Skip to content

security: public-claims accuracy: SECURITY.md, AUDIT_POSTURE, profile + public-truth gate - #7

Merged
SaulBuilds merged 5 commits into
mainfrom
fix/pba-r2-truth
Sep 25, 2026
Merged

SaulBuilds merged 5 commits into
mainfrom
fix/pba-r2-truth

Conversation

@SaulBuilds

@SaulBuilds SaulBuilds commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Pre-bounty remediation R2, public-claims accuracy. This PR fixes the org security policy and the profile claims, and adds a draft bug bounty.

OWNER: BOUNTY.md is a draft, not in force, and nothing links to it yet. SECURITY.md says "Bounty policy: coming soon" until counsel signs off on the safe harbor.

Still OWNER TO FILL:

  • reward amounts, launch date, payout and eligibility
  • the PGP key
  • the proposed host rate limits (5 req/s and 10,000 req/day per host)
  • counsel review of the safe-harbor text

The "Known issues" section is an empty placeholder, published per finding once fixed. Tracking: CitrateNetwork/citrate-security#87.

Finding Severity Check Tripwire Proof Status
public-claims item disclosure and bounty MEDIUM scripts/ci/public_truth.py CI step in ci.yml 18 errors on origin/main, OK on head. Also FAILS: a list under Known issues; SECURITY.md linking BOUNTY.md while it is not in force PARTIAL (OWNER items above)
public-claims item supply-chain claims MEDIUM same same Probe "Crates are signed with cosign; every release ships a CycloneDX SBOM" → FAIL FIXED
public-claims item paid rails MEDIUM same same Probe "x402-metered pay-per-call ... live today" → FAIL FIXED
public-claims item @v1, ws, specs path LOW same (tags read with git ls-remote, so it works under a shallow checkout) same Probe @v1 → FAIL FIXED
public-claims item HITL LOW same (case-sensitive HITL / H.I.T.L, plus a whitespace-normalised "human in the loop") same Probes "Human-in-\n the-loop" and "H.I.T.L" → FAIL; "Whitlock" → pass FIXED

Rework (independent verifier)

  • Known issues: now an empty placeholder.
  • TEE row: the tier is inert on 40204 because no TEE oracle is registered (teeOracleCount() is 0).
  • ZK and passkey rows: product status only.
  • Safe harbor: no longer bound into SECURITY.md.
  • Finding IDs: none remain.
  • Em-dashes: removed from the edited profile bullets.
  • Checker: rewritten in Python, with text normalisation and a finding-ID rule.
  • History: squashed into three commits.

Local CI

  • workflow-guardrails: PASS
  • test-canon-guardrail: 4/4 PASS
  • canon-guardrail: PASS
  • public-truth: OK
  • gitleaks: clean

No open Dependabot PRs.

Pass 2

  • AUDIT_POSTURE.md no longer links BOUNTY.md or describes remediation.
  • public_truth.py now checks every .md for BOUNTY.md links while it is not in force, requires qualifiers next to the claim, catches 'generally available' paid rails and numbered or prose Known-issues entries (all probes FAIL; origin/main 18; head OK).

Split

  • BOUNTY.md moved to its own draft PR ("draft: bug bounty policy (owner to fill)"). This PR no longer adds it, so it can merge now.
  • public_truth.py passes with or without BOUNTY.md. While the file is absent, any .md that links it fails. While it is present, its structure and placeholder rules apply.

🤖 Generated with Claude Code

https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P

BerryManifold and others added 3 commits September 24, 2026 23:23
…iled tier table, no private-archive or PGP path

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
…endpoints only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
…E; public-truth checks every .md for bounty links and tighter qualifiers

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
@SaulBuilds SaulBuilds changed the title security: draft BOUNTY.md (OWNER TO FILL rewards), reconciled SECURITY.md, profile truth + public-truth gate (PBA-L8 R2) security: public-claims accuracy: draft BOUNTY.md (not in force), SECURITY.md, profile + public-truth gate Sep 25, 2026
…s with or without BOUNTY.md

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
@SaulBuilds SaulBuilds changed the title security: public-claims accuracy: draft BOUNTY.md (not in force), SECURITY.md, profile + public-truth gate security: public-claims accuracy: SECURITY.md, AUDIT_POSTURE, profile + public-truth gate Sep 25, 2026
@SaulBuilds
SaulBuilds merged commit 8d6af62 into main Sep 25, 2026
6 checks passed
@SaulBuilds
SaulBuilds deleted the fix/pba-r2-truth branch September 25, 2026 07:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants