The repository is public now: tidy what it shows, fix a vulnerable dependency, and add a licence #146

Closed
opened 2026-10-05 15:16:05 -04:00 by cmoriarty · 1 comment
Owner

The repository was made public on 2026-10-05 and renamed from openspec-flow to braid. A review of the tree, the history, the issues and the deploy setup found no credentials, but it left a list of smaller things to put right.

What is wrong

  • A dependency has known advisories. urllib3 is locked at 2.7.0, which pip-audit reports under PYSEC-2026-4175, -4176 and -4177. All three are fixed in 2.8.0.
  • Scratch files are tracked at the root. outA.json, outB.json and an empty pa.json date from the first design commit and are used by nothing.
  • The operator's network is written into the deploy docs. deploy/README.md, deploy/.env.example, deploy/forgejo/README.md and docs/environment.md give LAN addresses, the Portainer address and an ssh login. None of it is reachable from outside, but a public runbook should read as an example to adapt, not as a map of one network.
  • The old name is still in use. README.md, CLAUDE.md, openspec/config.yaml, deploy/README.md and the image's source label point at cmoriarty/openspec-flow. The web redirect works; git over ssh does not follow it.
  • There is no licence. A public repository with no LICENSE grants a reader nothing. The owner has chosen MIT.
  • There is no SECURITY.md saying how to report a problem and what the trust model is (an internal tool, with no login in front on a private network).

What should not change

  • The container image stays forgejo.underthere.xyz/cmoriarty/openspec-flow. A package's name is its own, not the repository's, and production pulls it by that name.
  • Production keeps working with no new variable to set on the stack before the deploy.
  • The <!-- openspec-flow:begin --> markers and the Python package name stay: runs and their AGENTS.md blocks depend on them.
  • The archived OpenSpec changes and the design documents of record are left as they were written.

Out of scope

Rewriting history to drop the run state committed in 184fb8e (decided against: it holds no credential, and a force-push costs every clone). Rotating tokens. The Forgejo instance's own settings, which were fixed by hand on 2026-10-05 (OpenID sign-up off, 2FA on the admin account).

The repository was made public on 2026-10-05 and renamed from `openspec-flow` to `braid`. A review of the tree, the history, the issues and the deploy setup found no credentials, but it left a list of smaller things to put right. ## What is wrong - **A dependency has known advisories.** `urllib3` is locked at 2.7.0, which `pip-audit` reports under PYSEC-2026-4175, -4176 and -4177. All three are fixed in 2.8.0. - **Scratch files are tracked at the root.** `outA.json`, `outB.json` and an empty `pa.json` date from the first design commit and are used by nothing. - **The operator's network is written into the deploy docs.** `deploy/README.md`, `deploy/.env.example`, `deploy/forgejo/README.md` and `docs/environment.md` give LAN addresses, the Portainer address and an ssh login. None of it is reachable from outside, but a public runbook should read as an example to adapt, not as a map of one network. - **The old name is still in use.** `README.md`, `CLAUDE.md`, `openspec/config.yaml`, `deploy/README.md` and the image's source label point at `cmoriarty/openspec-flow`. The web redirect works; git over ssh does not follow it. - **There is no licence.** A public repository with no `LICENSE` grants a reader nothing. The owner has chosen MIT. - **There is no `SECURITY.md`** saying how to report a problem and what the trust model is (an internal tool, with no login in front on a private network). ## What should not change - The container image stays `forgejo.underthere.xyz/cmoriarty/openspec-flow`. A package's name is its own, not the repository's, and production pulls it by that name. - Production keeps working with no new variable to set on the stack before the deploy. - The `<!-- openspec-flow:begin -->` markers and the Python package name stay: runs and their AGENTS.md blocks depend on them. - The archived OpenSpec changes and the design documents of record are left as they were written. ## Out of scope Rewriting history to drop the run state committed in `184fb8e` (decided against: it holds no credential, and a force-push costs every clone). Rotating tokens. The Forgejo instance's own settings, which were fixed by hand on 2026-10-05 (OpenID sign-up off, 2FA on the admin account).
Author
Owner

Shipped in 67060dc and live on production since 2026-10-05 20:44Z; the change is archived as 2026-10-05-public-repo-tidy (f78da2b).

What shipped

  • urllib3 2.7.0 → 2.8.0 in uv.lock. pip-audit on the runtime requirements reports no known vulnerability, and the running container has 2.8.0.
  • outA.json, outB.json and pa.json are deleted.
  • deploy/README.md, deploy/forgejo/README.md, docs/environment.md and the README no longer give LAN addresses, the Portainer address or an ssh login.
  • Links and the image's source label point at cmoriarty/braid.
  • MIT licence: LICENSE, the field in pyproject.toml, and a line in the README.

What did not

  • No SECURITY.md: decided against.
  • The model server's private address stays as the default in deploy/docker-compose.yml, deploy/.env.example, src/osf/config.py, src/osf/notify.py, tools/demo.sh and tools/context_curve.py, so production and a laptop start with no new variable. openspec/specs/deployment/spec.md still names the VM's address in a requirement.
  • The container image keeps the name cmoriarty/openspec-flow.

Checks

The fast lane passed (2,603 backend tests, UI types, unit tests, build and browser specs). The image's self-check passed in the deploy.

One thing found on the way

The deploy's Portainer webhook was accepted and did nothing for three runs in a row (deploy runs 110, 111 and 112); production took the commit only after a manual Pull and redeploy. Runs 108 and 109 earlier the same day worked. The cause is not known yet and needs Portainer's own log.

Shipped in 67060dc and live on production since 2026-10-05 20:44Z; the change is archived as `2026-10-05-public-repo-tidy` (f78da2b). **What shipped** - `urllib3` 2.7.0 → 2.8.0 in `uv.lock`. `pip-audit` on the runtime requirements reports no known vulnerability, and the running container has 2.8.0. - `outA.json`, `outB.json` and `pa.json` are deleted. - `deploy/README.md`, `deploy/forgejo/README.md`, `docs/environment.md` and the README no longer give LAN addresses, the Portainer address or an ssh login. - Links and the image's source label point at `cmoriarty/braid`. - MIT licence: `LICENSE`, the field in `pyproject.toml`, and a line in the README. **What did not** - No `SECURITY.md`: decided against. - The model server's private address stays as the default in `deploy/docker-compose.yml`, `deploy/.env.example`, `src/osf/config.py`, `src/osf/notify.py`, `tools/demo.sh` and `tools/context_curve.py`, so production and a laptop start with no new variable. `openspec/specs/deployment/spec.md` still names the VM's address in a requirement. - The container image keeps the name `cmoriarty/openspec-flow`. **Checks** The fast lane passed (2,603 backend tests, UI types, unit tests, build and browser specs). The image's self-check passed in the deploy. **One thing found on the way** The deploy's Portainer webhook was accepted and did nothing for three runs in a row (deploy runs 110, 111 and 112); production took the commit only after a manual Pull and redeploy. Runs 108 and 109 earlier the same day worked. The cause is not known yet and needs Portainer's own log.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
cmoriarty/braid#146
No description provided.