feat: Add repository protection systems
- Add PR template to prevent commercial content leakage - Add automated workflow to scan for prohibited content - Protect against business strategy, infrastructure details, customer info
This commit is contained in:
parent
f8c45f2d8d
commit
7432fab3bc
3 changed files with 13792 additions and 0 deletions
18
.github/pull_request_template.md
vendored
Normal file
18
.github/pull_request_template.md
vendored
Normal file
|
|
@ -0,0 +1,18 @@
|
||||||
|
# 🚨 CRITICAL: Public Repository Checklist
|
||||||
|
|
||||||
|
## Before merging this PR, confirm:
|
||||||
|
|
||||||
|
- [ ] **No business strategy** - No pricing, revenue plans, or commercial roadmaps
|
||||||
|
- [ ] **No customer info** - No specific customer details or enterprise discussions
|
||||||
|
- [ ] **No infrastructure details** - No Google Cloud project IDs or internal URLs
|
||||||
|
- [ ] **No SkillVill content** - All SkillVill planning belongs in brain-cloud repo
|
||||||
|
- [ ] **Open source focused** - Content appropriate for public consumption
|
||||||
|
- [ ] **Registry references OK** - Only registry.soulcraft.com endpoint references allowed
|
||||||
|
|
||||||
|
## ✅ This PR contains only:
|
||||||
|
- [ ] Open source Brainy library improvements
|
||||||
|
- [ ] Generic documentation updates
|
||||||
|
- [ ] CLI enhancements (registry integration OK)
|
||||||
|
- [ ] Community-focused features
|
||||||
|
|
||||||
|
**🛡️ When in doubt, move content to brain-cloud private repo instead!**
|
||||||
43
.github/workflows/repo-audit.yml
vendored
Normal file
43
.github/workflows/repo-audit.yml
vendored
Normal file
|
|
@ -0,0 +1,43 @@
|
||||||
|
name: 🚨 Repository Content Audit
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [ main ]
|
||||||
|
pull_request:
|
||||||
|
branches: [ main ]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
audit-content:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: 🔍 Scan for commercial content
|
||||||
|
run: |
|
||||||
|
echo "🚨 Scanning for prohibited content..."
|
||||||
|
|
||||||
|
# Scan for business terms
|
||||||
|
if grep -r -i "skillvill\|revenue\|pricing.*\$[0-9]\|enterprise.*plan\|business.*plan.*\$" . --exclude-dir=.git --exclude-dir=node_modules; then
|
||||||
|
echo "❌ FOUND BUSINESS CONTENT IN PUBLIC REPO!"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Scan for infrastructure details
|
||||||
|
if grep -r "476163328636\|brain-cloud-api.*\.run\.app" . --exclude-dir=.git --exclude-dir=node_modules; then
|
||||||
|
echo "❌ FOUND INFRASTRUCTURE DETAILS IN PUBLIC REPO!"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Scan for customer info
|
||||||
|
if grep -r -i "customer.*\$\|client.*enterprise\|acme.*corp.*\$" . --exclude-dir=.git --exclude-dir=node_modules; then
|
||||||
|
echo "❌ FOUND CUSTOMER INFO IN PUBLIC REPO!"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "✅ Content audit passed - repository is clean!"
|
||||||
|
|
||||||
|
- name: 📝 Verify allowed content
|
||||||
|
run: |
|
||||||
|
echo "✅ Checking for required open source content..."
|
||||||
|
ls -la src/ bin/ README.md package.json
|
||||||
|
echo "✅ All good - open source content present"
|
||||||
13731
package-lock.json
generated
Normal file
13731
package-lock.json
generated
Normal file
File diff suppressed because it is too large
Load diff
Loading…
Add table
Add a link
Reference in a new issue