Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 23 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@
[![Coverage](https://img.shields.io/badge/coverage-99%25-brightgreen.svg)](https://github.com/allxsmith/bestax/blob/main/bulma-ui/jest.config.js)
[![Bulma](https://img.shields.io/badge/Bulma-v1.0+-00d1b2.svg)](https://bulma.io)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Socket Badge](https://socket.dev/api/badge/npm/package/@allxsmith/bestax-bulma)](https://socket.dev/npm/package/@allxsmith/bestax-bulma/overview)
[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/allxsmith/bestax/badge)](https://scorecard.dev/viewer/?uri=github.com/allxsmith/bestax)
[![npm provenance](https://img.shields.io/badge/npm-provenance-3fb950.svg)](https://www.npmjs.com/package/@allxsmith/bestax-bulma#provenance)
[![Security policy](https://img.shields.io/badge/security-policy-blue.svg)](https://github.com/allxsmith/bestax/blob/main/SECURITY.md)

TypeScript-first React component library for the **Bulma v1** CSS framework β€” 80+ fully typed components β€” plus a project scaffolder and AI agent tooling.

Expand Down Expand Up @@ -173,6 +177,25 @@ Building with an AI agent (Claude Code, Cursor, Copilot)? bestax-bulma ships LLM

---

## πŸ”’ Hardened by default

Supply-chain security here is a standing constraint on how the project is built, not a checklist we filled in once:

- **Signed provenance on every release** β€” each tarball carries a sigstore attestation linking it to the exact commit and CI run that produced it. Check it yourself with `npm audit signatures`, or on the package page's Provenance section.
- **npm OIDC trusted publishing** β€” releases authenticate with short-lived, per-run tokens. There is no long-lived `NPM_TOKEN` in this repo to steal.
- **Signed release commits** β€” release commits and tags are GPG-signed, and `main` rejects unsigned commits outright.
- **Socket.dev scans every PR** β€” dependency changes are checked for malware, install scripts, obfuscated code, and privilege escalation before they can reach `main`.
- **Every GitHub Action pinned to a full commit SHA** β€” no movable tags, so a compromised action release can't roll silently into the pipeline.
- **Install scripts blocked by default** β€” dependency `install`/`postinstall` scripts don't run unless explicitly allow-listed one at a time, each with a written rationale ([`pnpm-workspace.yaml`](pnpm-workspace.yaml)).
- **3-day dependency cooldown** β€” freshly published versions won't install. This is the main defense against account-takeover worms, which are usually yanked within hours.
- **Frozen lockfile + audit gate** β€” CI installs exactly what the reviewed lockfile resolves and fails on high-severity advisories.
- **CodeQL, Dependency Review, and Dependabot** β€” static analysis over both the source and the workflow files, PR-level advisory blocking, and weekly grouped dependency updates.
- **Layered AI review before merge** β€” every PR gets a [CodeRabbit](https://coderabbit.ai) review plus an independent adversarial Claude review that deliberately runs a different model from the one writing AI-authored changes. On top of that, `main` requires green CI, one approving review, and a human merge. AI agents are structurally barred from editing the workflows, release config, or supply-chain settings that gate them.

Full detail: [`SECURITY.md`](SECURITY.md) Β· [Security guide](https://bestax.io/docs/guides/security)

---

## πŸ’¬ Community

- [Discord](https://discord.gg/zehJrQGtKu)
Expand Down
37 changes: 29 additions & 8 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,15 +3,16 @@
## Supported Versions

Security fixes land on the **latest release line only** β€” currently
`@allxsmith/bestax-bulma` 5.x and `create-bestax` 3.x. Both packages release
automatically from `main` (semantic-release), so the latest published version
is always the patched one. Older majors may still work but receive no security
updates; please upgrade.
`@allxsmith/bestax-bulma` 5.x, `create-bestax` 3.x, and `bestax-migrate` 1.x.
All three packages release automatically from `main` (semantic-release), so the
latest published version is always the patched one. Older majors may still work
but receive no security updates; please upgrade.

| Package | Supported | Unsupported |
| ------------------------- | ------------ | ----------- |
| `@allxsmith/bestax-bulma` | 5.x (latest) | < 5.0 |
| `create-bestax` | 3.x (latest) | < 3.0 |
| `bestax-migrate` | 1.x (latest) | β€” |

## Supply-Chain Security

Expand All @@ -22,28 +23,48 @@ Measures active in this repository and its release pipeline:
(`allowBuilds` in `pnpm-workspace.yaml`).
- **Dependency cooldown** β€” by default, versions published less than 3 days
ago won't install (`minimumReleaseAge`), defending against just-published
malicious releases. One dev-only exception: `prettier` is excluded (and
pinned) so formatting stays deterministic; it is never shipped to users.
malicious releases. Exceptions are listed in `minimumReleaseAgeExclude` and
are the deliberate minority: `prettier` is excluded (and pinned) so
formatting stays deterministic and is never shipped to users, and an
individual package may be excluded temporarily to pull an urgent security
patch in ahead of the cooldown β€” each such entry carries an inline rationale
and a removal date.
- **Isolated `node_modules`** β€” pnpm's isolated linker prevents phantom
(undeclared) dependencies from being imported.
- **Frozen lockfile in CI** β€” builds and releases install with
`pnpm install --frozen-lockfile`, so what ships is exactly what the
reviewed lockfile resolves. (The React 18/19 compatibility matrix is the
one deliberate exception: it re-resolves to pin the requested React major
for testing, and never publishes.)
- **npm provenance** β€” both published packages set
- **npm provenance** β€” all three published packages set
`publishConfig.provenance`, so every release carries a signed attestation
linking the tarball to the exact commit and CI run that built it.
- **OIDC trusted publishing** β€” releases authenticate to npm with
short-lived OIDC tokens minted per run; there is no long-lived `NPM_TOKEN`
to steal.
- **SHA-pinned GitHub Actions** β€” every third-party action is pinned to a
full commit SHA, not a movable tag.
- **Socket.dev** β€” the Socket GitHub App reviews every pull request for
malware, install scripts, obfuscated code, and privilege escalation in
dependency changes, and posts two checks on every pull request. Its policy
is managed in the Socket dashboard rather than in this repository, so it has
no config file here.
- **CodeQL** β€” GitHub code scanning runs on JavaScript/TypeScript and the
workflow files themselves.
workflow files themselves. It uses GitHub's _default setup_, so there is no
`codeql.yml` in `.github/workflows/`.
- **OpenSSF Scorecard** β€” `.github/workflows/scorecard.yml` scores this
repository's supply-chain posture weekly and publishes the result publicly.
- **Dependency review** β€” a workflow blocks PRs that introduce dependencies
with known advisories.
- **Dependabot** β€” weekly, grouped dependency update PRs.
- **Protected `main`** β€” unsigned commits, force pushes, and branch deletion
are rejected. Merges require green CI (`Build and Test`, the React 18/19
compatibility matrix, and `Dependency Review`) plus an approving review.
- **Layered automated review** β€” every PR is reviewed by CodeRabbit and by an
independent adversarial Claude review that deliberately runs a different
model from the one used to write AI-authored changes. AI agents working in
this repository are barred from modifying the workflows, release
configuration, or supply-chain settings that gate them.

Consumers can verify provenance themselves: the npm package pages show the
attestation ("Provenance" section), and β€” in projects installed with the npm
Expand Down
22 changes: 22 additions & 0 deletions bestax-migrate/README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,13 @@
# bestax-migrate

[![npm version](https://img.shields.io/npm/v/bestax-migrate.svg)](https://www.npmjs.com/package/bestax-migrate)
[![npm downloads](https://img.shields.io/npm/dm/bestax-migrate.svg)](https://www.npmjs.com/package/bestax-migrate)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Socket Badge](https://socket.dev/api/badge/npm/package/bestax-migrate)](https://socket.dev/npm/package/bestax-migrate/overview)
[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/allxsmith/bestax/badge)](https://scorecard.dev/viewer/?uri=github.com/allxsmith/bestax)
[![npm provenance](https://img.shields.io/badge/npm-provenance-3fb950.svg)](https://www.npmjs.com/package/bestax-migrate#provenance)
[![Security policy](https://img.shields.io/badge/security-policy-blue.svg)](https://github.com/allxsmith/bestax/blob/main/SECURITY.md)

Codemods that migrate existing React apps to [`@allxsmith/bestax-bulma`](https://www.npmjs.com/package/@allxsmith/bestax-bulma) β€” the actively maintained React component library for **Bulma v1**.

Currently supported source libraries:
Expand Down Expand Up @@ -54,6 +62,20 @@ npx skills add https://github.com/allxsmith/bestax --skill bestax-migrate

Full walkthrough: [react-bulma-components migration guide](https://bestax.io/docs/guides/getting-started/migration/react-bulma-components).

## Hardened by default

A codemod rewrites your source in place, so how it is built and published matters:

- **Signed provenance** β€” every release carries a sigstore attestation linking the tarball to the exact commit and CI run that built it. Check the **Provenance** section on the [npm page](https://www.npmjs.com/package/bestax-migrate#provenance), or run `npm audit signatures`.
- **npm OIDC trusted publishing** β€” short-lived, per-run credentials; no long-lived `NPM_TOKEN` exists to be stolen. Release commits and tags are GPG-signed.
- **Socket.dev scans every PR** for malware, install scripts, obfuscated code, and privilege escalation before it can reach `main`.
- **The libraries this tool migrates away from are never installed here** β€” source fixtures are read as text only, so no unmaintained third-party package enters the dependency tree.
- **Dependencies are a deliberate act** β€” install scripts are blocked unless individually allow-listed, freshly published versions are refused for 3 days, and CI installs only what the reviewed lockfile resolves.
- **Every GitHub Action is pinned to a full commit SHA**, and CodeQL, Dependency Review, and Dependabot run continuously alongside a high-severity `pnpm audit` gate.
- **Layered AI review before merge** β€” [CodeRabbit](https://coderabbit.ai) plus an independent adversarial Claude review (a different model from the one writing AI-authored changes), on top of required green CI, an approving review, and a human merge.

Full detail: [`SECURITY.md`](https://github.com/allxsmith/bestax/blob/main/SECURITY.md) Β· [Security guide](https://bestax.io/docs/guides/security)

## License

MIT Β© Alex Smith
20 changes: 20 additions & 0 deletions bulma-ui/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,10 @@
[![Coverage](https://img.shields.io/badge/coverage-99%25-brightgreen.svg)](https://github.com/allxsmith/bestax/blob/main/bulma-ui/jest.config.js)
[![Bulma](https://img.shields.io/badge/Bulma-v1.0+-00d1b2.svg)](https://bulma.io)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Socket Badge](https://socket.dev/api/badge/npm/package/@allxsmith/bestax-bulma)](https://socket.dev/npm/package/@allxsmith/bestax-bulma/overview)
[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/allxsmith/bestax/badge)](https://scorecard.dev/viewer/?uri=github.com/allxsmith/bestax)
[![npm provenance](https://img.shields.io/badge/npm-provenance-3fb950.svg)](https://www.npmjs.com/package/@allxsmith/bestax-bulma#provenance)
[![Security policy](https://img.shields.io/badge/security-policy-blue.svg)](https://github.com/allxsmith/bestax/blob/main/SECURITY.md)

TypeScript-first React component library for the **Bulma v1** CSS framework β€” 80+ fully typed, tree-shakeable components, including extras like Carousel, Dialog, Sidebar, Steps, and date/time pickers.

Expand Down Expand Up @@ -124,6 +128,22 @@ View the package on npmjs:

---

## πŸ”’ Hardened by default

This package is one runtime dependency deep (Bulma) and is published under a deliberately strict pipeline:

- **Signed provenance** β€” every release carries a sigstore attestation linking the tarball to the exact commit and CI run that built it. Verify it in the **Provenance** section of the [npm page](https://www.npmjs.com/package/@allxsmith/bestax-bulma#provenance), or run `npm audit signatures` in your project.
- **npm OIDC trusted publishing** β€” short-lived, per-run credentials; no long-lived `NPM_TOKEN` exists to be stolen. Release commits and tags are GPG-signed.
- **Socket.dev scans every PR** for malware, install scripts, obfuscated code, and privilege escalation before it can reach `main`.
- **Dependencies are a deliberate act** β€” install scripts are blocked unless individually allow-listed, freshly published versions are refused for 3 days, and CI installs only what the reviewed lockfile resolves.
- **Every GitHub Action is pinned to a full commit SHA**, so a compromised action release can't roll silently into a build of this package.
- **CodeQL, Dependency Review, and Dependabot** run continuously, alongside a high-severity `pnpm audit` gate.
- **Layered AI review before merge** β€” [CodeRabbit](https://coderabbit.ai) plus an independent adversarial Claude review (a different model from the one writing AI-authored changes), on top of required green CI, an approving review, and a human merge.

Full detail: [`SECURITY.md`](https://github.com/allxsmith/bestax/blob/main/SECURITY.md) Β· [Security guide](https://bestax.io/docs/guides/security)

---

## πŸ“š Documentation

**For full documentation, guides, and best practices, please use our official docs site:**
Expand Down
18 changes: 18 additions & 0 deletions create-bestax/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@
[![npm version](https://img.shields.io/npm/v/create-bestax.svg)](https://www.npmjs.com/package/create-bestax)
[![npm downloads](https://img.shields.io/npm/dm/create-bestax.svg)](https://www.npmjs.com/package/create-bestax)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Socket Badge](https://socket.dev/api/badge/npm/package/create-bestax)](https://socket.dev/npm/package/create-bestax/overview)
[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/allxsmith/bestax/badge)](https://scorecard.dev/viewer/?uri=github.com/allxsmith/bestax)
[![npm provenance](https://img.shields.io/badge/npm-provenance-3fb950.svg)](https://www.npmjs.com/package/create-bestax#provenance)
[![Security policy](https://img.shields.io/badge/security-policy-blue.svg)](https://github.com/allxsmith/bestax/blob/main/SECURITY.md)

The scaffolder for [`@allxsmith/bestax-bulma`](https://www.npmjs.com/package/@allxsmith/bestax-bulma) β€” spin up a Vite app pre-wired for the **Bulma v1** React component library in one command. Picks your framework (JS or TypeScript), CSS flavor, and icon library, and can drop in the bestax **AI skills** so an agent like Claude Code knows the library from the first prompt.

Expand Down Expand Up @@ -127,6 +131,20 @@ npm run typecheck # Type check CLI source code

**Note on Templates:** Template files in `templates/` are excluded from linting. They should be manually validated by scaffolding a test project and running lint/build there before releasing.

## Hardened by default

A scaffolder runs with write access to your filesystem and picks your starting dependencies, so how it is built and published matters:

- **Signed provenance** β€” every release carries a sigstore attestation linking the tarball to the exact commit and CI run that built it. Check the **Provenance** section on the [npm page](https://www.npmjs.com/package/create-bestax#provenance), or run `npm audit signatures`.
- **npm OIDC trusted publishing** β€” short-lived, per-run credentials; no long-lived `NPM_TOKEN` exists to be stolen. Release commits and tags are GPG-signed.
- **Socket.dev scans every PR** for malware, install scripts, obfuscated code, and privilege escalation before it can reach `main`.
- **Dependencies are a deliberate act** β€” install scripts are blocked unless individually allow-listed, freshly published versions are refused for 3 days, and CI installs only what the reviewed lockfile resolves.
- **Every GitHub Action is pinned to a full commit SHA**, so a compromised action release can't roll silently into a build of this CLI.
- **CodeQL, Dependency Review, and Dependabot** run continuously, alongside a high-severity `pnpm audit` gate.
- **Layered AI review before merge** β€” [CodeRabbit](https://coderabbit.ai) plus an independent adversarial Claude review (a different model from the one writing AI-authored changes), on top of required green CI, an approving review, and a human merge.

Full detail: [`SECURITY.md`](https://github.com/allxsmith/bestax/blob/main/SECURITY.md) Β· [Security guide](https://bestax.io/docs/guides/security)

## Publishing

This package uses semantic-release with scope-based rules. Only commits with `feat(create-bestax)` or `fix(create-bestax)` will trigger releases.
Loading