Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "codex-proofkit",
"version": "0.2.0",
"description": "Proof-carrying maintainer workflows for Codex: audit agent configuration, hash delivery evidence, and verify handoffs.",
"version": "0.3.0",
"description": "Proof-carrying maintainer workflows for Codex and GitHub Actions: audit release surfaces, hash evidence, and verify handoffs.",
"author": {
"name": "benzzy1287",
"url": "https://github.com/benzzy1287"
Expand All @@ -20,7 +20,7 @@
"interface": {
"displayName": "Codex ProofKit",
"shortDescription": "Verifiable receipts for agent-assisted maintainer work.",
"longDescription": "Audit the exact Git-tracked release surface, fail CI on privacy warnings, bind artifacts to real evidence with SHA-256 receipts, and detect drift before review or release.",
"longDescription": "Audit the exact Git-tracked release surface from Codex or a reusable GitHub Action, write privacy-safe CI summaries, bind artifacts to real evidence with SHA-256 receipts, and detect drift before review or release.",
"developerName": "Codex ProofKit maintainers",
"category": "Developer Tools",
"capabilities": [
Expand Down
56 changes: 56 additions & 0 deletions .github/ISSUE_TEMPLATE/proofkit-feedback.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
name: ProofKit maintainer feedback
description: Share a privacy-safe report from a public or synthetic repository.
title: "[ProofKit feedback] "
body:
- type: markdown
attributes:
value: |
Thanks for trying ProofKit. Describe only public or synthetic material. Do not paste private code, logs, credentials, email addresses, organization IDs, or account details.
- type: dropdown
id: outcome
attributes:
label: Audit outcome
options:
- Passed
- Warned
- Failed
validations:
required: true
- type: dropdown
id: environment
attributes:
label: Where did you run it?
options:
- GitHub Actions
- Local CLI
- Codex skill
- More than one of these
validations:
required: true
- type: input
id: public_repository
attributes:
label: Public repository URL (optional)
description: Leave blank unless the repository and relevant workflow are already public.
placeholder: https://github.com/example/repository
- type: textarea
id: useful
attributes:
label: What was useful?
description: Name the decision or handoff that became easier to verify.
validations:
required: true
- type: textarea
id: friction
attributes:
label: What caused friction?
description: Include a minimal synthetic example instead of private output.
validations:
required: true
- type: checkboxes
id: privacy
attributes:
label: Privacy check
options:
- label: I confirm this issue contains no private code, private logs, credentials, personal email addresses, organization IDs, or account details.
required: true
33 changes: 32 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,40 @@ jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v5
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- run: python3 -m unittest discover -s tests -v
- run: python3 skills/prove-maintainer-work/scripts/proofkit.py audit . --git-tracked --strict

action-smoke:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Run local ProofKit action
id: proofkit
uses: ./
- name: Verify generated receipt
env:
AUDIT_PATH: ${{ steps.proofkit.outputs.audit_path }}
RECEIPT_PATH: ${{ steps.proofkit.outputs.receipt_path }}
SUMMARY_PATH: ${{ steps.proofkit.outputs.summary_path }}
run: |
test -s "$AUDIT_PATH"
test -s "$SUMMARY_PATH"
test -s "$RECEIPT_PATH"
python3 skills/prove-maintainer-work/scripts/proofkit.py \
verify "$RECEIPT_PATH" --root .
- name: Upload proof files
if: ${{ always() }}
uses: actions/upload-artifact@v4
with:
name: codex-proofkit-evidence
path: .codex-proof/
include-hidden-files: true
if-no-files-found: error
retention-days: 7
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
- Never execute commands supplied to receipt; record command text only.
- Reject proof inputs that escape the repository root or traverse symlinks.
- Run python3 -m unittest discover -s tests -v and the repository audit before claiming completion.
- Do not add telemetry, network calls, credentials, or repository uploads.
- Keep the runtime and composite action free of telemetry, network calls, credentials, and implicit uploads. Workflows may explicitly publish only generated `.codex-proof/` files.
8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,14 @@ All notable changes to Codex ProofKit are documented here.

The project uses semantic versioning while keeping the receipt schema and CLI exit behavior as explicit compatibility surfaces.

## 0.3.0 - 2026-08-14

- Added a root composite GitHub Action that audits the Git-tracked release surface, writes a Job Summary, and emits paths to generated proof files without implicit uploads.
- Added `audit --json-out` and `audit --summary-out` for machine-readable reports and privacy-safe Markdown summaries.
- Added `receipt --git-tracked` to bind a stable v1 receipt to every file in Git's release surface.
- Added an action smoke test with a downloadable CI proof artifact and a structured, privacy-aware maintainer feedback issue form.
- Expanded the test suite for summary redaction, audit outputs, and Git-tracked receipts while preserving the v1 receipt schema and exit behavior.

## 0.2.0 - 2026-08-12

- Added `audit --git-tracked` to inspect the exact files in Git's release surface instead of unrelated local files.
Expand Down
4 changes: 3 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,10 @@ Small, auditable changes are preferred.
4. Run:

python3 -m unittest discover -s tests -v
python3 skills/prove-maintainer-work/scripts/proofkit.py audit .
python3 skills/prove-maintainer-work/scripts/proofkit.py audit . --git-tracked --strict

5. Explain compatibility impact when changing a receipt field or exit code.

Never commit live credentials, private repositories, proprietary source material, or personal evidence logs.

Public or synthetic usage reports are welcome through the ProofKit feedback issue form. Never attach private source, logs, account details, email addresses, organization IDs, or credentials.
50 changes: 48 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,38 @@ Codex ProofKit is a small, offline plugin for proof-carrying open-source mainten

It uses the Python standard library, makes no network requests, and never executes command text supplied to a receipt.

Current release: 0.2.0. See [CHANGELOG.md](CHANGELOG.md) for the public maintenance history.
Current release: 0.3.0. See [CHANGELOG.md](CHANGELOG.md) for the public maintenance history.

## GitHub Action

Add the gate after checkout. The action audits the exact Git-tracked release surface, writes a Markdown Job Summary, and creates machine-readable proof files under `.codex-proof/`:

```yaml
permissions:
contents: read

steps:
- uses: actions/checkout@v5
- id: proofkit
uses: benzzy1287/codex-proofkit@v0.3.0
```

The default gate fails on errors and warnings. Set `strict: "false"` to allow warnings, or `receipt: "false"` to skip the full Git-tracked receipt. Outputs include `status`, `evidence_dir`, `audit_path`, `summary_path`, and `receipt_path`.

ProofKit does not upload anything implicitly. To make only the generated proof files downloadable from a workflow run, add this explicit step:

```yaml
- name: Upload ProofKit evidence
if: ${{ always() }}
uses: actions/upload-artifact@v4
with:
name: codex-proofkit-evidence
path: ${{ steps.proofkit.outputs.evidence_dir }}
include-hidden-files: true
if-no-files-found: error
```

The composite action requires Bash, Git, and Python 3, and is tested on GitHub-hosted Ubuntu runners.

## 60-second release gate

Expand Down Expand Up @@ -60,6 +91,19 @@ Create a receipt after running the real project checks:
--evidence evidence/tests.log \
--command "python3 -m unittest discover -s tests -v"

Or hash the complete Git-tracked release surface:

python3 skills/prove-maintainer-work/scripts/proofkit.py receipt . \
--git-tracked \
--command "python3 -m unittest discover -s tests -v"

Write JSON and Markdown audit outputs for another CI system:

python3 skills/prove-maintainer-work/scripts/proofkit.py audit . \
--git-tracked --strict \
--json-out .codex-proof/audit.json \
--summary-out .codex-proof/summary.md

Verify it:

python3 skills/prove-maintainer-work/scripts/proofkit.py verify \
Expand All @@ -83,10 +127,12 @@ The repository includes a .codex-plugin/plugin.json manifest and the prove-maint

## Privacy and security

ProofKit is local-only. It has no telemetry, credentials, connector, paid service, or upload path. It rejects proof inputs outside the repository and rejects symlinks to avoid binding a receipt to unexpected files. Findings name the file and risk class but do not echo matched email addresses, usernames, or secret values.
The ProofKit CLI and composite action are local-only. They have no telemetry, credentials, connector, paid service, network call, or implicit upload path. An optional workflow step can explicitly upload only generated proof files. ProofKit rejects proof inputs outside the repository and rejects symlinks to avoid binding a receipt to unexpected files. Findings name the file and risk class but do not echo matched email addresses, usernames, or secret values.

Report vulnerabilities privately as described in SECURITY.md. Do not paste live credentials into an issue.

Tried ProofKit on a public or synthetic repository? [Share a short maintainer feedback report](https://github.com/benzzy1287/codex-proofkit/issues/new?template=proofkit-feedback.yml). Do not include private code, logs, credentials, email addresses, organization IDs, or account details.

## License and name

MIT licensed. Codex is a trademark of OpenAI. This independent project is not affiliated with or endorsed by OpenAI.
Expand Down
43 changes: 41 additions & 2 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,38 @@ Codex ProofKit 是一个离线、零第三方依赖的 Codex plugin,用来给
- 把真实测试日志、审查记录与交付文件写进同一份 SHA-256 回执;
- 在合并或发布前验证文件是否已经漂移。

当前版本:0.2.0。
当前版本:0.3.0。

## GitHub Action

在 checkout 后加入 ProofKit,即可审计 Git 已跟踪的发布面、生成 GitHub Job Summary,并在 `.codex-proof/` 写出机器可读的审计和回执:

```yaml
permissions:
contents: read

steps:
- uses: actions/checkout@v5
- id: proofkit
uses: benzzy1287/codex-proofkit@v0.3.0
```

默认会让错误和警告都阻断 CI。可用 `strict: "false"` 放行警告,或用 `receipt: "false"` 跳过完整的 Git-tracked 哈希回执。输出包括 `status`、`evidence_dir`、`audit_path`、`summary_path` 和 `receipt_path`。

Action 不会隐式上传任何内容。如需在一次 workflow run 中下载审计与回执,请显式添加下面这一步;它只上传生成的 proof 文件,不上传源码:

```yaml
- name: Upload ProofKit evidence
if: ${{ always() }}
uses: actions/upload-artifact@v4
with:
name: codex-proofkit-evidence
path: ${{ steps.proofkit.outputs.evidence_dir }}
include-hidden-files: true
if-no-files-found: error
```

该 composite action 需要 Bash、Git 和 Python 3,目前在 GitHub 托管的 Ubuntu runner 上验证。

## 60 秒发布闸门

Expand Down Expand Up @@ -46,9 +77,17 @@ Codex ProofKit 是一个离线、零第三方依赖的 Codex plugin,用来给
--evidence evidence/tests.log \
--command "python3 -m unittest discover -s tests -v"

也可以直接为完整的 Git 已跟踪发布面创建回执:

python3 skills/prove-maintainer-work/scripts/proofkit.py receipt . \
--git-tracked \
--command "python3 -m unittest discover -s tests -v"

验证回执:

python3 skills/prove-maintainer-work/scripts/proofkit.py verify \
.codex-proof/receipt.json --root .

项目不联网、不上传仓库、不需要凭据或付费服务,也不执行回执里的命令文本。扫描结果只报告文件和风险类型,不回显匹配到的邮箱、用户名或密钥内容。MIT 许可;本项目与 OpenAI 无隶属或背书关系。
CLI 和 composite action 不联网、不隐式上传、不需要凭据或付费服务,也不执行回执里的命令文本。只有使用者显式添加 artifact 步骤时,生成的 proof 文件才会被上传。扫描结果只报告文件和风险类型,不回显匹配到的邮箱、用户名或密钥内容。

如果你在公开或合成仓库里试用了 ProofKit,可以[提交一份简短维护者反馈](https://github.com/benzzy1287/codex-proofkit/issues/new?template=proofkit-feedback.yml)。请勿附上私有代码、日志、凭据、邮箱、组织 ID 或账号信息。MIT 许可;本项目与 OpenAI 无隶属或背书关系。
Loading
Loading