Skip to content

docs: advertise supply-chain hardening in READMEs and correct SECURITY.md - #407

Merged
allxsmith merged 2 commits into
mainfrom
docs/hardening-readme
Jul 30, 2026
Merged

allxsmith merged 2 commits into
mainfrom
docs/hardening-readme

Conversation

@allxsmith

Copy link
Copy Markdown
Owner

Closes #403. Also lands the badge half of #404 and the documentation half of #405.

What

Badges + a Hardened by default section in all four READMEs, and four factual corrections to SECURITY.md.

File Badges added Section
README.md Socket, Scorecard, provenance, security policy ## 🔒 Hardened by default
bulma-ui/README.md same, scoped to @allxsmith/bestax-bulma after ## 📦 NPM Package
create-bestax/README.md same, scoped to create-bestax before ## Publishing
bestax-migrate/README.md had none — full block added before ## License

Why

bulma-ui/README.md and create-bestax/README.md are the npmjs.com package pages — the highest-leverage place to answer "is this dependency safe to add" — and they said nothing about provenance, scanning, or review. Socket.dev in particular was completely invisible: it's configured in the Socket dashboard, so no file in this repo mentioned it.

SECURITY.md corrections found while auditing

These were wrong before this PR, independent of the new copy:

  1. Socket.dev and CodeQL were undocumented. Both are dashboard-configured, so a file-only audit couldn't discover either. Added, each noting why there's no config file.
  2. Cooldown exceptions understated — said "One dev-only exception: prettier". pnpm-workspace.yaml:33-38 also excludes fast-uri. Reworded to describe the actual policy rather than enumerate a list that drifts.
  3. bestax-migrate missing from the supported-versions table. It's published (1.0.0) and sets publishConfig.provenance.
  4. "both published packages" → three.

Wording note

The review layer is described as AI bot reviews — CodeRabbit plus an independent adversarial Claude review on a deliberately different model — followed by required green CI, an approving review, and a human merge. It does not claim multiple human reviewers.

Verification

  • prettier --check passes on all five files
  • pnpm check:conformance — all 9 checks green
  • Package READMEs use absolute URLs for SECURITY.md and the docs guide, so links work when rendered on npmjs.com rather than resolving against a repo path
  • Every claim spot-checked against its source (ci.yml, pnpm-workspace.yaml, .coderabbit.yaml, dependency-review.yml, branch protection API)
  • Socket + Scorecard badge images actually render. Could not verify from the dev sandbox — Cloudflare 403s automated requests to socket.dev, and npmjs.com blocks them too. The Socket URL format is verified against live public usage in t3-oss/t3-env and ccusage/ccusage. Please eyeball the rendered README here on GitHub, and the npm pages after the next release. Fallback if npm strips Socket-hosted images: swap to a shields.io badge linking to the Socket package page — shields.io is definitively rendered by npm, as the existing badges prove.

Merge order

Merge #406 first. The Scorecard badge 404s until scorecard.yml has run on main at least once.

Follow-up not done here

pnpm-workspace.yaml still excludes fast-uri from the cooldown, past its own stated removal date of 2026-07-22. Pruning it is a dependency-resolution change, not a docs change, so it's deliberately out of scope — worth a small separate PR (related: #391).

@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@allxsmith, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 59 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: a43c9488-ff6c-4b4e-ab61-d3a1d4d7ce18

📥 Commits

Reviewing files that changed from the base of the PR and between 69f9fe7 and 180bd6b.

📒 Files selected for processing (5)
  • README.md
  • SECURITY.md
  • bestax-migrate/README.md
  • bulma-ui/README.md
  • create-bestax/README.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://ef1f7ef9.bestax.pages.dev

Comment thread SECURITY.md Outdated
full commit SHA, not a movable tag.
- **Socket.dev** — the Socket GitHub App reviews every pull request for
malware, install scripts, obfuscated code, and privilege escalation in
dependency changes, and posts two required checks. Its policy is managed in

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Socket checks are not "required" checks — 🟡 Minor · Correctness

What: This new bullet says Socket "posts two required checks", but the Socket checks are not part of main's branch protection. The live required_status_checks on main are exactly four — Build and Test, React 18 compatibility, React 19 compatibility, Dependency Review — none of them Socket.

Why it matters: SECURITY.md is the canonical, precise statement of the gate. Calling the Socket checks "required" claims a merge gate that does not exist — exactly the "advertising a gate that isn't configured" failure that #405 was filed to stop. #405 even enumerates the two Socket Security checks under "Checks deliberately NOT required". Socket posts the checks and surfaces alerts on every PR, but it does not block merge.

Evidence — live branch protection on main
"required_status_checks": {
  "contexts": ["Build and Test", "React 18 compatibility",
               "React 19 compatibility", "Dependency Review"]
}

No Socket context present. rulesets is [].

Fix:

Suggested change
dependency changes, and posts two required checks. Its policy is managed in
dependency changes, and posts two status checks on every PR. Its policy is managed in

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deep review — 1 blocking · 2 advisory

# Severity Area Finding Location
1 🟡 Minor Correctness Socket checks described as "required" — they are not in main's required_status_checks; only the four CI checks are SECURITY.md:49
2 🔵 Advisory Correctness SECURITY.md states .github/workflows/scorecard.yml scores the repo weekly, and 4 READMEs add Scorecard badges — but that file is absent from main and PR #406 (issue #404) is still open. Copy/badges are false until #406 merges. Author documented "merge #406 first." SECURITY.md:55, README badges
3 🔵 Advisory Correctness "an approving review" is required at merge — I confirmed required_status_checks (4 CI contexts) but could not read required_pull_request_reviews (token 403 on the protection endpoint) and #405 is still open. Owner should confirm a 1-approval rule is actually configured. SECURITY.md:62, README.md:198

Overall: This is a well-researched, accurate docs PR — I chased each supply-chain claim to its source and the great majority hold up (signed provenance on all three packages incl. bestax-migrate provenance:true, OIDC/no-NPM_TOKEN, SHA-pinned actions, install-scripts-blocked, 3-day cooldown with the prettier exclusion, frozen-lockfile + pnpm audit --audit-level=high gate, CodeQL default-setup with no codeql.yml, .github/** write-lock for AI agents, required-signatures + no-force-push + no-deletion, and the four required CI checks all verified live). The riskiest part is timing and precision around gates that aren't fully in place yet: the "required" Socket wording overstates the merge gate (blocking), and the Scorecard workflow the doc names doesn't exist on main yet. The human should fix the one word on line 49 and honor the stated merge-after-#406 ordering.

Residual risk: the failure class here is documenting a security gate that isn't actually enforced (the exact concern of #405):

  • Required-checks overstatement — confirmed once: Socket's two checks are posted but not in branch protection (finding #1). The four CI checks are genuinely required (verified against the live protection payload), so the green-CI claim is sound.
  • Scorecard forward-reference — confirmed: scorecard.yml is absent from main and #406/#404 are open; mitigated only by the PR body's explicit "merge #406 first" note, which a human merge must honor (finding #2).
  • Approving-review requirement — unverifiable from here (protection endpoint 403'd); refuted only partially since the sibling required_status_checks half of #405 is demonstrably applied. Owner-confirmable in seconds (finding #3).

🏄 Solid, honest write-up, dude — the security story mostly checks out clean against the live config. Just one gnarly little word ("required" on the Socket line) paddling out ahead of the actual gate, and a couple badges waiting on the #406 set to roll in. Fix the word, mind the merge order, and this one's good to ride.

allxsmith added a commit that referenced this pull request Jul 29, 2026
Socket posts two checks on every PR, but they are not in main's
required_status_checks — only Build and Test, the React 18/19 matrix,
and Dependency Review are. Caught by deep review on #407.
@allxsmith

Copy link
Copy Markdown
Owner Author

Good catch on #1 — that one was a real error. All three addressed.

Finding 1 (🟡 Minor, "required" overstates the gate) — fixed in c9fb21c

Correct and mine. Socket posts two checks on every PR, but they are not in main's required_status_checks — only Build and Test, React 18 compatibility, React 19 compatibility, and Dependency Review are. Reworded to "posts two checks on every pull request." Grepped the other four files; no other required check claim anywhere in the PR.

Finding 2 (🔵 Advisory, Scorecard forward-reference) — acknowledged, merge order stands

Accurate. scorecard.yml lands in #406; the SECURITY.md bullet and the four Scorecard badges are forward references until then. The PR body calls out merge #406 first and that ordering needs to be honored on merge.

Finding 3 (🔵 Advisory, unverified approval rule) — resolved: it is configured

The 403 was a token-scope limit on the review's side, not an absent rule. Live payload:

$ gh api repos/allxsmith/bestax/branches/main/protection
required_status_checks: strict=false
  contexts: [Build and Test, React 18 compatibility, React 19 compatibility, Dependency Review]
required_pull_request_reviews:
  required_approving_review_count: 1
  dismiss_stale_reviews: true
  require_code_owner_reviews: false
required_signatures: true

Applied under #405 before this PR was opened. Independent confirmation: both #406 and #407 currently report mergeStateStatus: BLOCKED / reviewDecision: REVIEW_REQUIRED — the rule is visibly gating these very PRs.

enforce_admins stays false deliberately: GitHub doesn't allow approving your own PR, and this is a solo-maintained repo, so the owner retains bypass. The approval requirement binds bestaxbot, Dependabot, and outside contributors — which is the gate .coderabbit.yaml:10-12 was written to protect, and it is now real rather than aspirational.

@github-actions

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://05fbcc74.bestax.pages.dev

@allxsmith

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

…Y.md

Adds Socket.dev, OpenSSF Scorecard, npm provenance, and security-policy
badges plus a 'Hardened by default' section to all four READMEs. The two
npm-published package READMEs are the highest-leverage place to say this
and previously said nothing.

Package READMEs use absolute URLs so links survive rendering on npmjs.com.

SECURITY.md corrections:
- Socket.dev and CodeQL were invisible in-repo (both dashboard-configured)
- cooldown exceptions described as prettier-only; there are more
- bestax-migrate missing from the supported-versions table
- provenance said 'both packages'; there are three

Closes #403
Socket posts two checks on every PR, but they are not in main's
required_status_checks — only Build and Test, the React 18/19 matrix,
and Dependency Review are. Caught by deep review on #407.
@allxsmith
allxsmith force-pushed the docs/hardening-readme branch from c9fb21c to 180bd6b Compare July 29, 2026 22:24
@github-actions

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://39717241.bestax.pages.dev

@allxsmith

Copy link
Copy Markdown
Owner Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@allxsmith
allxsmith merged commit 92e94e0 into main Jul 30, 2026
24 checks passed
@allxsmith
allxsmith deleted the docs/hardening-readme branch July 30, 2026 00:01
@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: RE-REVIEW — verify the prior finding was properly addressed, and re-verify every public security claim. Head is rebased; note CodeRabbit has NEVER successfully reviewed this PR (rate-limited), so you are the only reviewer on it.

Your previous review flagged (🟡 Minor) that SECURITY.md called Socket’s checks "required" when they are not in main’s required_status_checks. The author claims this is fixed.

Verify independently — this PR publishes security claims to npmjs.com, so an overstatement ships to consumers:

  1. Confirm the Socket wording is now accurate, and that no other file in the diff makes the same overstatement.
  2. Re-verify EVERY claim in the new "Hardened by default" sections and the SECURITY.md additions against the live repo state: branch protection (required checks, approvals, signatures), publishConfig.provenance across packages, OIDC publishing with no NPM_TOKEN, install-script blocking, cooldown, SHA-pinned actions, CodeQL, Dependency Review, Dependabot. Flag anything overstated, understated, or unverifiable.
  3. The author asserts main now requires green CI and 1 approval (applied under [Security] main lacks required status checks and required reviews — two in-repo comments claim a gate that doesn't exist #405). If your token cannot read the protection endpoint, say so rather than assuming either way.
  4. The section claims an "independent adversarial Claude review ... a different model from the one writing AI-authored changes". Confirm that is actually true of claude-review.yml vs claude-implement.yml.
  5. Check the package READMEs use absolute URLs so links resolve when rendered on npmjs.com rather than against a repo path.
  6. bestax-migrate is added to the supported-versions table and given badges, but it is currently uninstallable from npm ([Bug] bestax-migrate is uninstallable from npm — published manifest contains "workspace:^" #412). Assess whether advertising it here is misleading.

@allxsmith

Copy link
Copy Markdown
Owner Author

@claude Please re-review this PR to verify prior review feedback was addressed, and independently re-verify every public security claim in it. Two reasons this needs a careful pass: CodeRabbit never successfully reviewed this PR (rate-limited every attempt), and the content ships to npmjs.com, so an overstatement reaches consumers.

Your earlier deep review flagged (🟡 Minor) that SECURITY.md called Socket’s checks "required" when they are not in main’s required_status_checks. The author claims that is fixed.

Please verify independently, treating claims in the PR body and comments as unverified:

  1. Confirm the Socket wording is now accurate and that no other file in the diff repeats the overstatement.
  2. Re-verify every claim in the new "Hardened by default" sections and the SECURITY.md additions against live repo state: branch protection (required checks, approvals, signatures), publishConfig.provenance across packages, OIDC publishing with no NPM_TOKEN, install-script blocking, the cooldown, SHA-pinned actions, CodeQL, Dependency Review, Dependabot. Flag anything overstated, understated, or unverifiable.
  3. The author asserts main now requires green CI and 1 approving review (applied under [Security] main lacks required status checks and required reviews — two in-repo comments claim a gate that doesn't exist #405). If your token cannot read the protection endpoint, say so explicitly rather than assuming either way.
  4. The copy claims "an independent adversarial Claude review ... a different model from the one writing AI-authored changes." Confirm that is actually true of claude-review.yml vs claude-implement.yml.
  5. Confirm the package READMEs use absolute URLs, so links resolve when rendered on npmjs.com rather than against a repo path.
  6. bestax-migrate gains badges and a supported-versions row here, but it is currently uninstallable from npm ([Bug] bestax-migrate is uninstallable from npm — published manifest contains "workspace:^" #412 — published manifest carries workspace:^). Assess whether advertising it in this state is misleading.

Report what is actually wrong. If a claim checks out, say so briefly rather than manufacturing findings.

@claude

claude Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Claude finished @allxsmith's task in 3m 47s —— View job


Re-review — verifying prior fix + every public security claim

  • Gather context (repo files at the merge commit, workflow configs)
  • Verify Socket wording fix + scan for repeats
  • Re-verify README/SECURITY.md claims against live repo files
  • Attempt live branch-protection check
  • Verify publishConfig.provenance across packages
  • Verify claude-review.yml vs claude-implement.yml models
  • Verify package READMEs use absolute URLs
  • Assess bestax-migrate npm-installability vs [Bug] bestax-migrate is uninstallable from npm — published manifest contains "workspace:^" #412
  • Post findings

Note on method: this sandbox has no network access — git fetch, gh api, curl, and WebFetch all require an approval I couldn't obtain. Every claim below is checked against the actual repo files at the merge commit (92e94e0), not by re-running the commands the PR author pasted output from. Per your instruction, I'm treating those pasted outputs as unverified rather than trusting them.


1. Socket wording — fixed, no repeat elsewhere

SECURITY.md:47-51 now reads "posts two checks on every pull request... managed in the Socket dashboard" — no "required" language. Grepped required across all five changed files: the only other hits are "required green CI" / "an approving review" in the four READMEs' AI-review bullets, which refer to the CI+approval gate, not Socket. No file repeats the overstatement.

2. Claims re-verified against live repo state (not just prose)

Claim Verified against Result
Install scripts blocked by default pnpm-workspace.yaml:12-24 (allowBuilds, default-deny) ✅ matches
3-day cooldown pnpm-workspace.yaml:29 minimumReleaseAge: 4320 (min) ✅ matches (4320 min = 3 days)
Cooldown exceptions reworded from "prettier-only" pnpm-workspace.yaml:33-34 — only prettier currently listed ✅ generic wording is accurate; no fast-uri entry exists in this checkout (matches the PR's own "follow-up not done here" note that it's still pending removal elsewhere)
Isolated node_modules pnpm-workspace.yaml:68 nodeLinker: isolated ✅ matches
Frozen lockfile in CI ci.yml:39,204 pnpm install --frozen-lockfile; React matrix job explicitly uses --no-frozen-lockfile (ci.yml:153) — matches the doc's stated exception ✅ matches
publishConfig.provenance on all three packages bulma-ui/package.json:205, create-bestax/package.json:77, bestax-migrate/package.json:72 — all true ✅ "three" is correct
OIDC publishing, no NPM_TOKEN ci.yml:224-235 — publish job comment explicitly documents no NPM_TOKEN, only id-token: write ✅ matches
SHA-pinned actions grepped every uses: line in .github/workflows/*.yml — 100% pinned to 40-char SHAs; the one non-SHA hit is a local composite action (./.github/actions/verified-commit), correctly out of scope ✅ matches
Dependency Review blocks on high severity dependency-review.yml:23 fail-on-severity: high, job named exactly Dependency Review ✅ matches
Dependabot weekly, grouped .github/dependabot.yml — interval: weekly, dev-dependencies/production-dependencies groups ✅ matches
Scorecard weekly + badge scorecard.yml exists on this checkout (schedule + push-to-main triggers, publish_results: true) — no longer a forward reference now that #406 is merged ✅ matches
CodeQL / Socket dashboard-configured, no workflow file confirmed no codeql.yml in .github/workflows/ ✅ matches (can't verify the dashboard toggle itself — see #3)
Package README SECURITY.md/docs-guide links are absolute all three package READMEs link https://github.com/allxsmith/bestax/blob/main/SECURITY.md and https://bestax.io/docs/guides/security ✅ matches — resolves correctly on npmjs.com

3. Branch protection — could not verify, saying so explicitly

git fetch, gh api, curl, and WebFetch all require approval this sandbox doesn't grant, so I cannot independently confirm required_status_checks, required_approving_review_count, or required_signatures on main right now. The four CI context names SECURITY.md cites (Build and Test, React 18 compatibility, React 19 compatibility, Dependency Review) do match the actual job names in ci.yml — so the doc isn't inventing checks that don't exist in the workflow — but whether they're wired into branch protection as required, and whether the 1-approval/signed-commits rules are live, is unverified by me. The author's pasted gh api payload in the thread may well be accurate, but I have no independent confirmation of it.

4. Independent adversarial review, different model — confirmed true

.github/workflows/claude-review.yml:267 pins --model claude-opus-4-8. .github/workflows/claude-implement.yml:116 pins --model claude-sonnet-5. Different models, confirmed directly in the workflow files — this claim is accurate.

5. bestax-migrate advertised while uninstallable — confirmed real, not fixed by this PR

bestax-migrate/package.json:51 still declares "@allxsmith/bestax-bulma": "workspace:^" in dependencies at the commit this PR merged into. A fix exists (fix(bestax-migrate): resolve workspace: specifiers before publishing, commit 782829a) but only on the still-open branch fix/412-migrate-workspace-protocol — git merge-base --is-ancestor 782829a 92e94e0 confirms it is not an ancestor of this PR's merge commit, i.e. not merged. So as of this PR, bestax-migrate 1.0.0 is genuinely what #412 describes: published with an unresolved workspace specifier, meaning npm install bestax-migrate pulls a dependency npm can't resolve.

This PR adds four Socket/Scorecard/provenance/security-policy badges and a supported-versions row for a package in that state. That's not a factual error — every individual badge/claim is still true (it does have provenance, Socket does scan it) — but the overall effect is advertising install-readiness for a package that currently can't be installed. Worth a one-line caveat in the table or a follow-up, though I'd call this advisory, not blocking: it doesn't misstate any security control, and it's arguably out of scope for a docs-only PR whose job is describing the pipeline, not the artifact.


Summary

The one prior blocking finding (Socket "required" wording) is genuinely fixed, and I found no instance of it recurring elsewhere in the diff. Every checkable claim in the new "Hardened by default" sections and SECURITY.md matches the actual repo/workflow state — I did not find any new overstatement. Two residual items are worth the author's attention, neither of which is a defect introduced by this PR:

  1. Branch protection (required checks/approvals/signatures) remains unverifiable from here — I have no network access in this environment, so I can't independently confirm it the way the author's pasted gh api output claims. This isn't a finding against the PR; it's a limitation of this review pass.
  2. bestax-migrate is advertised as hardened/supported while #412 (unresolved workspace:^) is still open on an unmerged branch — every claim about it is individually true, but the overall impression (safe to install) is currently inaccurate for that one package. Advisory-level, not blocking, and arguably belongs in a follow-up rather than this PR.

Since this PR is already merged, there's nothing to implement here — this is a verification pass only, as requested.

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 4.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 2.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 5.8.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Docs] Advertise our supply-chain hardening — Socket.dev + provenance badges and a "Hardened by default" README section

1 participant