Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions .security/CRYPTO_NOTICE.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
== Cryptographic Hash Policy

=== Current Status

This repo uses MD5 or SHA1 in some files.

=== Policy

* *NEVER* use MD5/SHA1 for security purposes (passwords, signatures,
integrity)
* MD5/SHA1 is acceptable ONLY for:
** Cache key generation (non-security)
** Legacy format compatibility
** File checksums (when not security-critical)

=== Migration

Replace security-critical usage: - `+md5(password)+` → `+argon2+` or
`+bcrypt+` - `+sha1(signature)+` → `+sha256+` or `+sha384+` -
`+md5(integrity)+` → `+sha256+`

=== Files to Review

Check files flagged by CI for MD5/SHA1 usage.
24 changes: 0 additions & 24 deletions .security/CRYPTO_NOTICE.md

This file was deleted.

48 changes: 48 additions & 0 deletions ARCHITECTURE.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
== Architecture

=== Overview

This repository follows a modular, maintainable architecture designed
for clarity, scalability, and long-term sustainability.

=== Directory Structure

....
.
├── src/ # Source code
├── tests/ # Test suites
├── docs/ # Documentation
├── scripts/ # Utility scripts
├── config/ # Configuration files
├── LICENSE # License file
├── LICENSES/ # Full license texts
└── README.adoc # Project documentation
....

=== Design Principles

* *Separation of Concerns*: Each module has a single responsibility
* *Testability*: Code is written to be easily testable
* *Documentation*: All public APIs are documented
* *Configuration*: Environment-specific settings are externalized

=== Dependencies

* External dependencies are minimized and clearly declared
* Version pinning is used for reproducibility

=== Security Considerations

* Sensitive data is never committed to the repository
* Secrets are managed through environment variables or secure vaults
* Regular dependency audits are performed

=== Maintainability

* Code follows consistent style guidelines
* Pull requests require review and CI checks
* Issues and discussions are tracked transparently

'''''

_Last updated: 2026-07-18_
47 changes: 0 additions & 47 deletions ARCHITECTURE.md

This file was deleted.

Loading
Loading