Report privately through GitHub's private vulnerability reporting on this repository. Please do not open a public issue for a security problem.
Include what you did, what happened, and the Forgelore version (forgelore version).
You will get an acknowledgement within a week.
Every release artifact is built by a tag-triggered workflow and attested there, before the release is created. To check that a binary came from that workflow and not from somewhere else:
gh attestation verify forgelore_linux_amd64 -R forgeprint/forgeloreOn gh 2.102 that prints nothing when it succeeds, so read the exit status
rather than the output. A binary the workflow did not build is refused with
a 404: no attestation exists for its digest. To see what the attestation
actually claims — the workflow, the tag and the commit — add --format json.
SHA256SUMS answers a narrower question — whether the bytes are the
published ones — and works offline. It cannot answer who published them,
because it travels in the same release as the binaries.
Two things are deliberately not covered, and are worth knowing before you rely on this:
- the npm packages
[email protected]and0.1.5, which were published by hand and carry no provenance. From v0.1.6 they are published by a workflow using npm trusted publishing, andnpm audit signaturesreports a verified attestation (ADR-0024); - operating-system code signing. Sigstore means nothing to macOS Gatekeeper or Windows SmartScreen, and you will still meet their warnings.
Forgelore stores a project's accumulated debugging knowledge and feeds parts of it back into a coding agent's context. That makes two things security-relevant:
Secrets reaching disk or a git remote. Records are plain files in the
repository. Redaction runs before a record is written, common credential
patterns are masked, and content inside a <private> tag is never stored. Team
records are additionally scanned before they can be committed. Local records
stay out of git entirely.
Persistent prompt injection. A record that an agent reads later is an
instruction channel. Candidate records derived from content an agent fetched
from the network are marked tainted and never become team memory without an
explicit human review step.
Forgelore makes no network calls of its own, sends no telemetry, and runs no background service.
In scope: anything that writes an unredacted secret to disk or to git, anything that lets untrusted content become a trusted record without review, and any path where a hook failure can block or alter an agent's work beyond injecting a hint.
Out of scope: vulnerabilities in the coding agents themselves, and in the projects Forgelore is installed into.