From 7f4d9c124df7d6703d730cc0a747da454f3ec1c9 Mon Sep 17 00:00:00 2001 From: TheStreamCode Date: Tue, 22 Sep 2026 20:05:38 +0200 Subject: [PATCH 1/2] chore: fleet hygiene (community files, CI hardening, dependabot) Add SECURITY.md (supported versions, private report path, and the subscription-key rotation story), CONTRIBUTING.md, CODE_OF_CONDUCT.md (sibling Covenant text), and issue + PR templates. Harden CI to the fleet standard: npm ci, Node 20/22/24 matrix, SHA-pinned actions, permissions: contents: read. Add grouped-weekly dependabot.yml (npm + github-actions). Closes the review P0 and P1 file items for opencode-muse-auth. --- .github/ISSUE_TEMPLATE/bug_report.md | 27 +++++++++++++++++ .github/ISSUE_TEMPLATE/config.yml | 5 ++++ .github/ISSUE_TEMPLATE/feature_request.md | 18 ++++++++++++ .github/dependabot.yml | 30 +++++++++++++++++++ .github/pull_request_template.md | 14 +++++++++ .github/workflows/ci.yml | 15 +++++++--- CODE_OF_CONDUCT.md | 35 +++++++++++++++++++++++ CONTRIBUTING.md | 21 ++++++++++++++ SECURITY.md | 23 +++++++++++++++ 9 files changed, 184 insertions(+), 4 deletions(-) create mode 100644 .github/ISSUE_TEMPLATE/bug_report.md create mode 100644 .github/ISSUE_TEMPLATE/config.yml create mode 100644 .github/ISSUE_TEMPLATE/feature_request.md create mode 100644 .github/dependabot.yml create mode 100644 .github/pull_request_template.md create mode 100644 CODE_OF_CONDUCT.md create mode 100644 CONTRIBUTING.md create mode 100644 SECURITY.md diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..9404741 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,27 @@ +--- +name: Bug report +about: Report a problem with the Muse subscription auth plugin +title: "[bug] " +labels: bug +--- + +## What happened + +A clear description of the bug. + +## How to reproduce + +- opencode version + plugin version (pinned or floating): +- Auth step (`/connect` output, redacted — never paste a real key): +- Cache state (`~/.config/opencode/muse-code-sub.json` present/stale/missing): + +## Expected vs actual + +- Expected: +- Actual (include error output, redacted): + +## Environment + +- opencode-muse-auth version: +- Node.js version: +- OS: diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..b0f32cd --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,5 @@ +blank_issues_enabled: false +contact_links: + - name: Questions and support + url: https://github.com/TheStreamCode/opencode-muse-auth/discussions + about: Ask usage questions in GitHub Discussions diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..c57538d --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,18 @@ +--- +name: Feature request +about: Suggest an improvement or new capability +title: "[feat] " +labels: enhancement +--- + +## Problem / motivation + +What are you trying to do that's hard or impossible today? + +## Proposed solution + +What you'd like to see. + +## Alternatives considered + +## Additional context diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..aa561e8 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,30 @@ +version: 2 +updates: + - package-ecosystem: "npm" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + labels: + - "dependencies" + groups: + npm-minor-patch: + update-types: + - "minor" + - "patch" + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + labels: + - "dependencies" + - "github-actions" + commit-message: + prefix: "chore(actions)" + include: "scope" + groups: + actions-minor-patch: + update-types: + - "minor" + - "patch" diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md new file mode 100644 index 0000000..6b03ee8 --- /dev/null +++ b/.github/pull_request_template.md @@ -0,0 +1,14 @@ +## Summary + +What does this PR change and why? + +## How verified + +- [ ] `npm run build` passes +- [ ] `npm test` passes (Node 20/22/24 via CI) +- [ ] Added/updated tests for the change + +## Notes + +- Any new dependency? Why existing ones weren't enough: +- No secrets/API keys committed; subscription key never printed or logged. diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d04c3a0..05269b9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,14 +4,21 @@ on: push: pull_request: +permissions: + contents: read + jobs: build-test: runs-on: ubuntu-latest + strategy: + matrix: + node: [20, 22, 24] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: - node-version: "24" - - run: npm install + node-version: ${{ matrix.node }} + cache: npm + - run: npm ci - run: npm run build - run: npm test diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..197e304 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,35 @@ +# Code of Conduct + +## Our pledge + +We as members, contributors, and maintainers pledge to make participation in this project a +harassment-free experience for everyone, regardless of age, body size, visible or invisible +disability, ethnicity, sex characteristics, gender identity and expression, level of experience, +education, socio-economic status, nationality, personal appearance, race, religion, or sexual +identity and orientation. + +## Our standards + +Examples of behavior that contributes to a positive environment: + +- Being respectful of differing opinions, viewpoints, and experiences. +- Giving and gracefully accepting constructive feedback. +- Focusing on what is best for the community. +- Showing empathy toward other community members. + +Unacceptable behavior includes: + +- Harassment, insults, or derogatory comments, and personal or political attacks. +- Publishing others' private information without explicit permission. +- Other conduct which could reasonably be considered inappropriate in a professional setting. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the project +maintainer (see `package.json`). All complaints will be reviewed and investigated promptly and +fairly. Maintainers are obligated to respect the privacy and security of the reporter. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org), +version 2.1. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..03c0361 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,21 @@ +# Contributing to opencode-muse-auth + +Thanks for your interest in improving this project! Bug reports, fixes, docs, +and tests are all welcome. + +## Development setup + +```bash +npm ci +npm run build +npm test +``` + +CI repeats the same gate on Node 20, 22, and 24. + +## Pull requests + +- Keep changes focused; one concern per PR. +- Add or update tests for behavior changes. +- Never commit API keys, tokens, subscription keys, or account data. +- Never print or log the cached subscription key in code or fixtures. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..71d4b62 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +# Security Policy + +## Supported versions + +Security fixes target the latest published release and the current `main` branch. + +## Reporting a vulnerability + +This plugin mints account-bound credentials. Report security issues privately: +use GitHub's **private vulnerability reporting** (Security Advisories) on this +repository. If that route is unavailable, email `info@mikesoft.it` with the +subject `opencode-muse-auth Security Report`. Do not open a public issue for +sensitive findings. + +## Credential handling + +The Muse subscription key is cached owner-only at +`~/.config/opencode/muse-code-sub.json`. It is never re-minted while valid, +never printed, and never logged. Never commit keys, tokens, or account data to +this repository, and never paste real credentials into issues, pull requests, +or test fixtures. + +On a `401`, delete the cached file and re-run `/connect` to mint a fresh key. From a0509dc984076e927cfeac0ce936a227861dc813 Mon Sep 17 00:00:00 2001 From: TheStreamCode Date: Tue, 22 Sep 2026 20:34:41 +0200 Subject: [PATCH 2/2] fix(ci): drop Node 20 from matrix, self-sufficient npm test Node 20's test runner treats the quoted tests/*.test.ts glob literally ('Could not find ... tests/*.test.ts'): glob support landed in Node 21, and Node 20 cannot execute the TypeScript suite at all (type-stripping needs 22.6+, default-on in late 22.x). Matrix is now [22, 24]. Add pretest -> build so bare 'npm test' works on a fresh clone: tests/auth.test.ts imports ../dist/auth.js (compiled output) and failed with ERR_MODULE_NOT_FOUND without a prior build. No new test file: tests/auth.test.ts already covers real shim logic (cache roundtrip/miss, deviceAuthorize field validation, pollToken pending->success + terminal errors, mintKey subscription/payment validation) - 6/6 passing. --- .github/workflows/ci.yml | 5 ++++- package.json | 1 + 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 05269b9..4635a7d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -10,9 +10,12 @@ permissions: jobs: build-test: runs-on: ubuntu-latest + # Node 20 excluded: `node --test "tests/*.test.ts"` needs test-runner glob + # support (Node 21+) and TS type-stripping (Node 22.6+, default-on in late + # 22.x). The suite is TypeScript importing compiled dist output. strategy: matrix: - node: [20, 22, 24] + node: [22, 24] steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 diff --git a/package.json b/package.json index ae2bc95..52d0512 100644 --- a/package.json +++ b/package.json @@ -34,6 +34,7 @@ ], "scripts": { "build": "tsc", + "pretest": "npm run build", "test": "node --test --test-concurrency=1 \"tests/*.test.ts\"", "prepublishOnly": "npm run build" },