{"id":51787729,"url":"https://github.com/anulum/rigor-foundry","last_synced_at":"2026-07-20T19:13:15.667Z","repository":{"id":371587929,"uuid":"1301511150","full_name":"anulum/rigor-foundry","owner":"anulum","description":"Evidence-bound repository auditing and remediation planning.","archived":false,"fork":false,"pushed_at":"2026-07-15T20:02:57.000Z","size":4062,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-15T20:05:11.562Z","etag":null,"topics":["code-audit","code-quality","devsecops","evidence","governance","python","remediation","security","software-architecture","supply-chain"],"latest_commit_sha":null,"homepage":"https://anulum.github.io/rigor-foundry/","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/anulum.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":"CITATION.cff","codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":"SUPPORT.md","governance":"GOVERNANCE.md","roadmap":"ROADMAP.md","authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":".zenodo.json","notice":"NOTICE","maintainers":null,"copyright":"COPYRIGHT","agents":null,"dco":null,"cla":null},"funding":{"custom":["https://www.anulum.li"]}},"created_at":"2026-07-15T10:54:46.000Z","updated_at":"2026-07-15T20:02:59.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/anulum/rigor-foundry","commit_stats":null,"previous_names":["anulum/rigor-foundry"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/anulum/rigor-foundry","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anulum%2Frigor-foundry","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anulum%2Frigor-foundry/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anulum%2Frigor-foundry/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anulum%2Frigor-foundry/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/anulum","download_url":"https://codeload.github.com/anulum/rigor-foundry/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anulum%2Frigor-foundry/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35696962,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"ssl_error","status_checked_at":"2026-07-20T02:08:09.736Z","response_time":111,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["code-audit","code-quality","devsecops","evidence","governance","python","remediation","security","software-architecture","supply-chain"],"created_at":"2026-07-20T19:13:14.913Z","updated_at":"2026-07-20T19:13:15.661Z","avatar_url":"https://github.com/anulum.png","language":"Python","funding_links":["https://www.anulum.li","https://github.com/sponsors/anulum"],"categories":[],"sub_categories":[],"readme":"# RigorFoundry\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/anulum/rigor-foundry/actions/workflows/ci.yml\"\u003e\u003cimg src=\"https://github.com/anulum/rigor-foundry/actions/workflows/ci.yml/badge.svg\" alt=\"CI\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/anulum/rigor-foundry/actions/workflows/docs.yml\"\u003e\u003cimg src=\"https://github.com/anulum/rigor-foundry/actions/workflows/docs.yml/badge.svg\" alt=\"Documentation\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/anulum/rigor-foundry/actions/workflows/fuzz.yml\"\u003e\u003cimg src=\"https://github.com/anulum/rigor-foundry/actions/workflows/fuzz.yml/badge.svg\" alt=\"Fuzz\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/anulum/rigor-foundry/actions/workflows/security.yml\"\u003e\u003cimg src=\"https://github.com/anulum/rigor-foundry/actions/workflows/security.yml/badge.svg\" alt=\"Security\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/anulum/rigor-foundry/actions/workflows/codeql.yml\"\u003e\u003cimg src=\"https://github.com/anulum/rigor-foundry/actions/workflows/codeql.yml/badge.svg\" alt=\"CodeQL\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://app.codecov.io/gh/anulum/rigor-foundry\"\u003e\u003cimg src=\"https://codecov.io/gh/anulum/rigor-foundry/branch/main/graph/badge.svg\" alt=\"Codecov coverage\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://pypi.org/project/rigor-foundry/\"\u003e\u003cimg src=\"https://img.shields.io/pypi/v/rigor-foundry\" alt=\"PyPI version\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://pypi.org/project/rigor-foundry/\"\u003e\u003cimg src=\"https://img.shields.io/pypi/dm/rigor-foundry\" alt=\"PyPI downloads\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://pepy.tech/project/rigor-foundry\"\u003e\u003cimg src=\"https://static.pepy.tech/badge/rigor-foundry\" alt=\"Total downloads\"\u003e\u003c/a\u003e\n  \u003ca href=\"LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/badge/license-Apache--2.0-blue.svg\" alt=\"License: Apache-2.0\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://www.anulum.li/\"\u003e\u003cimg src=\"https://img.shields.io/badge/commercial%20licence-available-0a7d3c\" alt=\"Commercial licence available\"\u003e\u003c/a\u003e\n  \u003ca href=\"pyproject.toml\"\u003e\u003cimg src=\"https://img.shields.io/badge/python-3.11--3.13-blue.svg\" alt=\"Python 3.11–3.13\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://reuse.software/\"\u003e\u003cimg src=\"https://api.reuse.software/badge/github.com/anulum/rigor-foundry\" alt=\"REUSE status\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://securityscorecards.dev/viewer/?uri=github.com/anulum/rigor-foundry\"\u003e\u003cimg src=\"https://api.securityscorecards.dev/projects/github.com/anulum/rigor-foundry/badge\" alt=\"OpenSSF Scorecard\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/astral-sh/ruff\"\u003e\u003cimg src=\"https://img.shields.io/endpoint?url=https://raw.githubusercontent.com/astral-sh/ruff/main/assets/badge/v2.json\" alt=\"Ruff\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/sponsors/anulum\"\u003e\u003cimg src=\"https://img.shields.io/badge/sponsor-GitHub-ea4aaa?logo=githubsponsors\" alt=\"Sponsor on GitHub\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n![RigorFoundry audit forge](docs/assets/rigor_foundry_repo_header.png)\n\nEvidence-bound codebase transformation.\n\nRigorFoundry inventories Git-tracked repository content, emits reproducible\naudit candidates, binds review decisions to exact evidence, and prepares\nremediation inputs without treating static heuristics as defect verdicts.\n\n\u003e **Current status:** standalone pre-alpha. Versioned\n\u003e [GitHub Releases](https://github.com/anulum/rigor-foundry/releases) and\n\u003e [GHCR images](https://github.com/anulum/rigor-foundry/pkgs/container/rigor-foundry)\n\u003e are published through the repository, beginning with `v0.1.0`. PyPI\n\u003e availability is established from the\n\u003e [public registry](https://pypi.org/project/rigor-foundry/), not inferred from\n\u003e a tag or workflow result. RigorFoundry has not been promoted as the GOTM\n\u003e fleet audit authority. A clean static scan is not a clean-repository claim.\n\n## Operating contract\n\n- `scan` is read-only and inspects only the exact Git-tracked inventory.\n- Findings remain candidates until reviewed against the production surface.\n- Missing evidence is explicit; it never resolves to pass.\n- Reports bind repository HEAD, tree, Git object format, tracked-content,\n  policy, rule-pack, and exact Git executable/version provenance.\n- Every candidate binds either the exact scanned blob and inclusive line span\n  or the exact repository tree and tracked-content digest for an absence or\n  repository-wide search. Human-readable evidence is bounded.\n- Promotion rejects stale reports, stale policies, changed Git provenance,\n  duplicate findings, and mismatched repositories.\n- Pack and reviewer signatures use distinct versioned Ed25519 message domains;\n  legacy raw-digest signatures are rejected rather than reinterpreted.\n- `rigor verify` checks caller-supplied signed evidence, explicit key lifecycle,\n  expiry, unavailable records, and model-alias collapse entirely offline.\n- Native audit adapters use validated argv, bounded execution time, and\n  `shell=False`.\n- Internal campaign records are written only below Git-ignored paths.\n\n## Architecture\n\n```mermaid\nflowchart LR\n    A[Git repository] --\u003e B[Fail-closed inventory]\n    B --\u003e C[Portable scanners]\n    B --\u003e D[Declared native adapters]\n    C --\u003e E[Content-addressed AuditReport]\n    D --\u003e F[Adapter evidence]\n    E --\u003e G[Evidence review]\n    E --\u003e L[SARIF candidate export]\n    G --\u003e L\n    F --\u003e G\n    G --\u003e M[Adjudicated rule maturity]\n    M --\u003e H[Enforcement decision]\n    G --\u003e H\n    G --\u003e I[Verified TODO promotion]\n    E --\u003e J[Independent campaign attestations]\n    J --\u003e K[Divergence comparison]\n```\n\nThe target profile model keeps five records separate:\n\n1. `StandardPack` — versioned controls, licence, signature, and provenance.\n2. `ProjectProfile` — selected controls, applicability, targets, and typed\n   project variables.\n3. `EffectiveProfileLock` — resolved inputs, digests, adapters, and\n   contradiction evidence.\n4. `ControlAssessment` — evidence-bound states such as `needs-evidence`,\n   `blocked`, `fail`, `pass`, and `accepted-risk`.\n5. `TargetGap` / `RemediationPlan` — the dependency-ordered difference between\n   observed state and the declared target.\n\nThese records and their fail-closed resolver are implemented as a local typed\nAPI. They do not grant execution authority, make RigorFoundry the fleet audit\nauthority, or prove effectiveness on an external corpus. See\n[ARCHITECTURE.md](ARCHITECTURE.md).\n\n## Install a published release\n\nAfter the exact version appears in the\n[PyPI release history](https://pypi.org/project/rigor-foundry/#history), install\nit with:\n\n```bash\npython -m pip install \"rigor-foundry==0.1.1\"\n```\n\n## Quick start from source\n\n```bash\ngit clone https://github.com/anulum/rigor-foundry.git RIGOR-FOUNDRY\ncd RIGOR-FOUNDRY\npython3 -m venv .venv\n.venv/bin/python -m pip install --require-hashes -r requirements/ci.txt\n.venv/bin/python -m pip install --no-build-isolation --no-deps -e .\n.venv/bin/rigor --version\n```\n\nFor an adopter repository, follow the explicit [first-repository\ntutorial](docs/getting-started.md). Bootstrap requires the policy, canonical\nTODO, review-ledger, source-root, and test-root paths; it never guesses or\noverwrites them. The [consumer integration guide](docs/integrations.md)\nprovides immutable-SHA GitHub Action and pre-commit configurations with\nexplicit policy/evidence paths and no remediation authority.\n\n## Command surface\n\n| Command | Contract |\n| --- | --- |\n| `rigor bootstrap` | Create one explicit policy and ignored canonical TODO without guessing or overwrite. |\n| `rigor scan` | Emit a deterministic JSON or Markdown candidate report. |\n| `rigor contract` | Emit the digest-bound proposed-1.0 Python, CLI, and schema compatibility contract. |\n| `rigor report-diff` | Compare two exact reports as replay-verifiable candidate-transition evidence. |\n| `rigor verify` | Verify signed reports, reviews, packs, model aliases, freshness, and unavailable evidence offline. |\n| `rigor review-template` | Create explicit `needs-evidence` review records. |\n| `rigor validate-review` | Verify reviews against one exact report. |\n| `rigor sarif` | Export every candidate and optional review verdict as deterministic SARIF 2.1.0. |\n| `rigor maturity-evaluate` | Derive probation or active status from explicit adjudicated review cases. |\n| `rigor promote` | Preview or append one finding from a verified cross-model promotion campaign. |\n| `rigor gate` | Apply observe, ratchet, or zero enforcement; non-observe modes require a maturity report whose policy digest is repository-bound. |\n| `rigor campaign-create` | Freeze an independent-audit input contract. |\n| `rigor campaign-run` | Execute and attest one independent run. |\n| `rigor campaign-compare` | Record disagreement and unresolved evidence. |\n| `rigor cra-bootstrap` | Create fresh Git-ignored offline CRA state and one operator-declared product registration. |\n| `rigor vuln-register` | Append a content-addressed vulnerability or severe-incident revision. |\n| `rigor vuln-timeline` | Print verified 24-hour, 72-hour, and track-specific final-report clocks. |\n| `rigor cra-draft` | Prepare deterministic Article 14 JSON and Markdown without submitting them. |\n| `rigor cra-receipt` | Bind operator-supplied receipt evidence without claiming authority acceptance. |\n| `rigor cra-skip` | Record an explicit later-stage already-provided decision bound to an earlier receipt. |\n| `rigor user-notice` | Prepare an offline Article 14(8) user-notice payload pair. |\n| `rigor cra-status` | Replay all CRA records and return operational alert status. |\n| `rigor advisory-draft` / `advisory-publish` / `advisory-delay` | Bind prepare-only fixed-vulnerability advisory evidence; never publish. |\n| `rigor cra-pack` | Emit the CRA StandardPack signed by a caller-supplied Ed25519 key. |\n\n`rigor --version` reports the canonical installed package version. The exact\nstable/provisional top-level import inventory and deprecation policy are\ndocumented in [Public API stability](docs/api-stability.md).\nThe proposed-1.0 command and serialized-protocol freeze is documented in the\n[1.0 stable compatibility contract](docs/stable-contract-1.0.md); the current\npackage remains pre-1.0 until the release gates and protected tag complete.\n\nThe [offline CRA preparation guide](docs/cra-reporting.md) documents the exact\noperator workflow, evidence boundary, clocks, append-only storage, and exit\ncodes. It is a drafting aid, not legal advice, a conformity assessment, or an\nexternal submission client.\n\nThe [content-addressed report-diff guide](docs/report-diff.md) documents strict\ncompatibility declarations, ambiguous anchor matching, deterministic replay,\nand the boundary between candidate trends and correctness verdicts.\n\nThe [offline evidence-verification guide](docs/offline-verification.md)\ndocuments caller-selected trust, key lifecycle, signature domains, bundle and\nresult schemas, exit codes, alias collapse, and the assurance boundary.\n\nDeclared native adapters run only after `--allow-native-audits` consent. They\nexecute in a no-network, read-only sandbox with a credential-free environment,\nhard output and time bounds, process-tree termination, and structured durable\nevidence. Native execution currently requires Bubblewrap at\n`/usr/bin/bwrap` on a dpkg-based host, `/usr/bin/dpkg-query`, and a compatible\nBubblewrap 0.9.x installation. Passive scans and report review do not require\nthese native surfaces.\n\nVerified built-in Semgrep, offline Trivy, and offline OSV lockfile profiles additionally bind the\nimmutable command/parser contract, exact tracked-only input snapshot,\nconfiguration and executable bytes, tool version, structured status, and\nprofile evidence digest. Partial or unavailable evidence never supplies domain\ncoverage. See [Built-in adapter profiles](docs/adapter-profiles.md) for the\nstrict policy form, installation boundary, coverage limits, and benchmark.\n\n## Module ownership\n\n| Surface | Modules | Responsibility |\n| --- | --- | --- |\n| Git trust | `git_provenance` | Fixed-root executable selection, supported versions, replacement detection, and content-addressed provenance. |\n| Inventory | `git_inventory` | Exact tracked paths, content kinds, scanned blob identities, and digests through the trusted Git runner. |\n| Candidate anchors | `candidate_anchor` | Strict blob/tree anchor schemas, inclusive line spans, bounded excerpts, and anchor verification. |\n| Candidate collection | `architecture`, `godfiles`, `polyglot_architecture`, `test_authenticity` | Static signals requiring review, each bound to a verified anchor. |\n| Policy and records | `rules`, `domains`, `audit_primitives`, `policy_models`, `models` | Versioned rules, strict protocol primitives, applicability, repository policy, and content-addressed report/review records. |\n| Report differences | `report_diff`, `report_diff_cli` | Replay-verifiable candidate transitions over two exact reports, with explicit compatibility and ambiguity evidence. |\n| Offline verification | `verification_policy`, `offline_verification_models`, `offline_verification`, `offline_verification_report`, `offline_verification_cli` | Caller-selected key lifecycle, signed multi-protocol evidence, alias collapse, explicit unavailability, deterministic aggregate results, and a no-network CLI. |\n| Review and enforcement | `review`, `enforcement` | Evidence validation, stale-state rejection, and controlled promotion. |\n| Rule calibration | `rule_maturity`, `rule_maturity_manifest` | Explicit activation thresholds, source-bound adjudications, reviewer-effort evidence, and probation-safe gate input. |\n| Interchange | `sarif` | Deterministic SARIF 2.1.0 projection that preserves candidate, review, and exact-anchor state. |\n| Native boundaries | `adapters`, `adapter_runtime`, `adapter_profiles`, `adapter_workspace`, `osv_database`, `sandbox_provenance`, `trusted_executable` | Descriptor-pinned, time/output-bounded repository commands; immutable built-in profiles; tracked-only snapshots; verified offline OSV databases; structured evidence; and versioned Bubblewrap compatibility. |\n| External sources | `source_capture`, `source_provenance` | Content-addressed advisory/version/standard/digest claims, bounded capture metadata, stable retained-file reads, and deterministic offline verification. |\n| Campaigns | `campaign_identity`, `campaign_evidence`, `campaign_models`, `campaign_store`, `campaign_workflow`, `campaign_compare`, `campaign_promotion` | Inference and toolchain identity, correlated-witness collapse, durable provenance, divergence, and promotion eligibility. |\n| Profile primitives | `model_primitives`, `condition_language` | Typed variables, opaque secret references, strict values, and bounded conditions. |\n| Desired state | `standard_pack`, `project_profile`, `effective_profile`, `profile_resolution`, `trust` | Versioned controls, explicit Ed25519 trust stores, adopter intent, exact pack locks, contradiction evidence, and fail-closed resolution. |\n| Assessment and planning | `control_assessment`, `review_attestation`, `remediation_plan`, `_remediation_graph` | Signed fresh evidence, cryptographically verified reviewer separation, target gaps, adapter-bound procedures, and conflict-safe batches. |\n| Work lifecycle | `internal_storage`, `work_models` | Ignored crash-safe storage and digest-bound task/event closure records. |\n\n## Container use\n\n```bash\ndocker build -t rigor-foundry:local .\ndocker run --rm --read-only \\\n  --mount type=bind,src=/path/to/repository,dst=/workspace,readonly \\\n  rigor-foundry:local scan --root /workspace\n```\n\nThe container runs as a non-root user and contains Git because repository\ninventory is a production dependency of the CLI.\n\n## Verification and reproducibility\n\n- Python support is declared only for 3.11, 3.12, and 3.13 and is represented\n  in the CI matrix.\n- CI dependencies are resolved into a hash-locked requirements file.\n- Local work uses the repository-owned `.venv` on the GOTM working disk.\n- GOTM authoring policy uses focused single-file tests locally; CI owns the\n  exhaustive test and coverage gate. External contributors may opt into the\n  same local matrix explicitly.\n- Releases, when authorised after public-repository promotion, build wheel and\n  source distributions, run metadata checks, generate a CycloneDX SBOM, create\n  Sigstore signatures and provenance, and publish through an owner-gated OIDC\n  environment.\n- Benchmark and effectiveness claims require committed methodology and measured\n  evidence. No such performance claim is made by the migration baseline.\n\nSee [VALIDATION.md](VALIDATION.md) for the gate matrix and\n[SECURITY.md](SECURITY.md) for the threat boundary.\n\n## Development\n\n```bash\nmake install\nmake lint\nmake typecheck\nmake audit\nmake preflight-fast\n```\n\nRun focused test files with `pytest tests/test_name.py`. GOTM operators do not\nrun the local full suite unless the owner explicitly authorises it for the\ncurrent session; external contributors may opt in as documented in\n`CONTRIBUTING.md`.\nSee [CONTRIBUTING.md](CONTRIBUTING.md).\n\n## Community\n\n- [Issue tracker](https://github.com/anulum/rigor-foundry/issues)\n- [Discussions](https://github.com/anulum/rigor-foundry/discussions)\n- [Support](SUPPORT.md)\n- [Security reporting](SECURITY.md)\n- [Sponsor the public core](https://github.com/sponsors/anulum)\n\n## Licence\n\nRigorFoundry is available under the [Apache License 2.0](LICENSE). The licence\nincludes an explicit contribution-scoped patent grant; it does not grant rights\nto use the RigorFoundry name or marks except as the licence permits.\n\n---\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://www.anulum.li\"\u003e\u003cimg src=\"docs/assets/anulum_logo_company.jpg\" height=\"70\" alt=\"ANULUM\"\u003e\u003c/a\u003e\n  \u0026nbsp;\u0026nbsp;\u0026nbsp;\n  \u003cimg src=\"docs/assets/fortis_studio_logo.jpg\" height=\"70\" alt=\"Fortis Studio\"\u003e\n  \u003cbr\u003e\n  \u003cem\u003eDeveloped by \u003ca href=\"https://www.anulum.li\"\u003eANULUM\u003c/a\u003e / Fortis Studio\u003c/em\u003e\n\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanulum%2Frigor-foundry","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fanulum%2Frigor-foundry","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanulum%2Frigor-foundry/lists"}