Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,8 @@ GITHUB_TOKEN=your_github_personal_access_token
# connectors for local development only, set this to 1 (logged as a warning).
# CONCORD_ALLOW_INSECURE_TRANSPORT=1

# ── Connector tokens ──────────────────────────────────────────────TERRASECURE_TOKEN=
# ── Connector tokens ──────────────────────────────────────────────
TERRASECURE_TOKEN=
TRIVY_TOKEN=
KAGENT_TOKEN=
HOLMESGPT_TOKEN=
Expand Down
26 changes: 23 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,34 @@ on:
pull_request:
branches: [main, develop]

# Least privilege: this workflow only needs to read the repo.
permissions:
contents: read

# Cancel superseded runs on the same ref to save minutes.
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true

jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: actions/setup-python@v5
with:
python-version: "3.11"
- run: pip install -r requirements/dev.txt
- run: ruff check .
- run: pytest tests/unit -v --tb=short
cache: pip
cache-dependency-path: requirements/dev.txt

- name: Install dependencies
run: pip install -r requirements/dev.txt "psycopg[binary,pool]"

- name: Lint
run: ruff check .

- name: Test (full suite, excluding slow)
env:
CONCORD_DB_PATH: ":memory:"
run: pytest tests/ -q -m "not slow"
33 changes: 31 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,39 @@ on:
push:
tags: ["v*"]

permissions:
contents: read

concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false

jobs:
release:
runs-on: ubuntu-latest
permissions:
contents: write # create the GitHub release
packages: write # push the image to GHCR
steps:
- uses: actions/checkout@v4
- run: docker build -t ghcr.io/beyondbug/concord:${{ github.ref_name }} .
- uses: softprops/action-gh-release@v2

- name: Log in to GHCR
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Build and push image
uses: docker/build-push-action@v6
with:
context: .
push: true
tags: |
ghcr.io/beyondbug/concord:${{ github.ref_name }}
ghcr.io/beyondbug/concord:latest

- name: Create GitHub release
uses: softprops/action-gh-release@v2
with:
generate_release_notes: true
32 changes: 28 additions & 4 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,25 +5,49 @@ on:
branches: [main, develop]
pull_request:

# Default to read-only; the SARIF upload job elevates only what it needs.
permissions:
contents: read
security-events: write
actions: read

concurrency:
group: security-${{ github.ref }}
cancel-in-progress: true

jobs:
trivy:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # required to upload SARIF to code scanning
steps:
- uses: actions/checkout@v4
- name: Run Trivy filesystem scan
uses: aquasecurity/trivy-action@master

- name: Trivy filesystem scan
# Pinned to a released tag rather than @master for supply-chain safety.
uses: aquasecurity/trivy-action@0.35.0
with:
scan-type: fs
scan-ref: .
format: sarif
output: trivy.sarif
severity: CRITICAL,HIGH

- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: trivy.sarif
continue-on-error: true

pip-audit:
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Audit Python dependencies
run: |
pip install pip-audit
pip-audit -r requirements/base.txt
52 changes: 52 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
# Changelog

All notable changes to Concord are documented here. The format is based on
[Keep a Changelog](https://keepachangelog.com/), and the project aims to follow
semantic versioning once it reaches a tagged release.

## [Unreleased]

### Added
- **SecurityPolicyAgent** with a dependency-free source-code pattern scanner
(Python/JS/TS/Go/PHP).
- **Durable persistence**: SQLite by default, optional **PostgreSQL** backend
selected via `CONCORD_DATABASE_URL` with graceful fallback and schema
migration.
- **API authentication** (API key, fail-safe dev mode) and request
**correlation IDs** threaded into logs and the audit trail.
- **MCP transport hardening**: TLS verification by default, CA bundles, mTLS,
and refusal of plaintext URLs unless explicitly opted in.
- **Prompt-injection sanitization** of untrusted tool output before it reaches
the LLM prompt.
- **Redis-backed dedup** with an in-memory TTL fallback.
- **Approval lifecycle**: approve, reject, and expire flows — all durable and
audited — plus a pending-approvals queue.
- **Structured (JSON) logging** mode.
- **Web dashboard** with seven live views: Overview, Findings, Incidents, Security,
Approvals, Audit, Settings (all read from the live API; no mock data).
- **CLI** with human and `--json` output: `health`, `findings`, `audit`,
`approvals`, `approve`, `reject`, `stats`, `diagnostics`, `invoke`, `agents`,
and shell-completion help.
- **Docker** multi-stage non-root image with a health check; hardened
`docker-compose` (loopback ports, read-only rootfs, required secrets,
service health checks).
- **Helm chart** with security context, resource limits, probes, and a
least-privilege service account.
- **Documentation**: rewritten `README.md`, `docs/ARCHITECTURE.md`, and
`docs/threat-model.md`.
- **CI/CD hardening**: least-privilege workflow permissions, full-suite CI,
pinned actions, and a dependency-audit job.

### Changed
- Confidence scoring remains deterministic
(`severity_weight × source_reliability`), never LLM self-reported.
- Audit records are now durable and correlation-tagged (previously log-only).

### Security
- Per-connector scoped credentials; no master credential.
- Human approval gate for consequential/tie-break outcomes.

### Known limitations
- Kubernetes and Observability agents are scaffolded but require live MCP
services (kagent / HolmesGPT) to complete.
- Terraform assets under `infra/` remain placeholders.
Loading
Loading