json, verify-keys.yml (nightly KRL sweep of
  release tags), release-pipeline and CI integration.

Hel-Phone#587 Soroban open source sustainability reserve
- contracts/helphone_dao/src/sustainability.rs: 1% protocol fee into a
  SAC-token reserve, DAO-voted maintainer grants paid on proposal
  execution (retryable when the reserve is short), funding stats.
- Fix helphone_dao compile errors (invalid event fields, Vec alias,
  missing SEP-41 total_supply -> admin-set voting supply) and replace its
  non-running tests; add it to CI.
- contract.ts client, VaultDashboard sustainability panel, types, docs.

Closes Hel-Phone#586
Closes Hel-Phone#587
Closes Hel-Phone#599
Closes Hel-Phone#619
Merges upstream additions (egress monitor, API drift guard, e2e layout
matrix, security guardians in helphone_dao, ProposalQueuedEvent, oracle
price feed, emergency_vault, WebTransport spike, WASM reader) with the
feature branch supply-chain security additions (Hel-Phone#586 Hel-Phone#587 Hel-Phone#591 Hel-Phone#599 Hel-Phone#619):
license gate, CVE patch bot, maintainer key KRL engine, sustainability reserve.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@KingFRANKHOOD Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Mikey-222
Mikey-222 merged commit 992018e into Hel-Phone:main Sep 29, 2026
1 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants