Skip to content

security: define an explicit application payload for standalone packaging #510

Description

@codeforester

Goal

define an explicit application payload for standalone packaging.

Background and verified evidence

Review date: 2026-09-17. Reviewed commit: 38042cbf23b9380c626aae6c9fe168f97096c1cc. Parent: #214.

scripts/vendor builds the application portion through copy_tree, which enumerates every regular file beneath the supplied application directory. The documented workflow packages a project checkout directly. Define a reviewable distribution boundary for that application payload so development-only material cannot enter a distributable package by default. A local synthetic fixture confirmed the current traversal is broader than the runnable application. Detailed security reproduction material is retained locally rather than included in this public issue.

Scope and acceptance criteria

  • Use an explicit application distribution manifest or comparably bounded allowlist for consumer-owned payloads.
  • Exclude repository internals, local configuration, caches and previous output/staging trees by default; require an explicit reviewed inclusion rule for optional assets.
  • Reject unsafe/special entries and handle an output directory located inside the source tree.
  • Retain the generated app, consumer version/README, required runtime assets and verified framework copies; document the packaging boundary.

Validation

Use synthetic marker fixtures only, verify both included and excluded inventory, exercise the documented dist/app path, and run vendor/artifact tests plus full validation.

Non-goals

No unrelated API expansion or automatic release publication. Preserve immutable published assets and unrelated consumer files.

Project fields

  • Status: Ready
  • Priority: P1
  • Area: Security
  • Initiative: Adoption Polish
  • Size: M
  • Milestone: v2.2.0
  • Target date: unset; no delivery date has been committed.
  • Type: Task

Agent assignment

Assignee: codeforester. This is review/backlog intake; implementation has not started.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

securitySecurity hardening or vulnerability work

Type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions