Skip to content

docs: add AGENTS.md index and inherit org SECURITY.md - #121

Merged
liquidsec merged 2 commits into
devfrom
chore/org-standards-index
Oct 5, 2026
Merged

liquidsec merged 2 commits into
devfrom
chore/org-standards-index

Conversation

@singlerider

@singlerider singlerider commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Part of blacklanternsecurity/bbot-enterprise#157.

  • AGENTS.md: what the repo is, toolchain, setup, test commands, an index of the org standards with when to read each, and only facts specific to this repo. Versions are referenced in the manifest, not retyped.
  • CLAUDE.md points at AGENTS.md.
  • Setup documents the venv, pip, and maturin flow CI uses, since [tool.uv] managed = false makes uv sync fail.
  • SECURITY.md removed so the org default applies.

Validation

$ git diff --stat upstream/dev
  AGENTS.md   | 47 +++++++++++++++++++++++++++++++++++++++++++++++
  CLAUDE.md   |  1 +
  SECURITY.md | 16 ----------------
  3 files changed, 48 insertions(+), 16 deletions(-)
$ ./scripts/build-openssl.sh && python -m venv .venv && . .venv/bin/activate
$ pip install --upgrade pip maturin && pip install --group dev && maturin develop
Installed blasthttp-0.10.0
$ pytest -q
162 passed in 17.96s

Standards links point at blacklanternsecurity/.github/blob/main/standards. They resolve once the standards land in .github and it is made public (admin step).

Refs blacklanternsecurity/bbot-enterprise#157

A local SECURITY.md overrides the org default in
blacklanternsecurity/.github, so this repo never saw the org policy.
AGENTS.md gives agents the toolchain and test commands and links the
org standards instead of restating them. CLAUDE.md points at it.

Refs blacklanternsecurity/bbot-enterprise#157
@singlerider
singlerider requested a review from en0f October 3, 2026 13:59
@singlerider singlerider self-assigned this Oct 3, 2026
`uv sync --group dev` errors here because pyproject.toml sets
[tool.uv] managed = false, and maturin then finds no virtualenv. The
build also needs the weak-cipher OpenSSL from scripts/build-openssl.sh
that .cargo/config.toml points at. Document the venv, pip, and maturin
flow CI uses. Toolchain rows reference the manifests instead of
retyping the edition and Python range.

@en0f en0f left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved, but some potential blockers:

Both come from things the PR relies on that don't exist yet in blacklanternsecurity/.github.

Deleting SECURITY.md leaves the repo with no security policy. The org .github repo has nothing to inherit from: its main branch holds only .github/workflows, workflow-templates and README.md. The PR branch has no .github/SECURITY.md or docs/SECURITY.md either. If this merges, blasthttp has no vulnerability disclosure policy at all. Either the org SECURITY.md has to land first, or this PR needs to keep the file.
All 8 standards links in AGENTS.md lead to 404s. There's no standards/ folder in the org .github repo, and no open PR there adds one. The "principles.md: Always" line sends agents to a page that doesn't exist. Same fix: merge the standards first, or hold this PR until they exist.

@liquidsec
liquidsec merged commit d6e72e4 into dev Oct 5, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants