Skip to content

Commit e5a7e50

Browse files
TheStreamCodeTheStreamCode
andauthored
chore: fleet hygiene (release automation, dependabot, community files) (#1)
* chore: fleet hygiene (community files, CI hardening, dependabot) Add SECURITY.md (supported versions, private report path, and the subscription-key rotation story), CONTRIBUTING.md, CODE_OF_CONDUCT.md (sibling Covenant text), and issue + PR templates. Harden CI to the fleet standard: npm ci, Node 20/22/24 matrix, SHA-pinned actions, permissions: contents: read. Add grouped-weekly dependabot.yml (npm + github-actions). Closes the review P0 and P1 file items for opencode-muse-auth. * fix(ci): drop Node 20 from matrix, self-sufficient npm test Node 20's test runner treats the quoted tests/*.test.ts glob literally ('Could not find ... tests/*.test.ts'): glob support landed in Node 21, and Node 20 cannot execute the TypeScript suite at all (type-stripping needs 22.6+, default-on in late 22.x). Matrix is now [22, 24]. Add pretest -> build so bare 'npm test' works on a fresh clone: tests/auth.test.ts imports ../dist/auth.js (compiled output) and failed with ERR_MODULE_NOT_FOUND without a prior build. No new test file: tests/auth.test.ts already covers real shim logic (cache roundtrip/miss, deviceAuthorize field validation, pollToken pending->success + terminal errors, mintKey subscription/payment validation) - 6/6 passing. --------- Co-authored-by: TheStreamCode <michael@mikesoft.it>
1 parent 9b184a0 commit e5a7e50

10 files changed

Lines changed: 188 additions & 4 deletions

File tree

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
---
2+
name: Bug report
3+
about: Report a problem with the Muse subscription auth plugin
4+
title: "[bug] "
5+
labels: bug
6+
---
7+
8+
## What happened
9+
10+
A clear description of the bug.
11+
12+
## How to reproduce
13+
14+
- opencode version + plugin version (pinned or floating):
15+
- Auth step (`/connect` output, redacted — never paste a real key):
16+
- Cache state (`~/.config/opencode/muse-code-sub.json` present/stale/missing):
17+
18+
## Expected vs actual
19+
20+
- Expected:
21+
- Actual (include error output, redacted):
22+
23+
## Environment
24+
25+
- opencode-muse-auth version:
26+
- Node.js version:
27+
- OS:

‎.github/ISSUE_TEMPLATE/config.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
blank_issues_enabled: false
2+
contact_links:
3+
- name: Questions and support
4+
url: https://github.com/TheStreamCode/opencode-muse-auth/discussions
5+
about: Ask usage questions in GitHub Discussions
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
name: Feature request
3+
about: Suggest an improvement or new capability
4+
title: "[feat] "
5+
labels: enhancement
6+
---
7+
8+
## Problem / motivation
9+
10+
What are you trying to do that's hard or impossible today?
11+
12+
## Proposed solution
13+
14+
What you'd like to see.
15+
16+
## Alternatives considered
17+
18+
## Additional context

‎.github/dependabot.yml‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: "npm"
4+
directory: "/"
5+
schedule:
6+
interval: "weekly"
7+
day: "monday"
8+
labels:
9+
- "dependencies"
10+
groups:
11+
npm-minor-patch:
12+
update-types:
13+
- "minor"
14+
- "patch"
15+
- package-ecosystem: "github-actions"
16+
directory: "/"
17+
schedule:
18+
interval: "weekly"
19+
day: "monday"
20+
labels:
21+
- "dependencies"
22+
- "github-actions"
23+
commit-message:
24+
prefix: "chore(actions)"
25+
include: "scope"
26+
groups:
27+
actions-minor-patch:
28+
update-types:
29+
- "minor"
30+
- "patch"

‎.github/pull_request_template.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
## Summary
2+
3+
What does this PR change and why?
4+
5+
## How verified
6+
7+
- [ ] `npm run build` passes
8+
- [ ] `npm test` passes (Node 20/22/24 via CI)
9+
- [ ] Added/updated tests for the change
10+
11+
## Notes
12+
13+
- Any new dependency? Why existing ones weren't enough:
14+
- No secrets/API keys committed; subscription key never printed or logged.

‎.github/workflows/ci.yml‎

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,24 @@ on:
44
push:
55
pull_request:
66

7+
permissions:
8+
contents: read
9+
710
jobs:
811
build-test:
912
runs-on: ubuntu-latest
13+
# Node 20 excluded: `node --test "tests/*.test.ts"` needs test-runner glob
14+
# support (Node 21+) and TS type-stripping (Node 22.6+, default-on in late
15+
# 22.x). The suite is TypeScript importing compiled dist output.
16+
strategy:
17+
matrix:
18+
node: [22, 24]
1019
steps:
11-
- uses: actions/checkout@v4
12-
- uses: actions/setup-node@v4
20+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
21+
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
1322
with:
14-
node-version: "24"
15-
- run: npm install
23+
node-version: ${{ matrix.node }}
24+
cache: npm
25+
- run: npm ci
1626
- run: npm run build
1727
- run: npm test

‎CODE_OF_CONDUCT.md‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Code of Conduct
2+
3+
## Our pledge
4+
5+
We as members, contributors, and maintainers pledge to make participation in this project a
6+
harassment-free experience for everyone, regardless of age, body size, visible or invisible
7+
disability, ethnicity, sex characteristics, gender identity and expression, level of experience,
8+
education, socio-economic status, nationality, personal appearance, race, religion, or sexual
9+
identity and orientation.
10+
11+
## Our standards
12+
13+
Examples of behavior that contributes to a positive environment:
14+
15+
- Being respectful of differing opinions, viewpoints, and experiences.
16+
- Giving and gracefully accepting constructive feedback.
17+
- Focusing on what is best for the community.
18+
- Showing empathy toward other community members.
19+
20+
Unacceptable behavior includes:
21+
22+
- Harassment, insults, or derogatory comments, and personal or political attacks.
23+
- Publishing others' private information without explicit permission.
24+
- Other conduct which could reasonably be considered inappropriate in a professional setting.
25+
26+
## Enforcement
27+
28+
Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the project
29+
maintainer (see `package.json`). All complaints will be reviewed and investigated promptly and
30+
fairly. Maintainers are obligated to respect the privacy and security of the reporter.
31+
32+
## Attribution
33+
34+
This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org),
35+
version 2.1.

‎CONTRIBUTING.md‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Contributing to opencode-muse-auth
2+
3+
Thanks for your interest in improving this project! Bug reports, fixes, docs,
4+
and tests are all welcome.
5+
6+
## Development setup
7+
8+
```bash
9+
npm ci
10+
npm run build
11+
npm test
12+
```
13+
14+
CI repeats the same gate on Node 20, 22, and 24.
15+
16+
## Pull requests
17+
18+
- Keep changes focused; one concern per PR.
19+
- Add or update tests for behavior changes.
20+
- Never commit API keys, tokens, subscription keys, or account data.
21+
- Never print or log the cached subscription key in code or fixtures.

‎SECURITY.md‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Security Policy
2+
3+
## Supported versions
4+
5+
Security fixes target the latest published release and the current `main` branch.
6+
7+
## Reporting a vulnerability
8+
9+
This plugin mints account-bound credentials. Report security issues privately:
10+
use GitHub's **private vulnerability reporting** (Security Advisories) on this
11+
repository. If that route is unavailable, email `info@mikesoft.it` with the
12+
subject `opencode-muse-auth Security Report`. Do not open a public issue for
13+
sensitive findings.
14+
15+
## Credential handling
16+
17+
The Muse subscription key is cached owner-only at
18+
`~/.config/opencode/muse-code-sub.json`. It is never re-minted while valid,
19+
never printed, and never logged. Never commit keys, tokens, or account data to
20+
this repository, and never paste real credentials into issues, pull requests,
21+
or test fixtures.
22+
23+
On a `401`, delete the cached file and re-run `/connect` to mint a fresh key.

‎package.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@
3434
],
3535
"scripts": {
3636
"build": "tsc",
37+
"pretest": "npm run build",
3738
"test": "node --test --test-concurrency=1 \"tests/*.test.ts\"",
3839
"prepublishOnly": "npm run build"
3940
},

0 commit comments

Comments
 (0)