Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .goreleaser.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,7 @@ archives:
{{- if eq .Os "darwin" }}macOS{{ else }}{{ .Os }}{{ end }}_{{ .Arch }}
files:
- README.md
- SECURITY.md
- LICENSE*

checksum:
Expand Down
7 changes: 5 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,9 @@ StarCLI is a versatile tool that provides a convenient environment for running S

Download the archive for your system and `checksums.txt` from the same
[GitHub Release](https://github.com/1set/starcli/releases). No Go installation is
needed to run a release binary.
needed to run a release binary. Starting with v0.1.3, each archive includes the README, license, and
[security policy](SECURITY.md), including the supported execution boundary and
private vulnerability reporting instructions.

| System | Architecture | Archive suffix |
|---|---|---|
Expand Down Expand Up @@ -423,7 +425,8 @@ Contributions are welcome! Please feel free to submit a Pull Request.

## Contact

For any questions or support, please open an issue on [GitHub](https://github.com/1set/starcli/issues).
For ordinary bugs, questions, or support, please open an issue on [GitHub](https://github.com/1set/starcli/issues).
For vulnerabilities, follow the private reporting instructions in [SECURITY.md](SECURITY.md).

### HTTP execution limits

Expand Down
40 changes: 40 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# Security policy

## Reporting a vulnerability

Please use [GitHub private vulnerability reporting](https://github.com/1set/starcli/security/advisories/new)
for security issues. Include the affected version or commit, operating system
and architecture, relevant capability grants and configuration, and a minimal
reproduction with the expected and actual behavior. For source builds, include
the Go version. Use synthetic data and remove credentials from scripts, logs,
and session recordings before sharing them.

Use public issues for ordinary bugs and support. There is no guaranteed
response time; keep vulnerability details private while coordinating a fix.

## Supported versions

Security fixes target the latest release through patch updates. Older releases
are not maintained as separate security branches. Review release notes for
behavior changes before upgrading, and keep a known working binary for rollback.

The `go.mod` version is a compatibility floor. Build production binaries with
a supported Go toolchain containing the latest security fixes, or use the
prebuilt release binaries. See the README for checksum and provenance checks.

## Execution boundary

StarCLI is intended for host-selected, reviewed scripts in a controlled,
single-tenant environment. Capability grants limit available operations; they
do not provide process or memory isolation. The default `open` tier permits
network and filesystem access. `--allow-cmd` authorizes arbitrary host commands
and process environment access, including through `gum` and `runtime`.

Use the narrowest capability grants and import directories that your script
needs. HTTP execution has request and cooperative execution limits, but these
do not preempt arbitrary Go builtins or impose a complete output-byte budget.
Untrusted scripts or public multi-tenant services need a separate constrained
worker, resource limits, and an independent security review.

Treat transcripts from `--record` as sensitive output: they can include input,
results, and errors. Control their access and retention at the host level.
8 changes: 6 additions & 2 deletions e2e/verify-release.py
Original file line number Diff line number Diff line change
Expand Up @@ -75,8 +75,12 @@ def verify_archives(directory, version, *, native_only=False):
if member.name == binary and not member.mode & 0o111:
raise ValueError(f"binary is not executable: {name}")
members[member.name] = package.extractfile(member).read()
if members.keys() != {binary, "README.md", "LICENSE"} or not all(members.values()):
raise ValueError(f"archive must contain only a binary, README and license: {name}")
required_members = {binary, "README.md", "LICENSE", "SECURITY.md"}
# The immutable rollback baseline predates the packaged security policy.
if version == "0.1.2":
required_members.remove("SECURITY.md")
if members.keys() != required_members or not all(members.values()):
raise ValueError(f"archive must contain exactly {sorted(required_members)}: {name}")
if (system, arch) == target:
native_binary = members[binary]
print(f"verified {name}", flush=True)
Expand Down
Loading