From 69a8eea4d3595534efaaaa05c2993168d198fac9 Mon Sep 17 00:00:00 2001 From: fig-ai-agent Date: Sat, 12 Sep 2026 15:04:20 +0000 Subject: [PATCH] docs: correct CI/supply-chain docs to match the tree MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit README.md: replace the pasted boilerplate block (which claimed CI was green) with a verified CI/CD & supply-chain integrity section — full-SHA pinning policy, current measured state on main, and reference SHAs for the actions ci.yml uses. SECURITY.md: rewrite the chat-style document as a real policy (supported versions, private-advisory reporting, SLA by severity, scope, coordinated disclosure, severity table). The supply-chain section now states plainly that pinning is policy but not yet enforced — there is no verify-sha job and no .github/workflows/scripts/verify-shas.py, contrary to the previous text. CHANGELOG.md: record both corrections. SHAs resolved from the actions' own repos on 2026-09-12. --- CHANGELOG.md | 17 +++ README.md | 188 +++++++------------------------- SECURITY.md | 300 +++++++++++++++++++++++---------------------------- 3 files changed, 191 insertions(+), 314 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d81e9f8b..02a6d986 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -36,6 +36,23 @@ Open problems and known blockers are tracked separately in gate in the suite README and `manifest.json`. ### Fixed +- **Docs** — corrected the CI/supply-chain documentation so it matches the tree. + (1) `README.md` still carried a copy-pasted boilerplate block that ended in a + "CI/CD: ผ่าน / Security: ตรวจสอบแล้ว" status line and a "ต้องการให้ผมช่วย:" + list — it claimed CI was green, which is false, and pasted a `SECURITY.md` + draft inline. The block is replaced with a verified + **CI/CD & supply-chain integrity** section: policy (full-SHA pinning), the + current state measured against `main`, and the reference SHAs for the actions + `ci.yml` uses. (2) `SECURITY.md` was a chat-style answer wrapped in prose and + code fences, and it had picked up a "Supply Chain" section describing a + `verify-sha` job in `ci.yml` and a pin-history row of "76 refs / all 12 + workflow files / repaired 5 fabricated pins" — none of which is true: there is + no `verify-sha` job and no `.github/workflows/scripts/verify-shas.py`. It is + rewritten as a normal policy document (supported versions, private-advisory + reporting, SLA by severity, scope, coordinated disclosure, severity table) with + a supply-chain section that states plainly that pinning is policy but **not yet + enforced**, backed by the same measured counts. All SHAs quoted in both files + were resolved from the actions' own repositories on 2026-09-12. - **PR #216** — two defects found by auditing the merged MCP guide against the actual tree. (1) `scripts/check-mcp-environment.sh --help` leaked source: the handler used a fixed line range, `sed -n '2,22p'`, but the comment header ends diff --git a/README.md b/README.md index dfe474d1..4a0dd06d 100644 --- a/README.md +++ b/README.md @@ -64,157 +64,43 @@ uvicorn main:app --reload - `docs/` — API, GraphQL, and reference guides. - `deliverables/` — each suite ships its own README, SKILL.md, and tests. -## License +## CI/CD & supply-chain integrity + +The repository's supply-chain policy is **full-SHA pinning**: every `uses:` reference +must point at a 40-character commit SHA, never a mutable tag such as `@v4`. The org's +policy gate refuses a workflow that references an action by tag. + +**Current state (2026-09-12) — verified against `main`:** + +- A minority of references are already SHA-pinned; the majority are still tags + (`actions/checkout@v4`, `actions/setup-python@v5`, `actions/upload-artifact@v4`, + `github/codeql-action/*@v3`, `docker/*` and others). +- Six workflow files are not valid YAML as committed, so they never run: + `ci.yml`, `secret-scan.yml`, `Auto-Index-Sync.yml`, `dependabot-automerge.yml`, + `test-suite.yml`, and `github-actions-autodebug-autorerun` (which also has no + `.yml`/`.yaml` extension). +- Because jobs cannot start, a feature PR shows red checks even when its own + tests pass locally. See the 2026-09-08 notes in [`CHANGELOG.md`](./CHANGELOG.md) + and [`PROBLEMS.md`](./PROBLEMS.md). + +**Reference SHAs** (tags resolved to commits, 2026-09-12) for the actions used by +`ci.yml`: + +```yaml +uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 +uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4 +uses: github/codeql-action/init@faaca9a8f6edddba5725ffe5adefdab6669a2eca # v3 +uses: github/codeql-action/analyze@faaca9a8f6edddba5725ffe5adefdab6669a2eca # v3 +uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 +uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5 +``` -See [LICENSE](./LICENSE). -🚀 ZyntroAI/fastapi-python-boilerplate - -เทมเพลต FastAPI พร้อมใช้งานจริง — โครงสร้างมาตรฐาน, ความปลอดภัยสูง, รองรับ Async เต็มรูปแบบ - -  - -📋 ภาพรวมรีโป - -เป็นแม่แบบเริ่มต้นสำหรับสร้าง API ที่ทันสมัย, มีโครงสร้างชัดเจน, มาพร้อมเครื่องมือพัฒนา & CI/CD ครบครัน ✅ - -- สถาปัตยกรรม: Clean Architecture / Modular -- Python: 3.12+ | FastAPI: ล่าสุด -- ฐานข้อมูล: Async SQLAlchemy 2.0 + PostgreSQL + Alembic -- ความปลอดภัย: OAuth2/JWT, CORS, Rate Limit, Validation -- CI/CD: GitHub Actions, Linting, Testing, Build, Security Scan - -  - -✨ คุณสมบัติหลัก - -🏗️ โครงสร้าง & สแต็ก - -- FastAPI: ประสิทธิภาพสูง, อัตโนมัติ OpenAPI/Docs -- Pydantic v2: ตรวจสอบข้อมูลที่รวดเร็ว, จัดการการตั้งค่า -- Async Ready: ฐานข้อมูล/คำขอทั้งหมดแบบ Async -- SQLAlchemy 2.0: ORM ทรงพลัง + asyncpg -- Alembic: การย้ายข้อมูล (Migration) อัตโนมัติ - -🔐 ความปลอดภัย & การตรวจสอบสิทธิ์ - -- OAuth2 + JWT: ระบบล็อกอินที่ปลอดภัย -- Role-Based Access: จัดการสิทธิ์ผู้ใช้ -- CORS Middleware: ตั้งค่าล่วงหน้า -- การตรวจสอบข้อมูล: Input validation ที่เข้มงวด -- รองรับ Supabase Auth: พร้อมผสานรวม - -🧪 เครื่องมือพัฒนา & คุณภาพโค้ด - -- Linting: Ruff + Black + isort -- ทดสอบ: pytest + async support + coverage -- คอนเทนเนอร์: Docker + Docker Compose พร้อมใช้ -- การตั้งค่า: .env, ตัวแปรสภาพแวดล้อม, ความลับ -- เอกสาร: Swagger/Redoc อัตโนมัติ + README ครบถ้วน - -🛠️ CI/CD & การปรับใช้ - -- GitHub Actions: Workflow สำหรับทดสอบ/บิลด์/ความปลอดภัย -- Codecov: ตรวจสอบความครอบคลุมโค้ด -- Security: CodeQL, Dependabot, SHA-pinning -- Ready for Cloud: Docker image, Kubernetes-ready - -  - -📂 โครงสร้างโฟลเดอร์ - -plaintext - -fastapi-python-boilerplate/ -├── .github/workflows/ # CI/CD YAML -├── app/ -│ ├── api/ # เส้นทาง API (v1) -│ ├── core/ # การตั้งค่า, ความปลอดภัย, ค่าคงที่ -│ ├── models/ # โมเดล Pydantic + SQLAlchemy -│ ├── schemas/ # รูปแบบข้อมูล/การตอบกลับ -│ ├── services/ # ตรรกะธุรกิจ -│ └── main.py # จุดเริ่มต้นแอป -├── tests/ # ชุดทดสอบ -├── alembic/ # การย้ายข้อมูล -├── Dockerfile -├── docker-compose.yml -├── requirements.txt / pyproject.toml -└── .env.example -  - -  - -🚀 เริ่มต้นใช้งาน - -bash - -# 1. โคลนรีโป -git clone https://github.com/ZyntroAI/fastapi-python-boilerplate.git -cd fastapi-python-boilerplate - -# 2. ติดตั้งข้อกำหนด -pip install -r requirements.txt +Fixing this requires write access to `.github/workflows/`, which the automation App +does not hold — it must be applied by a maintainer or with elevated App permissions. +See [`SECURITY.md`](./SECURITY.md) for the policy and how to report a supply-chain +issue. -# 3. ตั้งค่า .env -cp .env.example .env -# แก้ไขค่า เช่น DATABASE_URL, SECRET_KEY - -# 4. รันฐานข้อมูล + เริ่มเซิร์ฟเวอร์ -docker compose up -d -alembic upgrade head -uvicorn app.main:app --reload -  - -🌐 เข้าใช้งาน:  http://localhost:8000/docs  (เอกสาร Swagger) - -  - -🛡️ สถานะรีโป - -- License: MIT -- CI/CD: ✅ ผ่าน -- ความปลอดภัย: ✅ ตรวจสอบแล้ว -- รองรับ: Python 3.12+ - -  - -ต้องการให้ผมช่วย: - -- 📄 สรุปไฟล์  README.md  ฉบับเต็ม/ปรับแต่ง -- ⚙️ อธิบายการตั้งค่า  .env  / CI Workflow -- 🧩 เปรียบเทียบกับต้นฉบับ tiangolo/fastapi-boilerplate -- 📝 สร้างเทมเพลตเริ่มต้นโปรเจกต์ใหม่? 🧑‍💻🚀 -# 🚀 ZyntroAI FastAPI Boilerplate -**มาตรฐานองค์กร • ปลอดภัย • พร้อมใช้งาน • SHA-pinned** - -## 🧩 คุณสมบัติหลัก (อัปเดต) -- ✅ **CI/CD ปลอดภัย:** GitHub Actions ทั้งหมดใช้ **SHA-pinning เต็ม 40 ตัว** -- ✅ **สิทธิ์น้อยที่สุด:** แยก `permissions` ตามงานในแต่ละ Job -- ✅ **Workflow โปร่งใส:** รองรับ `workflow_dispatch` + ไอคอนชื่อ Job ชัดเจน -- ✅ ลินต์: `ruff` + `black` + `isort` -- ✅ ทดสอบ: `pytest` + ความครอบคลุม + Postgres บริการ -- ✅ ความปลอดภัย: CodeQL + การอัปเกรด `pip` อัตโนมัติ -- ✅ บิลด์: ด็อกเกอร์ไปยัง GHCR (เฉพาะสาขา `main`) - -## 🛠️ โครงสร้างไฟล์ CI - - -## ⚙️ นโยบายความปลอดภัย (สำคัญ) -- **🔒 SHA-pinning:** ห้ามใช้แท็ก `@vX` — ทุก `uses:` ต้องเป็นคอมมิต SHA เต็ม - ```yaml - uses: actions/checkout@11bd71903a754fa4acce1b6cd295a12fc38ffd4 - ---- - -## 📄 `SECURITY.md` — เพิ่มนโยบาย SHA-Pinning -```markdown -# 🛡️ นโยบายความปลอดภัย — CI/CD -**อัปเดต:** 12 กันยายน 2026 - -## ✅ การปัก SHA (Supply Chain) -- **บังคับ:** ทุก GitHub Actions ต้องใช้ **full commit SHA** (40 ตัว) -- ❌ ห้าม: `@v4`, `@main`, `@latest` -- ✅ ตัวอย่างที่ถูกต้อง: - ```yaml - uses: actions/checkout@11bd71903a754fa4acce1b6cd295a12fc38ffd4 - uses: actions/setup-python@8d9ed9ac65efc6b600b45b871c877404878e487 +## License +See [LICENSE](./LICENSE). diff --git a/SECURITY.md b/SECURITY.md index f5a40546..984d592b 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,175 +1,149 @@ -# 🔒 Security Policy — Final Production-Ready Version +# Security Policy -Here's the **complete, polished `SECURITY.md`** — ready to copy directly into your repository: +This is the security policy for the ZyntroAI repositories. It covers how to report +a vulnerability, what is in scope, and the supply-chain rules the CI enforces. + +## Supported versions ---- - -```markdown -# 🔒 Security Policy - -## 📌 Supported Versions - -This project aligns with **FastAPI + Python LTS support windows**. Only actively maintained releases receive security patches. - -| Branch / Version | Python Required | FastAPI Base | Supported | Security Updates | -|---|---|---|---|---| -| `main` → **v1.x (latest)** | 3.10 – 3.13 | ≥ 0.110.x | ✅ Active | ✅ Critical + High | -| `v0.104.x` LTS | 3.9 – 3.12 | 0.104.x | ✅ Maintenance | ✅ Critical only | -| `v0.100.x` | 3.8 – 3.11 | 0.100.x | ⚠️ End-of-Life | ❌ None | -| `<= 0.99.x` | Any | ≤ 0.99.x | ❌ Unsupported | ❌ None | - -> 📢 **Upgrade Policy:** When a version reaches End-of-Life (EOL), no further patches are issued. Upgrade to a supported release immediately. - ---- - -## 📥 Reporting a Vulnerability - -### ✅ Where to Report - -**Please DO NOT create public GitHub Issues for security vulnerabilities** — this exposes risks before a fix is ready. - -**Report privately via:** - -- 🔒 **GitHub Private Advisory:** Go to **Security → Report a Vulnerability** (preferred) -- 📧 **Email:** `security@zyntro.ai` — encrypted (see PGP key below) - -### 📋 What to Include - -To help us triage quickly, please provide: - -- **Description:** Clear summary of the vulnerability type -- **Reproduction Steps:** Minimal steps or proof-of-concept -- **Impact:** What an attacker could achieve -- **CVSS Score:** If known (e.g., `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`) -- **Affected Versions:** First known vulnerable version, latest confirmed affected -- **Suggested Fix:** Patch or mitigation, if available - -### ⏱️ Response SLA - -| Phase | Timeline | Action | -|---|---|---| -| ✅ Acknowledgement | **≤ 48 hours** | Confirm receipt + tracking ID assigned | -| 🔍 Triage | **≤ 5 business days** | Validate, assign severity, confirm scope | -| 🛠️ Fix Development | **≤ 90 days maximum** | Patch prepared, tested, validated | -| 🔑 Advisory Release | On Patch Day | Fixed release published + advisory disclosed | - -### ✅ Acceptance & Decline Process - -- **✅ Accepted:** We work with you on coordinated release. You receive credit in the advisory. -- **⚠️ Low Risk:** May be grouped with regular release cycle. -- **❌ Declined:** We explain why — e.g., out of scope, already patched, requires non-recommended configuration. - ---- - -## 🎯 Scope — In Scope vs Out of Scope - -### ✅ In Scope - -- Authentication / authorization bypasses -- Injection (SQL, NoSQL, Command, XSS) -- Secrets exposure in code or config -- Dependency supply chain vulnerabilities -- Insecure defaults or configuration flaws -- Broken access control / IDOR -- Server-Side Request Forgery (SSRF) -- Missing or weak data encryption - -### ❌ Out of Scope - -- Versions marked ❌ Unsupported -- Denial-of-service / brute-force (rate-limited endpoints) -- Social engineering, phishing, physical access -- Issues in upstream dependencies (report to upstream) -- Already publicly disclosed vulnerabilities -- Requires user compromise or non-standard deployment - ---- - -## 🛡️ Disclosure Policy & Safe Harbor - -We practice **Coordinated Vulnerability Disclosure**. - -- **Safe Harbor:** If you report in accordance with this policy, we will not pursue legal action — provided you: - - Allow **at least 90 days** before public disclosure - - Do not share details with third parties during the fix window - - Do not access or modify other users' data - -- **Disclosure Timeline:** - 1. Report received → ✅ Acknowledge within 48 hours - 2. Triage complete → 🕐 Share estimated fix date - 3. Patch ready → 🔒 Advisory drafted privately - 4. Release → 📢 Fix + advisory published simultaneously - ---- - -## 🔐 Encrypted Reporting (Optional) +The project follows the FastAPI + Python support windows. Only actively maintained +lines receive security patches. +| Branch / Version | Python | FastAPI base | Supported | Security updates | +| ---------------------- | ----------- | ------------ | --------------- | ----------------- | +| `main` -> v1.x (latest)| 3.10 - 3.13 | >= 0.110.x | Active | Critical + High | +| `v0.104.x` LTS | 3.9 - 3.12 | 0.104.x | Maintenance | Critical only | +| `v0.100.x` | 3.8 - 3.11 | 0.100.x | End-of-Life | None | +| `<= 0.99.x` | any | <= 0.99.x | Unsupported | None | + +When a version reaches end-of-life, no further patches are issued. Upgrade to a +supported line. + +## Reporting a vulnerability + +**Do not open a public GitHub Issue for a security problem** — that exposes the +issue before a fix is ready. + +Report privately via either channel: + +- **GitHub private advisory** (preferred) — `Security` -> `Report a vulnerability` + in the repository. +- **Email** — `security@zyntro.ai`. + +Please include: a clear description of the vulnerability type, minimal +reproduction steps or a proof-of-concept, the impact an attacker could achieve, +a CVSS score if known, the affected versions (first vulnerable and latest +confirmed), and a suggested fix or mitigation if you have one. + +### Response SLA + +| Phase | Timeline | Action | +| ------------------ | -------------------- | ------------------------------------------------- | +| Acknowledgement | <= 48 hours | Confirm receipt, assign a tracking ID | +| Triage | <= 5 business days | Validate, assign severity, confirm scope | +| Fix development | <= 90 days maximum | Patch prepared, tested, validated | +| Advisory release | on patch day | Fixed release and advisory published together | + +We work with you on a coordinated release and credit valid reports in the +advisory. Low-risk reports may be grouped into the regular release cycle. If we +decline a report we explain why — out of scope, already patched, or requiring a +non-recommended configuration. + +## Scope + +**In scope:** authentication and authorization bypasses; injection (SQL, NoSQL, +command, XSS); secrets committed to code or config; dependency supply-chain +issues; insecure defaults; broken access control / IDOR; SSRF; missing or weak +encryption of data at rest. + +**Out of scope:** versions marked unsupported above; denial-of-service and +brute-force against rate-limited endpoints; social engineering, phishing, or +physical access; vulnerabilities in upstream dependencies (report those +upstream); already publicly disclosed issues; anything requiring the user's own +machine to be compromised or a non-standard deployment. + +## Disclosure policy and safe harbor + +We practice coordinated vulnerability disclosure. If you report in line with this +policy we will not pursue legal action, provided you allow at least 90 days +before public disclosure, do not share details with third parties during the fix +window, and do not access or modify other users' data. + +Disclosure timeline: report received -> acknowledged within 48 hours; triage +complete -> estimated fix date shared; patch ready -> advisory drafted privately; +release -> fix and advisory published together. + +## Severity handling + +| Severity | CVSS | Response deadline | Example impact | +| -------- | --------- | ----------------- | ----------------------------------------- | +| Critical | 9.0-10.0 | 7 days | Remote code execution, full compromise | +| High | 7.0-8.9 | 14 days | Privilege escalation, data breach | +| Medium | 4.0-6.9 | 30 days | Partial data exposure | +| Low | 0.1-3.9 | next release | Informational / hardening | + +## Supply chain: GitHub Actions SHA pinning + +Every GitHub Action referenced in `.github/workflows/` must be pinned to a **full +40-character commit SHA**. Version tags (`@v4`) and branch refs (`@main`, +`@master`) are rejected: a tag is mutable, so it can be moved to point at +different code with no change to this repository. + +**Current state (verified against `main`, 2026-09-12):** + +- SHA-pinning is **policy, not yet enforced by CI**. `ci.yml` has no + `verify-sha` job and there is no `.github/workflows/scripts/verify-shas.py`; + an earlier revision of this document described both as if they existed. A + handful of references are already pinned; the majority are still tags + (`actions/checkout@v4` x18, `actions/upload-artifact@v4` x11, + `actions/setup-python@v5` x8, `github/codeql-action/*@v3`, `subosito/flutter-action@v2`, + `somaz94/compress-decompress@v1`, `docker/*` and others). +- Six workflow files are not valid YAML as committed and therefore never run: + `ci.yml`, `secret-scan.yml`, `Auto-Index-Sync.yml`, `dependabot-automerge.yml`, + `test-suite.yml`, and `github-actions-autodebug-autorerun` (which also lacks a + `.yml`/`.yaml` extension). +- Because jobs cannot start, a pull request shows red checks even when its own + tests pass locally. + +**Tooling.** `pin_workflows.py` resolves every tag or branch reference to a full +commit SHA via the GitHub API, verifies the commit exists upstream (never from a +fork), and rewrites only the affected lines: + +```bash +python3 pin_workflows.py --dry-run # preview +python3 pin_workflows.py # rewrite the workflow files ``` ------BEGIN PGP PUBLIC KEY BLOCK----- - ------END PGP PUBLIC KEY BLOCK----- -``` - -Fingerprint: `XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX` ---- - -## 📧 Contact & Updates - -- **Security Contact:** `security@zyntro.ai` -- **Advisory Feed:** Subscribe to **Security → Advisories** on GitHub -- **Updates:** Watch releases or enable Dependabot alerts - ---- - -## ✅ Quick Checklist - -- [ ] Report privately — **NOT** public issues -- [ ] Include reproduction steps + impact description -- [ ] Allow ≥ 90 days for patch preparation -- [ ] Stay within scope -- [ ] We credit all valid reports +The rewrite touches `.github/workflows/`, which the automation App is not +permitted to write — it must be applied by a maintainer, or after the App is +granted the `workflows` permission. + +**Reference SHAs** (tags resolved to commits, 2026-09-12) for the actions +`ci.yml` uses: + +```yaml +uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 +uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4 +uses: github/codeql-action/init@faaca9a8f6edddba5725ffe5adefdab6669a2eca # v3 +uses: github/codeql-action/analyze@faaca9a8f6edddba5725ffe5adefdab6669a2eca # v3 +uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 +uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5 ``` ---- - -## 📊 Key Improvements Summary - -| Feature | Original | ✅ Enhanced Version | -|---|---|---| -| Version matrix | Generic | Aligned to FastAPI/Python LTS | -| Reporting channel | ❌ Missing | GitHub Private Advisory + Email | -| Response SLA | ❌ None | 48h ack → 5d triage → 90d fix | -| Scope boundaries | ❌ None | Clear in/out scope list | -| CVSS guidance | ❌ None | Encouraged for severity | -| Disclosure policy | ❌ None | 90-day coordinated disclosure | -| Safe harbor | ❌ None | Legal protection for researchers | -| Credit policy | ❌ None | Acknowledgement in advisory | -| EOL guidance | ❌ None | Clear upgrade path | - ---- - -## 🚀 Implementation Checklist - -- [ ] Save as `SECURITY.md` in repository root -- [ ] Replace `` with your actual public key -- [ ] Update contact email if needed -- [ ] Enable **GitHub Private Vulnerability Reporting**: - → Repository → Settings → Security → "Private vulnerability reporting" ✅ - ---- +### Pin history -## 📋 Bonus: CVSS Severity Rating Guide (Internal Reference) +| Date | Actions pinned | Scope | Notes | +| ---------- | -------------- | ----------------- | ---------------------------------------------------------------- | +| 2026-09-12 | policy drafted | all workflow files| Policy documented; enforcement (CI gate + rewrite) still pending. | -| Severity | CVSS Score | Response Deadline | Example Impact | -|---|---|---|---| -| 🔴 Critical | 9.0–10.0 | 7 days | Remote code execution — full system compromise | -| 🟠 High | 7.0–8.9 | 14 days | Privilege escalation — data breach | -| 🟡 Medium | 4.0–6.9 | 30 days | Partial data exposure | -| 🟢 Low | 0.1–3.9 | Next release | Informational / hardening recommendation | +When a maintainer runs `pin_workflows.py` and merges the result, add a row here. ---- +## Repository security practices -✅ **Done!** This SECURITY.md is production-ready, aligned with FastAPI/Python support cycles, and compliant with GitHub Security Advisory standards. 🛡️🔒 +- Secrets live in environment variables and CI secrets only — never in source. + `.env` is untracked; a safe `.env.example` documents the required keys. +- Dependencies are kept current and advisories triaged promptly (Dependabot). +- CodeQL runs as part of the security job once the workflow files are valid. +- External-service failures fail open (graceful degradation). -Would you like me to also create a **`SECURITY-ADVISORY-TEMPLATE.md`** file so researchers can submit standardized reports? 📋🔐 +[advisories]: https://github.com/ZyntroAI/fastapi-python-boilerplate/security/advisories