From 2c0a2cc015a7517559c44829fc3489ac44ed2221 Mon Sep 17 00:00:00 2001 From: Lukas Geiger Date: Sat, 3 Oct 2026 23:43:43 +0200 Subject: [PATCH] docs: scope security and data claims by repository --- SECURITY.md | 8 +++++--- llms.txt | 7 ++++--- profile/README.md | 12 ++++++------ profile/README_de.md | 14 +++++++------- tests/test_profile_parity.py | 15 ++++++++++----- 5 files changed, 32 insertions(+), 24 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 94c9d4a..90cf010 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -12,6 +12,8 @@ If you discover a security vulnerability or security concern within any reposito - `lukas@open-bricks.org` - `support@lukasgeiger.com` +Project-specific SECURITY policies govern the repositories they cover. For a report about a product repository, consult that repository's current policy for its response commitments. + --- ## Response Timeline / Reaktionszeit @@ -34,6 +36,6 @@ If you discover a security vulnerability or security concern within any reposito ## Security Invariants / Sicherheitsinvarianten -- **Zero-Egress & Local-First:** All desktop utilities, document tools, MCP servers, and data storage workflows are engineered to run 100% locally with zero unconsented telemetry, analytics, or cloud data egress. -- **Unprivileged User Mode (Non-Elevation):** Tools operate within standard user privileges and do not require elevated administrator or root privileges for normal desktop operation. -- **Integrity & Source Preservation:** Local transformations, file actions, and data indexers preserve original input data by default and operate non-destructively. +- **Network, telemetry, and data behavior:** These properties vary by repository and are described in its current documentation and SECURITY policy; no blanket zero-egress guarantee applies to every linked project. +- **Privilege requirements:** Requirements depend on the repository and workflow. The Zombie-Killer-Tray tray launcher can request UAC elevation for termination workflows; see its project documentation. +- **Data integrity and source preservation:** These properties are repository-specific; consult the affected project's documentation rather than treating them as ecosystem-wide guarantees. diff --git a/llms.txt b/llms.txt index 5c448c1..afd0d28 100644 --- a/llms.txt +++ b/llms.txt @@ -12,14 +12,15 @@ Index status as of 2026-09-28: - The linked ecosystem has 128 active public product or research repositories plus 10 active public `.github` profile repositories (138 active public repositories total). - Private/internal repositories are intentionally excluded from this public index. - Archived public repositories are excluded from active counts unless they are explicitly named as archived context. +Targeted update: the Zombie-Killer-Tray entry below was checked against project main on 2026-10-03; the rest of this public index remains dated 2026-09-28. ## Audience -Developers, researchers, and desktop users looking for local-first, privacy-conscious open-source tools that work without cloud accounts — with optional AI integration through Ollama, MCP servers, and Claude/Gemini-compatible workflows. +Developers, researchers, and desktop users looking for open-source tools for local-first and cloud-connected workflows; check each repository's documentation for data, network, account, and AI requirements. Core positioning: - Local-first desktop software. -- No telemetry and no subscription layer by default. +- Storage, telemetry, and network behavior are documented per repository; no blanket zero-egress promise applies to the ecosystem. - Optional AI integration through Ollama, Claude/Gemini-compatible workflows, and MCP servers. - Python, PySide6, SQLite, CLI/API surfaces, web companions, and reproducible documentation. @@ -71,7 +72,7 @@ Representative repositories: - dev-bricks/WikiStub-Seed: documentation and wiki seed generator. - dev-bricks/safe-start-for-codex: Windows startup gate for Codex Desktop automations. - dev-bricks/app-rotator: quick window rotator and workspace task switcher. -- dev-bricks/zombie-killer-tray: safe Windows tray for conservative cleanup of orphaned MCP and language-server processes. +- dev-bricks/zombie-killer-tray: Windows tray utility for conservative cleanup of orphaned MCP and language-server processes (project main checked 2026-10-03). - ellmos-ai/bach: text-based operating system for LLMs. - ellmos-ai/agent-ops-stack: manifest-driven local agent-ops composition for ticket routing, locks, decision-avatar, skills, and MCP control. - ellmos-ai/clip-storyboard-director: local-first AI storyboard director and scene continuity orchestrator bridging video generation, CDP, and multitrack audio. diff --git a/profile/README.md b/profile/README.md index bd30264..eb90663 100644 --- a/profile/README.md +++ b/profile/README.md @@ -6,16 +6,15 @@

Local-first desktop software for files, documents, developer workflows, research, and AI-assisted work.
- Open source tools with no telemetry, no subscription layer, and optional local AI integration. + Many projects are designed for local-first use; data and network behavior is documented per repository, with optional local AI integration in some projects.

Ecosystem open-bricks Public Repositories - License MIT Local First AI Integration - Security SLA + Security Policy

@@ -40,9 +39,10 @@ > **Machine-Readable Context**: For AI agents, LLM crawlers, and automated tools, a structured ecosystem directory is available at [`llms.txt`](https://github.com/open-bricks/.github/blob/main/llms.txt). > [!IMPORTANT] -> **Local-First & Privacy First**: All tools in the open-bricks family store data locally on your machine without cloud subscription requirements, telemetry tracking, or forced remote dependencies. +> **Local-first use:** Storage, telemetry, network access, and external-service behavior are documented per repository. See each project's documentation and SECURITY policy for current details. **Public index verified: 2026-09-28.** The linked ecosystem currently exposes 128 active public product or research repositories plus 10 active public `.github` profile repositories (138 active public repositories in total). The `open-bricks` organization itself hosts the [`.github`](https://github.com/open-bricks/.github) profile and umbrella community-health repository; product code lives in the linked organizations below. +**Targeted update:** Zombie-Killer-Tray reflects a targeted main-branch readback on 2026-10-03; the wider index counts and remaining entries retain the 2026-09-28 snapshot. ## Start Here @@ -88,9 +88,9 @@ flowchart TD ## What This Ecosystem Is -open-bricks is the umbrella profile for a family of small, practical, local-first tools. The shared product idea is simple: +open-bricks is the umbrella profile for a family of small, practical tools. Shared design goals include: -- Your data stays on your machine. +- Prefer local data storage; storage and network behavior are documented per repository. - Desktop apps should still be useful without cloud accounts. - AI should be an optional capability, not a forced dependency. - Repositories should be inspectable by humans, GitHub search, and LLM agents. diff --git a/profile/README_de.md b/profile/README_de.md index ce04c11..2d471ee 100644 --- a/profile/README_de.md +++ b/profile/README_de.md @@ -6,16 +6,15 @@

Local-First Desktop-Software für Dateien, Dokumente, Entwickler-Workflows, Forschung und KI-gestützte Arbeit.
- Open-Source-Werkzeuge ohne Telemetrie, ohne Abomodell und mit optionaler lokaler KI-Integration. + Open-Source-Werkzeuge mit projektspezifisch dokumentiertem Daten- und Netzwerkverhalten und optionaler lokaler KI-Integration.

Ecosystem open-bricks - Öffentliche Repositories - Lizenz MIT + Öffentliche Repositories Local First KI Integration - Sicherheits-SLA + Sicherheitsrichtlinie

@@ -40,9 +39,10 @@ > **Maschinenlesbarer Kontext**: Für KI-Agenten, LLM-Crawler und automatisierte Tools steht unter [`llms.txt`](https://github.com/open-bricks/.github/blob/main/llms.txt) eine strukturierte Ökosystem-Übersicht bereit. > [!IMPORTANT] -> **Local-First & Datenschutz**: Alle Werkzeuge der open-bricks Familie speichern Daten lokal auf Ihrem System. Es bestehen keine Cloud-Abos, kein Telemetrie-Tracking und keine erzwungenen Remote-Abhängigkeiten. +> **Local-First & Datenschutz**: Viele Projekte bevorzugen lokale Datenspeicherung; Speicher-, Telemetrie- und Netzwerkverhalten ist in der jeweiligen Repository-Dokumentation beschrieben. **Öffentlicher Index verifiziert: 28.09.2026.** Das verlinkte Ökosystem umfasst aktuell 128 aktive öffentliche Produkt- und Forschungs-Repositories sowie 10 aktive öffentliche `.github` Profil-Repositories (insgesamt 138 aktive öffentliche Repositories). Die Organisation `open-bricks` selbst hostet das Profil- und Community-Health-Repository [`.github`](https://github.com/open-bricks/.github); der Produkt-Quellcode liegt in den verlinkten Teil-Organisationen. +**Gezieltes Update:** Der Branch `main` von Zombie-Killer-Tray wurde am 03.10.2026 gezielt geprüft; Gesamtzahlen und übrige Indexeinträge behalten den Stand vom 28.09.2026. ## Einstieg & Schnellübersicht @@ -88,9 +88,9 @@ flowchart TD ## Philosophie des Ökosystems -open-bricks bildet das gemeinsame Dach für praxisorientierte Local-First-Software. Der Grundsatz lautet: +open-bricks bildet das gemeinsame Dach für praxisorientierte Software. Zu den gemeinsamen Designzielen gehören: -- Ihre Daten verbleiben auf Ihrem Rechner. +- Lokale Datenspeicherung wird bevorzugt; Speicher-, Telemetrie- und Netzwerkverhalten ist im jeweiligen Repository dokumentiert. - Desktop-Anwendungen müssen ohne Cloud-Konto voll funktionsfähig sein. - KI ist eine optionale Ergänzung, keine erzwungene Abhängigkeit. - Repositories sind transparent für Menschen, GitHub-Suche und KI-Agenten lesbar. diff --git a/tests/test_profile_parity.py b/tests/test_profile_parity.py index 81e3055..a607ac4 100644 --- a/tests/test_profile_parity.py +++ b/tests/test_profile_parity.py @@ -1,4 +1,4 @@ -"""Tests for open-bricks profile parity, timestamps, and ecosystem consistency.""" +"""Text and link parity checks for open-bricks profiles, timestamps, and ecosystem consistency.""" import re from pathlib import Path @@ -36,7 +36,7 @@ def test_repository_counts(): # Badges assert "Public_Repositories-138_Active-success" in en_content - assert "Oeffentliche_Repositories-138_Aktiv-success" in de_content + assert "%C3%96ffentliche_Repositories-138_Aktiv-success" in de_content # Summary text assert "138 active public repositories" in en_content @@ -88,13 +88,18 @@ def test_fenced_code_blocks_and_mermaid(): assert "flowchart TD" in content, f"Missing flowchart TD in {path.name}" -def test_security_policy_parity(): +def test_security_policy_text_and_link_parity(): sec_path = REPO_ROOT / "SECURITY.md" assert sec_path.is_file(), "SECURITY.md does not exist" sec_content = sec_path.read_text(encoding="utf-8") - assert "48 hours" in sec_content, "Missing 48 hours SLA in SECURITY.md" + assert "48 hours" in sec_content, "Missing organization response commitment in SECURITY.md" assert "security@open-bricks.org" in sec_content, "Missing primary security contact" - assert "Zero-Egress" in sec_content, "Missing Zero-Egress invariant in SECURITY.md" + assert "These properties vary by repository" in sec_content + assert "Zombie-Killer-Tray tray launcher can request UAC elevation" in sec_content + + profile_content = PROFILE_EN.read_text(encoding="utf-8") + policy_href = "https://github.com/open-bricks/.github/blob/main/SECURITY.md" + assert f'href="{policy_href}"' in profile_content def test_key_ecosystem_repositories_in_llms():