Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 10 additions & 10 deletions .project/threatmodel/mitigations.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -146,7 +146,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.sink.dangerous_attr
file_hint: scripts/create-example-test-repo.py:142
file_hint: scripts/create-example-test-repo.py:142 # removed in 0.2.0, #487
- fingerprint: sha256:39dcf5bd1ab43e91
status: accepted
note: Test fixture, example, or build script — not production code. Commands are
Expand All @@ -155,7 +155,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.sink.dangerous_attr
file_hint: scripts/create-example-test-repo.py:308
file_hint: scripts/create-example-test-repo.py:308 # removed in 0.2.0, #487
- fingerprint: sha256:8da33a516f06a8ce
status: mitigated
note: Opengrep/Semgrep binary invocation with fully static argv. Binary path is
Expand Down Expand Up @@ -470,7 +470,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.sink.dangerous_attr
file_hint: scripts/create-example-test-repo.py:136
file_hint: scripts/create-example-test-repo.py:136 # removed in 0.2.0, #487
- fingerprint: sha256:d8b8307b8c16479f
status: accepted
note: Test fixture, example, or build script — not production code. Commands are
Expand All @@ -479,7 +479,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.sink.dangerous_attr
file_hint: scripts/create-example-test-repo.py:139
file_hint: scripts/create-example-test-repo.py:139 # removed in 0.2.0, #487
- fingerprint: sha256:2603b50ec203f5cc
status: accepted
note: Test fixture, example, or build script — not production code. Commands are
Expand All @@ -488,7 +488,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.sink.dangerous_attr
file_hint: scripts/create-example-test-repo.py:280
file_hint: scripts/create-example-test-repo.py:280 # removed in 0.2.0, #487
- fingerprint: sha256:18143895dff565cf
status: mitigated
note: TOML-config-driven command execution using list-form subprocess. The base
Expand Down Expand Up @@ -837,7 +837,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.info_disc.open_call
file_hint: packages/darnit-example/src/darnit_example/tools.py:89
file_hint: packages/darnit-example/src/darnit_example/tools.py:89 # removed in 0.2.0, #487
- fingerprint: sha256:a29e1edb04ab00ed
status: mitigated
note: 'All file paths originate from trusted sources: TOML configuration, computed
Expand All @@ -847,7 +847,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.info_disc.open_call
file_hint: packages/darnit-example/src/darnit_example/handlers.py:35
file_hint: packages/darnit-example/src/darnit_example/handlers.py:35 # removed in 0.2.0, #487; moved to darnit_testchecks/handlers.py
- fingerprint: sha256:f488c060d5b16b9c
status: mitigated
note: 'All file paths originate from trusted sources: TOML configuration, computed
Expand All @@ -857,7 +857,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.info_disc.open_call
file_hint: packages/darnit-example/src/darnit_example/handlers.py:85
file_hint: packages/darnit-example/src/darnit_example/handlers.py:85 # removed in 0.2.0, #487; moved to darnit_testchecks/handlers.py
- fingerprint: sha256:1efd167695e4ea87
status: accepted
note: Test fixture, example, or build script — not production code. Commands are
Expand All @@ -866,7 +866,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.sink.dangerous_attr
file_hint: scripts/create-example-test-repo.py:297
file_hint: scripts/create-example-test-repo.py:297 # removed in 0.2.0, #487
- fingerprint: sha256:74cd6b4caf19c0bc
status: accepted
note: Test fixture, example, or build script — not production code. Commands are
Expand All @@ -875,7 +875,7 @@ entries:
reviewer: claude-opus-4-6
reviewed_at: '2026-04-14'
query_id: python.sink.dangerous_attr
file_hint: scripts/create-example-test-repo.py:329
file_hint: scripts/create-example-test-repo.py:329 # removed in 0.2.0, #487
- fingerprint: sha256:2ef91acfef1096bd
status: mitigated
note: Git/gh CLI invocation with fixed binary name and list-form arguments. No shell=True,
Expand Down
3 changes: 1 addition & 2 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -120,8 +120,7 @@ baseline-mcp/
│ │ ├── threat_model/ # STRIDE analysis engine
│ │ └── formatters/ # SARIF output generation
│ │
│ ├── darnit-example/ # Example implementation (docs reference)
│ └── darnit-testchecks/ # Test implementation (for testing)
│ └── darnit-testchecks/ # Test-only plugin (not a template; see darnit-hello)
│
├── docs/
│ ├── WORKFLOW.md # Mermaid diagrams (audit, remediation, context, startup)
Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
discovered as before. The in-tree implementations drop them, and
`darnit-example` drops its `_RULES` catalog, `remediation/registry.py`, and
empty `controls` package (#487).
- The `darnit-example` workspace package (never published) and
`scripts/create-example-test-repo.py`. Plugin authors start from
`darnit-hello`; the custom step types the tests used moved to the test-only
`darnit-testchecks` package (#487).

### Added

Expand Down
16 changes: 8 additions & 8 deletions THREAT_MODEL.md
Original file line number Diff line number Diff line change
Expand Up @@ -722,7 +722,7 @@ Darnit is a compliance auditing tool — its core purpose is to read repository
- **Sieve handlers** (builtin_handlers.py): Read repository files to check compliance patterns. Paths come from TOML control definitions (file_exists, pattern handlers).
- **Remediation pipeline** (executor.py, helpers.py, github.py, orchestrator.py): Read templates and write remediation files. Paths from package resources or MCP `local_path` parameter.
- **Threat model generators** (remediation.py, dependencies.py): Read source files for structural analysis. Paths from directory traversal within `local_path`.
- **Example/test code** (darnit_example, test_repository.py): Not production — example and test fixtures.
- **Example/test code** (test_repository.py; darnit_example removed in 0.2.0, #487): Not production — example and test fixtures.
- **Cache and verification** (audit_cache.py, verification.py): Read/write cache files in known locations.

The `local_path` MCP parameter is the primary trust boundary — the user (MCP client) chooses which repository to audit. Reading files within that path is the intended behavior. Path traversal beyond `local_path` would be a valid concern but is not structurally present in these code paths.
Expand All @@ -733,13 +733,13 @@ The `local_path` MCP parameter is the primary trust boundary — the user (MCP c

| # | Title | Location | Score |
|---|-------|----------|-------|
| TM-D-001 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:136` | 1.80 |
| TM-D-002 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:139` | 1.80 |
| TM-D-003 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:142` | 1.80 |
| TM-D-004 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:280` | 1.80 |
| TM-D-005 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:297` | 1.80 |
| TM-D-006 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:308` | 1.80 |
| TM-D-007 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:329` | 1.80 |
| TM-D-001 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:136` (removed in 0.2.0, #487) | 1.80 |
| TM-D-002 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:139` (removed in 0.2.0, #487) | 1.80 |
| TM-D-003 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:142` (removed in 0.2.0, #487) | 1.80 |
| TM-D-004 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:280` (removed in 0.2.0, #487) | 1.80 |
| TM-D-005 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:297` (removed in 0.2.0, #487) | 1.80 |
| TM-D-006 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:308` (removed in 0.2.0, #487) | 1.80 |
| TM-D-007 | No timeout on subprocess.run() | `scripts/create-example-test-repo.py:329` (removed in 0.2.0, #487) | 1.80 |
| TM-D-008 | No timeout on subprocess.run() | `packages/darnit-baseline/src/darnit_baseline/attestation/git.py:24` | 1.80 |
| TM-D-009 | No timeout on subprocess.run() | `packages/darnit-baseline/src/darnit_baseline/attestation/git.py:48` | 1.80 |
| TM-D-010 | No timeout on subprocess.run() | `packages/darnit-baseline/src/darnit_baseline/attestation/git.py:60` | 1.80 |
Expand Down
13 changes: 7 additions & 6 deletions docs/HANDLER_AUTHORING.md
Original file line number Diff line number Diff line change
Expand Up @@ -213,8 +213,7 @@ def readme_description_handler(
...
```

The real example package in `packages/darnit-example/` already contains a good
reference implementation:
A complete version of that handler:

```python
import os
Expand Down Expand Up @@ -356,7 +355,7 @@ That catches bugs faster and avoids depending on unrelated controls:
from pathlib import Path

from darnit.sieve.handler_registry import HandlerContext, HandlerResultStatus
from darnit_example.handlers import readme_description_handler
from your_package.handlers import readme_description_handler


def test_readme_description_handler(tmp_path: Path) -> None:
Expand Down Expand Up @@ -423,9 +422,11 @@ These files are the best companions while authoring handlers:

- `docs/IMPLEMENTATION_GUIDE.md`
- `CLAUDE.md` sections `Sieve Pattern` and `TOML Schema Features`
- `packages/darnit-example/example-hygiene.toml`
- `packages/darnit-example/src/darnit_example/handlers.py`
- `packages/darnit-example/src/darnit_example/implementation.py`
- `packages/darnit-hello/` -- the minimal plugin template
- `packages/darnit-reproducibility/src/darnit_reproducibility/handlers.py` and
`implementation.py` -- a real plugin's custom step types and their
registration in `register_handlers()`
- `packages/darnit-gittuf/src/darnit_gittuf/handlers.py` and `implementation.py`
- `packages/darnit/src/darnit/sieve/builtin_handlers.py`
- `packages/darnit/src/darnit/sieve/handler_registry.py`

Expand Down
20 changes: 10 additions & 10 deletions docs/IMPLEMENTATION_GUIDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,10 +22,10 @@ against a fictional "My Compliance Standard". Along the way, we'll reference how
- Familiarity with Python packaging (pyproject.toml, entry points)
- A local clone of the darnit repository for reference

> **Working example**: The `packages/darnit-example/` package is a complete,
> installable implementation that follows every step in this guide. You can
> study it alongside these instructions — see `packages/darnit-example/README.md`
> for a mapping between guide sections and example files.
> **Starting point**: `packages/darnit-hello/` is the minimal plugin template:
> one control, the entry points, and a framework TOML inside the package. Copy
> it and grow it with this guide. For real plugins with custom step types, see
> `packages/darnit-reproducibility/` and `packages/darnit-gittuf/`.

## Architecture Overview

Expand Down Expand Up @@ -1339,8 +1339,9 @@ steps = [
]
```

> **Reference**: See `packages/darnit-example/src/darnit_example/handlers.py` for
> real custom handler examples (readme analysis, CI config detection).
> **Reference**: See `packages/darnit-reproducibility/src/darnit_reproducibility/handlers.py`
> and `packages/darnit-gittuf/src/darnit_gittuf/handlers.py` for real custom
> handlers, registered in each package's `implementation.py`.

---

Expand Down Expand Up @@ -1767,10 +1768,9 @@ from darnit.core.handlers import get_handler_registry
| MCP tool handler registry | `packages/darnit/src/darnit/core/handlers.py` |
| Reference implementation | `packages/darnit-baseline/src/darnit_baseline/implementation.py` |
| Reference TOML | `packages/darnit-baseline/src/darnit_baseline/openssf-baseline.toml` |
| Example implementation | `packages/darnit-example/src/darnit_example/implementation.py` |
| Example TOML config | `packages/darnit-example/example-hygiene.toml` |
| Example custom handlers | `packages/darnit-example/src/darnit_example/handlers.py` |
| Example tests | `tests/darnit_example/` |
| Plugin template | `packages/darnit-hello/` |
| Plugin with custom step types | `packages/darnit-reproducibility/src/darnit_reproducibility/implementation.py` |
| Custom step type tests | `tests/darnit_reproducibility/test_handlers.py` |
| Framework spec | `docs/architecture/framework-design.md` |
| Composition resolver | `packages/darnit/src/darnit/core/composition.py` |
| Composition spec | `specs/013-plugin-composition/spec.md` |
Expand Down
1 change: 0 additions & 1 deletion docs/architecture/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@ These are static reference docs, not in-flight feature specs (those live under `
- [Sieve handler authoring](./sieve-handler-authoring.md) -- contract for writing new sieve handlers
- [Shared handlers](./shared-handlers.md) -- built-in handlers usable across implementations
- [Implementation-provided tools](./implementation-provided-tools.md) -- MCP tool exposure model
- [Example plugin](./example-plugin.md) -- canonical worked example

## Audit lifecycle

Expand Down
111 changes: 0 additions & 111 deletions docs/architecture/example-plugin.md

This file was deleted.

Loading
Loading