- The suite is the source-available proprietary distribution of three canonical security tools.
- Each bundled module must remain independently runnable.
- A normal clone must include all source code without a submodule initialization step.
- Root CI must validate Python, both Node modules, packaging, and module provenance.
- The trust layer and unified deep reports remain roadmap items for a later tranche.
- Updates are reviewed and explicit; CI prevents silent drift after synchronization.
- Three modules and one primary maintainer keep subtree maintenance manageable.
- Security and reproducibility take priority over fully automatic upstream updates.
- Canonical module APIs remain unchanged during the initial synchronization.
- Live SocialScan monitoring stays in the Address Intelligence workflow and uses a secret.
- Local subtree conversion commits are allowed; nothing is pushed before final validation.
- Git subtree (selected): clone-ready source, upstream provenance, and explicit pulls.
- Vendored copies plus a lock file: simple, but easier to drift and lose file deletions.
- Git submodules: strong provenance, but adds clone/setup friction for users and packaging.
The root repository vendors each canonical repository through Git subtree:
| Prefix | Canonical repository | Branch |
|---|---|---|
skill-inspector/ |
arraya20/pharos_skill_inspector |
main |
contract-inspector/ |
arraya20/pharos-contract-inspector |
master |
address-intelligence/ |
arraya20/pharos-address-intelligence |
main |
modules.lock.json records the expected upstream URL, branch, and commit for each
prefix. A root drift checker validates the manifest schema, verifies that required
module files exist, and ensures the subtree commit recorded in Git history matches
the lock entry. Synchronization refuses a dirty worktree or unknown module.
Root CI owns suite-wide quality gates. It runs each module in its own working directory, builds distributable packages, and executes the drift/documentation checks. Live external-service smoke tests remain separate from deterministic CI.
- Synchronization exits before mutation when the worktree is dirty.
- Unknown module names, invalid lock entries, missing tools, and failed fetches are fatal.
- Drift validation fails closed when provenance cannot be established.
- No synchronization command force-pushes or rewrites an upstream repository.
- Add a failing drift test against the stale snapshots.
- Synchronize and test one module at a time.
- Add root CI and validate its commands locally.
- Check documentation versions and module references from the lock manifest.
- Run all tests, lint, audits, package builds, and
git diff --check.
- Use Git subtree instead of submodules so a normal clone is immediately usable.
- Keep synchronization explicit instead of automatically pulling unreviewed security code.
- Store upstream SHAs in a root lock manifest for review and release provenance.
- Put CI at the repository root because nested workflows are ignored by GitHub.
- Keep trust-layer and unified composition labeled as roadmap until implemented.