Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 11 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -140,7 +140,7 @@ Review new alerts on their own data flow.

### Benchmark dependency maintenance

As of September 7, 2026, `paste` 1.0.15 enters through the development dependency
As of October 1, 2026, `paste` 1.0.15 enters through the development dependency
`faer` 0.24.4, via `gemm` 0.19.0 and `pulp` 0.22.3. Those are the latest
published upstream versions checked on that date. Repository-owned Rust code
already uses `pastey`; changing that direct dependency cannot replace upstream
Expand All @@ -152,7 +152,14 @@ maintenance concern, separate from the logging false positives. `paste` is absen
from the library's normal and build dependency graph, including with `exact`
enabled, but its procedural macro executes when building development targets.

The root `osv-scanner.toml` temporarily accepts only `RUSTSEC-2024-0436` until
January 1, 2027, when OSV resumes blocking on it. This is a documented acceptance
of the maintenance risk, not a patched dependency. Native OSV configuration
discovery applies it to the root lockfiles scanned by `just security`; `paste`
remains in the package inventory, and all other advisories remain enabled.

Keep this advisory visible in `cargo audit`. Recheck the dependency path with
`cargo tree --locked --all-features -i paste` when updating `faer`, `gemm`, or
`pulp`, and remove the dependency through a maintained upstream release when
available.
`cargo tree --locked --workspace --all-features -i paste` when updating `faer`,
`gemm`, or `pulp`. Remove both the dependency and its OSV exception through a
maintained upstream release when available; reassess explicitly before extending
the exception.
17 changes: 16 additions & 1 deletion docs/code_organization.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,6 +119,10 @@ with local stubs; the [contributor review workflow](../CONTRIBUTING.md#coderabbi
owns prerequisites and invocation policy.
The [justfile](../justfile) owns executable development workflows.

`osv-scanner.toml` owns temporary advisory-specific dependency exceptions, and
`.gitleaks.toml` owns narrow secret-scan false-positive exceptions. Their rationale
and review policy belong in [Security Checks](../SECURITY.md#security-checks).

The shared package also owns managed tool installation, verification, and update
implementation. `.python-version`, `rust-toolchain.toml`, and `pyproject.toml`
own consumer declarations; `scripts/tests/test_toolchain_integration.py` checks
Expand All @@ -138,7 +142,18 @@ byte transport, CPU metadata, diagnostics, and zizmor authentication. The thin
`scripts/benchmark_process.py` adapter retains benchmark phase signatures and
consumer root selection. Generic `subprocess_utils.py` and `run_zizmor.sh`
implementations and their duplicate tests are retired; scientific schemas and
benchmark policy remain here. Hosted Dependabot approvals use the pinned shared
benchmark policy remain here.

Performance consumers use shared Criterion parsing and estimate/comparison
validation, digest verification, archive extraction, byte-preserving document
sections, and multi-file transactions. Local rendering produces complete candidate
outputs before publication. Historical artifact schemas and fingerprint framing,
benchmark selection and eligibility, common-harness orchestration, and complete
run retention remain in the consumer pending the corresponding shared workflow
contract. Generic parsing, staging, and rollback tests belong upstream; local
tests verify the scientific and retained-artifact integration boundaries.

Hosted Dependabot approvals use the pinned shared
GitHub workflow; the [rollout guide](dev/MANAGING_CHANGES.md#dependabot-approval-rollout)
owns settings and deployment verification.

Expand Down
6 changes: 6 additions & 0 deletions osv-scanner.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Advisory-specific, temporary acceptance; keep every other advisory enabled.
# Native OSV configuration applies to the lockfiles in this directory.
[[IgnoredVulns]]
id = "RUSTSEC-2024-0436"
ignoreUntil = 2027-01-01
reason = "Benchmark-only faer -> gemm/pulp -> paste has no maintained published replacement yet; see SECURITY.md#benchmark-dependency-maintenance."
9 changes: 6 additions & 3 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -77,8 +77,8 @@ ignore = [
[tool.ruff.lint.per-file-ignores]
"**/tests/test_*.py" = [ "S101", "SLF001", "D101", "D102", "D103" ]
# Static-analysis fixtures intentionally contain the patterns these rules reject.
"tests/semgrep/scripts/python_portability.py" = [ "D103", "INP001", "N813", "PLW1510", "S603", "S607", "SIM115", "UP020", "UP021" ]
"tests/semgrep/scripts/tests/python_exceptions.py" = [ "BLE001", "D100", "D103", "EM101", "INP001", "S110", "S607", "SIM105", "TRY002" ]
"tests/semgrep/scripts/python_portability.py" = [ "D103", "INP001", "N813", "PLW1510", "S603", "S607", "SIM115", "UP020" ]
"tests/semgrep/scripts/tests/python_exceptions.py" = [ "BLE001", "D100", "D103", "EM101", "INP001", "S110", "S607", "SIM105" ]

[tool.ruff.lint.mccabe]
max-complexity = 10
Expand Down Expand Up @@ -139,6 +139,8 @@ line-length = 160
[tool.uv]
package = true
required-version = "==0.12.21"
# Semgrep wheels bundle the native engine; building its sdist does not.
no-build-package = [ "semgrep" ]
# Semgrep 1.178.0 restricts PyJWT to 2.13.x; 2.15.1 contains the OSV fixes.
# Keep crypto support while overriding that restriction until upstream updates it.
override-dependencies = [ "pyjwt[crypto]>=2.15.1,<3" ]
Expand All @@ -149,7 +151,8 @@ dev = [
{ include-group = "tooling" },
"actionlint-py==1.7.12.25",
"pytest==9.1.1",
"ruff==0.16.9",
"ruff==0.16.10",
# 1.179.0 has no Windows wheel; its sdist omits semgrep-core.exe.
"semgrep==1.178.0",
"shellcheck-py==0.11.0.1",
"shfmt-py==4.2.0",
Expand Down
36 changes: 29 additions & 7 deletions scripts/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -352,9 +352,10 @@ checks the actual release selectors, preserved scientific evidence, DOI policy,
and recipe forwarding. `tests/test_cargo_update_integration.py` executes native
Cargo upgrades against a disposable local registry; Python updates have a
matching real-uv fixture in the toolchain tests. Common parser, transaction,
Markdown, and fixture regressions belong to the shared package. Scientific,
benchmark, and performance tooling remains consumer-owned. Notebook tooling
remains outside scope.
Markdown, and fixture regressions belong to the shared package. Scientific
eligibility, benchmark orchestration, retained schemas, and report layouts remain
consumer-owned. Shared performance primitives are adopted below.
Notebook tooling remains outside scope.

The same pinned release owns opt-in CodeRabbit review orchestration through
`research-repo-tools review branch --base=REF` and `review uncommitted`.
Expand Down Expand Up @@ -400,9 +401,30 @@ Shared process discovery, execution, byte transport, CPU detection, diagnostics,
and zizmor authentication belong to research-repo-tools. The former
`subprocess_utils.py` and `run_zizmor.sh` implementations and their duplicated
unit tests are removed. Consumer tests retain native adapter checks, benchmark
contracts, caller file-policy coverage, and recipe forwarding. The remaining
performance modules own la-stack's retained schemas, scientific eligibility,
benchmark inventories, and report layouts; shared primitives are not a drop-in
replacement for those contracts.
contracts, caller file-policy coverage, and recipe forwarding.

Performance scripts also use the published shared Criterion parser and estimate
validation, comparison arithmetic, exact-byte digest verification, safe archive
extraction, document marker replacement, and multi-file publication transaction.
Raw Criterion numeric strings are rejected by the shared parser. Plotting and
release publication still require complete confidence intervals; hosted baselines
and full local summaries additionally require 100 samples and 95% intervals.
README marker replacement preserves bytes outside the selected section.
Publication candidates are fully rendered and validated before one transaction
replaces the report, evidence, archive index, and retained summaries. Shared
recovery errors identify preserved backups if rollback fails.

The remaining modules own la-stack's historical CSV/JSON schemas and fingerprints,
scientific eligibility, benchmark inventories, current-harness installation,
release selection policy, complete run retention, and multi-library plot layout.
Existing evidence keeps its schema and digest framing. Generic parser and
transaction regressions belong upstream; consumer tests check retained-schema
round trips, complete output groups, failure preservation, and scientific policy.
The remaining workflow migration requires a published shared contract for common
harnesses, configurable measurement completeness, and immutable per-run retention.
[research-repo-tools#64](https://github.com/acgetchell/research-repo-tools/issues/64)
tracks that contract;
[la-stack#268](https://github.com/acgetchell/la-stack/issues/268) tracks adoption
after publication.

See `docs/RELEASING.md` for the full release workflow.
Loading
Loading