Repository navigation
Conversation
…s, regression replay Maintained fork of myxdvz/booktree (upstream inactive since 2026-03). This commit changes no runtime behaviour; it sets the project up for public maintenance: - image ghcr.io/mancolt/booktree built for amd64+arm64 with SBOM/provenance; base pinned to alpine:3.21; rapidfuzz pinned so fuzzy scores cannot drift - CI: ruff, unit tests, bandit, pip-audit, gitleaks, Trivy image scan; Dependabot for pip, actions, docker - SECURITY.md, CONTRIBUTING.md (compatibility promise, never write under the source path, MAM call budget) - docs/FORK.md: output contract kept byte-compatible, defect roadmap mapped to upstream issues - tests/replay: offline replay of historical run logs (search keys, cached Audible/MAM ranking, target paths, OPF, stdout transcripts) + compare tool; frozen baseline summary for the upstream code - .claude/agents: correctness/efficiency and security review agents used before every commit Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JdymXZSW4aRWMFREPAFzkZ
…-arch PR builds, authenticate Trivy pull Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JdymXZSW4aRWMFREPAFzkZ
Trivy flagged Alpine's py3-setuptools 70.3.0 (CVE-2025-47273) and py3-msgpack (GHSA-6v7p-g79w-8964), both pulled in only by 'apk add py3-pip'. The venv seeds its own pip via ensurepip, so the system packages are unnecessary; the venv's pip is removed after installing requirements so the runtime image carries no installer. Also 'apk upgrade' the base and pin build args to their CI defaults. Runtime unchanged: Python 3.12, same dependency versions; corpus replay identical to baseline. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JdymXZSW4aRWMFREPAFzkZ
Author
|
Opened against the wrong base by mistake, this is a fork; closing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.