Skip to content

security(wow): central source approvals and auditable provenance (#140) - #146

Merged
EagleFox31 merged 9 commits into
mainfrom
feat/140-wow-source-security
Oct 9, 2026
Merged

EagleFox31 merged 9 commits into
mainfrom
feat/140-wow-source-security

Conversation

@EagleFox31

Copy link
Copy Markdown
Contributor

Context

Closes #140. Builds on the existing AppFactory UI Registry and read-only WOW source inventory delivered by #139. No external component becomes available for automated import.

Added

  • ui-registry/wow-review-policy.json: central source approval policy, defaultDisposition: reference-only, no live approvals.
  • ui-registry/wow-security.mjs: validates trusted source approvals and human-reviewed license evidence, rejects mutable refs, unknown sources, unsafe files, unapproved install commands, duplicate approvals and colliding provenance.
  • ui-registry/schemas/wow-review-policy.schema.json and wow-provenance.schema.json.
  • Pure, deterministic reconcileWowProvenance() helper for the future consumer file .appfactory/frontend-provenance.json: idempotent no-op for the same request; explicit conflicts for changed refs/paths/evidence and file collisions.
  • verifyWowProvenanceFiles() checks that adopted code + notices exist, are nonempty and do not resolve through symlinks outside the checkout.
  • findExternalMediaHotlinks() flags likely external imagery in source text as a review cue, not a full browser/network audit.
  • test/wow-frontend-security.test.mjs, invoked through the existing test:ui-registry CI.
  • Security reviewer runbook docs/wow-reuse-security.md.

Security semantics

  • approved, reference-only, review-required, blocked dispositions.
  • Reviewed approval requires exact 40-character commit SHA, pinned upstream LICENSE/COPYING URL, SPDX allowlist, reviewer, review date, explicit mode and license notice destination.
  • Important: even a reviewed synthetic fixture can only yield manual eligibility; executeAllowed is always false. No package installs, clone, remote script, auto-copy or production modification.
  • No live approval is introduced. Metadata-only GitHub license fields do not authorize copying.
  • Human verification of actual legal terms, transitive assets and Pro restrictions remains mandatory; branch protection/CODEOWNERS is recommended.

Scope boundaries

  • Existing native ui-registry/registry.json, provenance.json, profiles.json, consumer blueprints and Worker runtime are unchanged.
  • No package dependency added; no changes to PostgreSQL migration PR Add PostgreSQL migration gate to Worker releases #74.
  • Reuses Impact-Aware CI UI Registry gate.

Verify

npm run test:ui-registry + existing typecheck and webapp gates. Only merge when CI green.

Next: #141 agent skill, #142 source adapters; neither may treat a reference-only inventory entry as installation permission.

@EagleFox31
EagleFox31 merged commit af7672e into main Oct 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] Add WOW Frontend license, provenance and supply-chain guardrails

1 participant