From dd73abe00fb0847bd71981330e7ee9d6cf0d19cb Mon Sep 17 00:00:00 2001 From: Lukas Geiger Date: Sat, 3 Oct 2026 23:43:42 +0200 Subject: [PATCH] docs: correct project-scoped security and activity claims --- README.md | 3 ++- SECURITY.md | 8 +++++--- llms.txt | 9 ++++++--- profile/README.md | 10 +++++----- profile/README_de.md | 10 +++++----- tests/test_profile_parity.py | 26 +++++++++++++++----------- 6 files changed, 38 insertions(+), 28 deletions(-) diff --git a/README.md b/README.md index 0703b08..71c3013 100644 --- a/README.md +++ b/README.md @@ -40,12 +40,13 @@ Last checked: 2026-10-01. Public-only list from live GitHub metadata; private or | [DevCenter](https://github.com/dev-bricks/DevCenter) | 2026-09-30 | Local-first developer dashboard and IDE | | [app-rotator](https://github.com/dev-bricks/app-rotator) | 2026-09-29 | Desktop app time-slicing and VRAM governance | | [CareCenter-for-Codex](https://github.com/dev-bricks/CareCenter-for-Codex) | 2026-09-29 | Codex Desktop repair and diagnostics | -| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | 2026-09-29 | Conservative orphan-process cleanup for MCP/language servers | +| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | 2026-10-03 | Conservative orphan-process cleanup for MCP/language servers | | [WikiStub-Seed](https://github.com/dev-bricks/WikiStub-Seed) | 2026-09-28 | Structured JSON/Markdown knowledge stubs | | [ApiProber](https://github.com/dev-bricks/ApiProber) | 2026-09-22 | Authorized API inventory and OpenAPI discovery | | [pythonbox](https://github.com/dev-bricks/pythonbox) | 2026-09-22 | Lightweight local Python IDE | | [automizer-for-claude-desktop](https://github.com/dev-bricks/automizer-for-claude-desktop) | 2026-09-21 | Claude Desktop scheduled-task automation | | [fable-5-hunter](https://github.com/dev-bricks/fable-5-hunter) *(archived)* | 2026-06-25 | Claude Fable 5 availability watcher | +**Targeted update:** Zombie-Killer-Tray reflects a targeted main-branch readback on 2026-10-03; other activity rows retain the 2026-10-01 snapshot. ### Integrated ellmos-ai Infrastructure diff --git a/SECURITY.md b/SECURITY.md index c52f761..3461109 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -12,6 +12,8 @@ If you discover a security vulnerability or security concern within any reposito - `lukas@open-bricks.org` - `support@lukasgeiger.com` +Project-specific SECURITY policies govern the repositories they cover. For a report about a product repository, consult that repository's current policy for its response commitments. + --- ## Response Timeline / Reaktionszeit @@ -33,6 +35,6 @@ If you discover a security vulnerability or security concern within any reposito ## Security Invariants / Sicherheitsinvarianten -- **Zero-Egress & Local-First:** All developer tools, static analyzers, and desktop apps run locally on the developer machine by default with zero unconsented telemetry or outbound data egress. -- **Unprivileged User Mode (Non-Elevation):** dev-bricks desktop applications and tray utilities run as normal user processes without requesting administrator elevation. -- **Conservative Process Management:** Process management tools such as `zombie-killer-tray` and `app-rotator` use strict parent-PID validation and heartbeat checks without performing indiscriminate process-tree kills. +- **Network, telemetry, and data behavior:** These properties vary by repository and are described in its current documentation and SECURITY policy; no blanket zero-egress guarantee applies to every linked project. +- **Privilege requirements:** Requirements depend on the repository and workflow. The Zombie-Killer-Tray tray launcher can request UAC elevation for termination workflows; see its project documentation. +- **Process management:** Safeguards vary by tool. Zombie-Killer-Tray validates sampled process identity, CPU ticks, and parent state before individual termination attempts; see each project's documented limits. diff --git a/llms.txt b/llms.txt index d216979..e1d3a63 100644 --- a/llms.txt +++ b/llms.txt @@ -8,7 +8,8 @@ Canonical organization: https://github.com/dev-bricks Organization profile repository: https://github.com/dev-bricks/.github Ecosystem: open-bricks, file-bricks, doc-bricks, ellmos-ai Public repository count: 13 total, including 11 active tool repositories, 1 archived tool repository (fable-5-hunter), and this organization profile repository. Public-only index; private or internal work is intentionally excluded. -Recent public activity snapshot from the public GitHub API, newest first: .github 2026-10-01, MethodenAnalyser 2026-09-30, safe-start-for-codex 2026-09-30, CodeBox 2026-09-30, DevCenter 2026-09-30, app-rotator 2026-09-29, CareCenter-for-Codex 2026-09-29, zombie-killer-tray 2026-09-29, WikiStub-Seed 2026-09-28, ApiProber 2026-09-22, pythonbox 2026-09-22, automizer-for-claude-desktop 2026-09-21, and archived fable-5-hunter 2026-06-25. +Recent public activity snapshot from the public GitHub API, newest first: zombie-killer-tray 2026-10-03 (targeted main-branch readback), .github 2026-10-01, MethodenAnalyser 2026-09-30, safe-start-for-codex 2026-09-30, CodeBox 2026-09-30, DevCenter 2026-09-30, app-rotator 2026-09-29, CareCenter-for-Codex 2026-09-29, WikiStub-Seed 2026-09-28, ApiProber 2026-09-22, pythonbox 2026-09-22, automizer-for-claude-desktop 2026-09-21, and archived fable-5-hunter 2026-06-25. +Targeted update: Zombie-Killer-Tray reflects a targeted main-branch readback on 2026-10-03; remaining activity dates retain the 2026-10-01 snapshot. ## Positioning @@ -66,7 +67,7 @@ The projects are intended for developers who want small, inspectable, local appl - https://github.com/dev-bricks/zombie-killer-tray - Conservative Windows tray utility for cleaning up orphaned Model Context Protocol (MCP) and language-server processes. - - Verifies process incarnation, dead-parent state, and zero CPU delta across multiple samples before terminating; never performs blanket process-tree kills. + - Verifies process identity and dead-parent state, and requires equal CPU tick readings across sampled observations before termination; never performs blanket process-tree kills. - https://github.com/dev-bricks/fable-5-hunter - Zero-dependency availability watcher for the Claude Fable 5 model in the Claude Code CLI (archived). @@ -75,13 +76,15 @@ The projects are intended for developers who want small, inspectable, local appl ## Current public activity +- 2026-10-03: `zombie-killer-tray` (targeted main-branch readback) - 2026-10-01: `.github` - 2026-09-30: MethodenAnalyser, safe-start-for-codex, CodeBox, DevCenter -- 2026-09-29: app-rotator, CareCenter-for-Codex, `zombie-killer-tray` +- 2026-09-29: app-rotator, CareCenter-for-Codex - 2026-09-28: WikiStub-Seed - 2026-09-22: ApiProber, pythonbox - 2026-09-21: automizer-for-claude-desktop - 2026-06-25: `fable-5-hunter` (archived) +> **Targeted update:** Zombie-Killer-Tray reflects a targeted main-branch readback on 2026-10-03; other activity dates retain the 2026-10-01 snapshot. ## Integrated ellmos-ai Multi-Agent Infrastructure diff --git a/profile/README.md b/profile/README.md index 232e502..0d2ad2c 100644 --- a/profile/README.md +++ b/profile/README.md @@ -2,8 +2,7 @@

Active Public Repos Local First - License - Security SLA + Security Policy Verified 2026-10-01 llms.txt German Version @@ -60,7 +59,7 @@ dev-bricks builds small, practical tools for software-development workflows: edi | [app-rotator](https://github.com/dev-bricks/app-rotator) | Windows tray application that time-slices resource-heavy desktop apps: runs exactly one configured app at a time, closes it after its slot, and continues in configured order (MIT) | | [automizer-for-claude-desktop](https://github.com/dev-bricks/automizer-for-claude-desktop) | Unofficial tool for reliably creating and changing planned Claude Desktop tasks from inside the app, from outside it, or while the app is closed | | [CareCenter-for-Codex](https://github.com/dev-bricks/CareCenter-for-Codex) | Local Windows tray and CLI for OpenAI Codex Desktop repair, cleanup, diagnostics, and safe maintenance | -| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | Conservative Windows tray utility for safely cleaning up orphaned Model Context Protocol (MCP) and language-server processes without blanket process-tree kills | +| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | Conservative Windows tray utility for cleaning up selected orphaned MCP and language-server processes one at a time, without blanket process-tree termination | | [fable-5-hunter](https://github.com/dev-bricks/fable-5-hunter) *(archived)* | Zero-dependency watcher that polls the Claude Code CLI for Claude Fable 5 and notifies you the moment it is reachable again — via Telegram, Discord, ntfy, desktop toast, or file fallback | | [.github](https://github.com/dev-bricks/.github) | Organization profile, shared issue templates, community workflows, security policy, contribution guidance, and machine-readable repository context | @@ -68,6 +67,7 @@ dev-bricks builds small, practical tools for software-development workflows: edi | Repository | Latest public push | Focus | |---|---:|---| +| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | 2026-10-03 | Conservative orphan-process cleanup for MCP/language servers | | [.github](https://github.com/dev-bricks/.github) | 2026-10-01 | Organization profile and public directory parity | | [MethodenAnalyser](https://github.com/dev-bricks/MethodenAnalyser) | 2026-09-30 | Static Python code analysis | | [safe-start-for-codex](https://github.com/dev-bricks/safe-start-for-codex) | 2026-09-30 | Codex Desktop startup gating | @@ -75,12 +75,12 @@ dev-bricks builds small, practical tools for software-development workflows: edi | [DevCenter](https://github.com/dev-bricks/DevCenter) | 2026-09-30 | Local-first developer dashboard and IDE | | [app-rotator](https://github.com/dev-bricks/app-rotator) | 2026-09-29 | Desktop app time-slicing and VRAM governance | | [CareCenter-for-Codex](https://github.com/dev-bricks/CareCenter-for-Codex) | 2026-09-29 | Codex Desktop repair and diagnostics | -| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | 2026-09-29 | Conservative orphan-process cleanup for MCP/language servers | | [WikiStub-Seed](https://github.com/dev-bricks/WikiStub-Seed) | 2026-09-28 | Structured JSON/Markdown knowledge stubs | | [ApiProber](https://github.com/dev-bricks/ApiProber) | 2026-09-22 | Authorized API inventory and OpenAPI discovery | | [pythonbox](https://github.com/dev-bricks/pythonbox) | 2026-09-22 | Lightweight local Python IDE | | [automizer-for-claude-desktop](https://github.com/dev-bricks/automizer-for-claude-desktop) | 2026-09-21 | Claude Desktop scheduled-task automation | | [fable-5-hunter](https://github.com/dev-bricks/fable-5-hunter) *(archived)* | 2026-06-25 | Claude Fable 5 availability watcher | +**Targeted update:** Zombie-Killer-Tray reflects a targeted main-branch readback on 2026-10-03; other activity rows retain the 2026-10-01 snapshot. ### Integrated ellmos-ai Infrastructure @@ -158,7 +158,7 @@ flowchart TD ## Design Principles -- **Local first:** project data, analysis results, and editor state stay on the user's machine by default. +- **Local first:** many projects are designed for local use; storage, network, and telemetry behavior is documented per repository. - **Small tools over platforms:** each repository targets a concrete workflow instead of replacing an entire development stack. - **Windows pragmatism:** desktop apps prioritize reliable local execution, predictable packaging, and low setup overhead. - **Clear boundaries:** security-adjacent tools such as API discovery are documented for owned or explicitly authorized services. diff --git a/profile/README_de.md b/profile/README_de.md index c6878d4..42070e4 100644 --- a/profile/README_de.md +++ b/profile/README_de.md @@ -2,8 +2,7 @@

Aktive Öffentliche Repos Local First - Lizenz - Sicherheits-SLA + Sicherheitsrichtlinie Geprüft 2026-10-01 llms.txt English Version @@ -62,7 +61,7 @@ dev-bricks entwickelt kompakte, praktische Software für tägliche Entwicklungsa | [app-rotator](https://github.com/dev-bricks/app-rotator) | Konfigurierbare Windows-Tray-App zur zeitlichen Staffelung (Time-Slicing) ressourcenintensiver Desktop-KI-Apps zur Vermeidung von VRAM-/GPU-Engpässen | Aktiv | | [automizer-for-claude-desktop](https://github.com/dev-bricks/automizer-for-claude-desktop) | Werkzeug für das Steuern und Ändern geplanter Claude Desktop Aufgaben | Aktiv | | [CareCenter-for-Codex](https://github.com/dev-bricks/CareCenter-for-Codex) | Windows-Tray und CLI für Reparatur, Diagnose und Log-Bereinigung von OpenAI Codex Desktop | Aktiv | -| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | Konservativer Windows-Tray zur sicheren Bereinigung verwaister Model-Context-Protocol- (MCP) und Language-Server-Prozesse ohne pauschale Prozessbaum-Kills | Aktiv | +| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | Konservativer Windows-Tray zur Bereinigung ausgewählter verwaister MCP- und Language-Server-Prozesse einzeln, ohne pauschale Prozessbaum-Beendigung | Aktiv | | [fable-5-hunter](https://github.com/dev-bricks/fable-5-hunter) | Benachrichtigungs-Watcher für die Erreichbarkeit von Claude Fable 5 in Claude Code *(archiviert)* | Archiviert | | [.github](https://github.com/dev-bricks/.github) | Organisationsprofil, Vorlagen für Issues/PRs, Community-Workflows und maschinenlesbarer Index | Aktiv | @@ -70,6 +69,7 @@ dev-bricks entwickelt kompakte, praktische Software für tägliche Entwicklungsa | Repository | Letzter öffentlicher Push | Fokus | |---|---:|---| +| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | 2026-10-03 | Bereinigung ausgewählter verwaister MCP-/Language-Server-Prozesse | | [.github](https://github.com/dev-bricks/.github) | 2026-10-01 | Organisationsprofil und öffentliche Verzeichnisparität | | [MethodenAnalyser](https://github.com/dev-bricks/MethodenAnalyser) | 2026-09-30 | Statische Python-Code-Analyse | | [safe-start-for-codex](https://github.com/dev-bricks/safe-start-for-codex) | 2026-09-30 | Start-Gate für Codex Desktop Automationen | @@ -77,12 +77,12 @@ dev-bricks entwickelt kompakte, praktische Software für tägliche Entwicklungsa | [DevCenter](https://github.com/dev-bricks/DevCenter) | 2026-09-30 | Lokales Entwickler-Dashboard und IDE | | [app-rotator](https://github.com/dev-bricks/app-rotator) | 2026-09-29 | Desktop-App-Time-Slicing und VRAM-Governance | | [CareCenter-for-Codex](https://github.com/dev-bricks/CareCenter-for-Codex) | 2026-09-29 | Reparatur und Diagnose für Codex Desktop | -| [zombie-killer-tray](https://github.com/dev-bricks/zombie-killer-tray) | 2026-09-29 | Bereinigung verwaister MCP-/Language-Server-Prozesse | | [WikiStub-Seed](https://github.com/dev-bricks/WikiStub-Seed) | 2026-09-28 | Strukturierte JSON/Markdown-Wissensstubs | | [ApiProber](https://github.com/dev-bricks/ApiProber) | 2026-09-22 | Autorisiertes API-Inventar und OpenAPI-Erkundung | | [pythonbox](https://github.com/dev-bricks/pythonbox) | 2026-09-22 | Leichtbau-Python-IDE | | [automizer-for-claude-desktop](https://github.com/dev-bricks/automizer-for-claude-desktop) | 2026-09-21 | Claude-Desktop-Aufgaben-Automation | | [fable-5-hunter](https://github.com/dev-bricks/fable-5-hunter) *(archiviert)* | 2026-06-25 | Benachrichtigungs-Watcher für Claude Fable 5 | +**Gezieltes Update:** Zombie-Killer-Tray wurde am 03.10.2026 gezielt auf dem Branch `main` geprüft; die übrigen Aktivitätszeilen behalten den Snapshot vom 01.10.2026. ### Integrierte ellmos-ai Infrastruktur @@ -160,7 +160,7 @@ flowchart TD ## Entwicklungs-Prinzipien -- **Local-First:** Projektdaten, Analyseergebnisse und Editor-Zustände verbleiben standardmäßig auf dem lokalen Rechner. +- **Local-First:** Viele Projekte sind auf lokale Nutzung ausgelegt; Speicher-, Netzwerk- und Telemetrieverhalten ist in der jeweiligen Repository-Dokumentation beschrieben. - **Spezialisierte Werkzeuge:** Jedes Repo fokussiert sich auf eine konkrete Aufgabe statt komplexe Plattformen zu imitieren. - **Pragmatische Windows-Unterstützung:** Verlässliche lokale Ausführung, saubere Distribution und minimaler Setup-Aufwand. - **Transparente Grenzen:** API-Erkundungswerkzeuge sind ausschließlich für eigene oder explizit freigegebene Systeme dokumentiert. diff --git a/tests/test_profile_parity.py b/tests/test_profile_parity.py index b7ca084..4ce311b 100644 --- a/tests/test_profile_parity.py +++ b/tests/test_profile_parity.py @@ -1,4 +1,4 @@ -"""Parity, inventory, and health contract tests for dev-bricks organization profile.""" +"""Text and link parity checks for dev-bricks organization profile, inventory, and public metadata.""" import re from pathlib import Path @@ -46,7 +46,7 @@ "DevCenter": "2026-09-30", "app-rotator": "2026-09-29", "CareCenter-for-Codex": "2026-09-29", - "zombie-killer-tray": "2026-09-29", + "zombie-killer-tray": "2026-10-03", "WikiStub-Seed": "2026-09-28", "ApiProber": "2026-09-22", "pythonbox": "2026-09-22", @@ -113,7 +113,7 @@ def test_check_timestamp_parity(file_contents): def test_public_activity_snapshot(file_contents): - """Verify the API-derived activity date for every public repository.""" + """Verify documented activity dates across the public text surfaces.""" for repo, date in PUBLIC_ACTIVITY_DATES.items(): marker = re.compile( rf"https://github\.com/dev-bricks/{re.escape(repo)}\)[^|]*\| {date} \|" @@ -140,25 +140,29 @@ def test_repository_counts_parity(file_contents): assert "Public repository count: 13 total" in file_contents["llms.txt"] -def test_verified_and_sla_badges_parity(file_contents): - """Verify Verified and Security SLA badges exist and are synchronized.""" +def test_verified_and_security_policy_badges_parity(file_contents): + """Verify dated badges and canonical security-policy links in both profiles.""" en_profile = file_contents["profile/README.md"] de_profile = file_contents["profile/README_de.md"] + policy_href = "https://github.com/dev-bricks/.github/blob/main/SECURITY.md" assert "Verified-2026--10--01" in en_profile - assert "Security_SLA-48h_Response" in en_profile + assert "Security_Policy" in en_profile + assert f'href="{policy_href}"' in en_profile - assert "Geprüft-2026--10--01" in de_profile - assert "Sicherheits_SLA-48h_Reaktion" in de_profile + assert "Gepr\u00fcft-2026--10--01" in de_profile + assert "Sicherheitsrichtlinie" in de_profile + assert f'href="{policy_href}"' in de_profile + assert (REPO_ROOT / "SECURITY.md").is_file() def test_security_policy_bilingual_parity(file_contents): - """Verify SECURITY.md is bilingual and establishes 48h response SLA.""" + """Verify the organization response commitment and repository-specific scope.""" sec = file_contents["SECURITY.md"] assert "Security Policy / Sicherheitsrichtlinie" in sec assert "48 hours" in sec - assert "Zero-Egress & Local-First" in sec - assert "Unprivileged User Mode" in sec + assert "These properties vary by repository" in sec + assert "Zombie-Killer-Tray tray launcher can request UAC elevation" in sec def test_ecosystem_cross_linking(file_contents):