diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c18490a..31f20b7 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -40,7 +40,7 @@ env: # which the 22.12.0 floor above does not satisfy, so installing it here would fail on a real # tag and only on a real tag. 11.19.0 accepts ^20.17.0 || >=22.9.0 and clears the OIDC floor. NPM_VERSION: "11.19.0" - IMAGE_NAME: ghcr.io/reesebuilt/agentwall + IMAGE_NAME: ghcr.io/repsecure/agentwall jobs: build: @@ -98,7 +98,7 @@ jobs: echo "version=${version}" echo "tag=${tag}" echo "is-release=${is_release}" - echo "tarball=reesebuilt-agentwall-${version}.tgz" + echo "tarball=repsecure-agentwall-${version}.tgz" } >> "$GITHUB_OUTPUT" echo "building ${tag} (release=${is_release})" @@ -328,7 +328,7 @@ jobs: # The binaries were built by this workflow from this tag, not by a person. slsa-verifier verify-artifact agentwall-verify-linux-amd64 \\ --provenance-path ${PROVENANCE} \\ - --source-uri github.com/reesebuilt/agentwall \\ + --source-uri github.com/repsecure/agentwall \\ --source-tag ${TAG} # The verifier shares no code with the tool that wrote the evidence. diff --git a/CHANGELOG.md b/CHANGELOG.md index b9a0d9b..836ec8f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -83,7 +83,7 @@ decision, policy file, or enforcement behavior moved in this release. - Approval webhook notifications for queued and resolved manual reviews via `approval.webhookUrl`. ### Changed -- The npm package is published as `@reesebuilt/agentwall`. The unscoped name `agentwall` on npm +- The npm package is published as `@repsecure/agentwall`. The unscoped name `agentwall` on npm belongs to an unrelated project and always has. The installed command is still `agentwall`. - The supported Node floor is 22.12.0, declared in `engines`. Node 20 reached end of life in April 2026 and a security tool should not advertise a runtime that stops receiving fixes. diff --git a/README.md b/README.md index 4e780d0..e3a2b4a 100644 --- a/README.md +++ b/README.md @@ -10,7 +10,7 @@ and keeps a record that cannot be quietly rewritten.
-
+
@@ -56,19 +56,19 @@ The rest of the limits are in [Limits](#limits). They are not footnotes.
Linux, Node.js 22.12 or newer. Verified on Node 24.14.1.
```bash
-npm install -g @reesebuilt/agentwall
+npm install -g @repsecure/agentwall
agentwall init --mode monitor
agentwall doctor
```
The npm package named `agentwall`, without a scope, is a different and unrelated project. This
-one is `@reesebuilt/agentwall`; the command it installs is `agentwall`.
+one is `@repsecure/agentwall`; the command it installs is `agentwall`.
From a checkout instead:
```bash
-git clone https://github.com/reesebuilt/agentwall.git
+git clone https://github.com/repsecure/agentwall.git
cd agentwall
npm install
npm run build
@@ -250,7 +250,7 @@ go list -m all
```
```
-github.com/reesebuilt/agentwall/verifier
+github.com/repsecure/agentwall/verifier
```
One line, and it is this module. SHA-256, Ed25519, SPKI parsing, and JSON all come from the Go
diff --git a/docs/install.md b/docs/install.md
index b7539e6..f4d5946 100644
--- a/docs/install.md
+++ b/docs/install.md
@@ -12,7 +12,7 @@
## Local source install
```bash
-git clone https://github.com/reesebuilt/agentwall
+git clone https://github.com/repsecure/agentwall
cd agentwall
npm install
npm run build
diff --git a/package-lock.json b/package-lock.json
index 3b2231e..4d93db7 100644
--- a/package-lock.json
+++ b/package-lock.json
@@ -1,11 +1,11 @@
{
- "name": "@reesebuilt/agentwall",
+ "name": "@repsecure/agentwall",
"version": "0.2.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
- "name": "@reesebuilt/agentwall",
+ "name": "@repsecure/agentwall",
"version": "0.2.0",
"license": "Apache-2.0",
"dependencies": {
diff --git a/package.json b/package.json
index fa75c6e..2941334 100644
--- a/package.json
+++ b/package.json
@@ -1,14 +1,14 @@
{
- "name": "@reesebuilt/agentwall",
+ "name": "@repsecure/agentwall",
"version": "0.2.0",
"description": "Agentwall: provenance-aware policy enforcement for agent egress, tools, content, and approvals",
- "homepage": "https://github.com/reesebuilt/agentwall#readme",
+ "homepage": "https://github.com/repsecure/agentwall#readme",
"bugs": {
- "url": "https://github.com/reesebuilt/agentwall/issues"
+ "url": "https://github.com/repsecure/agentwall/issues"
},
"repository": {
"type": "git",
- "url": "git+https://github.com/reesebuilt/agentwall.git"
+ "url": "git+https://github.com/repsecure/agentwall.git"
},
"main": "dist/index.js",
"scripts": {
diff --git a/verifier/README.md b/verifier/README.md
index f7b8119..da43ef4 100644
--- a/verifier/README.md
+++ b/verifier/README.md
@@ -35,7 +35,7 @@ the FORMAT.
Zero third party dependencies is a property you check rather than a claim you accept:
cd verifier && go list -m all
- github.com/reesebuilt/agentwall/verifier
+ github.com/repsecure/agentwall/verifier
One line, and it is this module. SHA-256, Ed25519, SPKI parsing, and JSON all come from the Go
standard library, maintained by the Go security team, so a reader auditing this verifier reads this
diff --git a/verifier/go.mod b/verifier/go.mod
index 402e8c3..0e394ea 100644
--- a/verifier/go.mod
+++ b/verifier/go.mod
@@ -1,3 +1,3 @@
-module github.com/reesebuilt/agentwall/verifier
+module github.com/repsecure/agentwall/verifier
go 1.22