Skip to content
220 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1import { RefreshCw, ShieldCheck } from "lucide-react";
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily2import { useFetcher, useSearchParams } from "react-router";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API3
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily4import type { AlertState, DismissReason } from "@g1t/contracts";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API5
6import type { Route } from "./+types/security";
7import { page } from "../../lib/meta";
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily8import {
9 type PullInfo,
10 ScanSummary,
11 SeverityCountsGrid,
12 StateFilter,
13 type UpgradeFix,
14 VulnerabilityList,
15} from "../../components/security";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API16import { Switch } from "../../components/ui/switch";
17import { security, work } from "../../lib/services.server";
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look18import { assertSameOrigin, getViewer, requireUser, unwrap } from "../../lib/session.server";
19import { refusal, requireInsider } from "../../lib/access.server";
20import { whyNot } from "../../lib/access";
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar21import { alertCapability, countByState, parseAlertState } from "../../lib/security-alerts";
22import { severityCounts } from "../../lib/security-suite";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API23
24export function meta({ params, ...args }: Route.MetaArgs) {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar25 return page(args, { title: `Vulnerabilities · ${params.owner}/${params.repo} · g1t` });
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API26}
27
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily28/** Upgrade issues and security update pull requests looked up per page, at most. */
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API29const MAX_FIXES = 30;
30
31export async function loader({ params, context, request }: Route.LoaderArgs) {
32 // Git's refusal links here; someone signed out signs in first.
33 const viewer = getViewer(context) ?? requireUser(context, request);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look34 // Findings are for people who can push, public project or not: Write and up.
35 const { access } = await requireInsider(context, params, "push");
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API36 const repo = { namespace: params.owner, name: params.repo };
37 const overview = unwrap(await security.overview(repo, viewer));
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily38 const unique = (numbers: (number | null | undefined)[]) =>
39 [...new Set(numbers.filter((n): n is number => n != null))].slice(0, MAX_FIXES);
40 // Security updates' pull requests, for their live status.
41 const pullNumbers = unique(overview.vulnerabilities.map((vuln) => vuln.update?.pull));
42 // Older upgrade issues, from before g1t opened pull requests itself.
43 const issueNumbers = unique(overview.vulnerabilities.filter((vuln) => !vuln.update).map((vuln) => vuln.issue));
44 const [pullDetails, issueDetails] = await Promise.all([
45 Promise.all(pullNumbers.map((number) => work.getPull(repo, number, viewer).catch(() => null))),
46 Promise.all(issueNumbers.map((number) => work.getIssue(repo, number, viewer).catch(() => null))),
47 ]);
48 const pulls: Record<number, PullInfo> = {};
49 for (const found of pullDetails) {
50 if (!found?.ok) continue;
51 const { pull } = found.value;
52 pulls[pull.number] = { number: pull.number, status: pull.status, title: pull.title };
53 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API54 const fixes: Record<number, UpgradeFix> = {};
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily55 for (const found of issueDetails) {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API56 if (!found?.ok) continue;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily57 const { issue, pulls: issuePulls } = found.value;
58 const latest = issuePulls.at(-1) ?? null;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API59 fixes[issue.number] = {
60 number: issue.number,
61 state: issue.state,
62 resolvedBy: issue.resolvedBy,
63 pull: latest ? { number: latest.number, status: latest.status, agent: latest.runtime === "hosted" ? latest.agent : null } : null,
64 };
65 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily66 return { overview, fixes, pulls, can: access.can };
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API67}
68
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily69const DISMISS_REASONS = new Set<string>([
70 "false_positive",
71 "used_in_tests",
72 "revoked",
73 "wont_fix",
74 "fix_started",
75 "no_bandwidth",
76 "tolerable_risk",
77 "inaccurate",
78 "not_used",
79]);
80
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API81export async function action({ params, context, request }: Route.ActionArgs) {
82 assertSameOrigin(request);
83 const user = requireUser(context, request);
84 const repo = { namespace: params.owner, name: params.repo };
85 const form = await request.formData();
86 const intent = String(form.get("intent") ?? "");
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily87 const id = String(form.get("id") ?? "");
88 // Scanning spends compute (Write); security updates are a setting
89 // (Maintain); a secret alert is dismissed or reopened by Admins, who
90 // manage the repository's secrets, and a dependency alert by Write.
91 const capability =
92 intent === "rescan" ? "run" : intent === "upkeep" ? "manage_settings" : intent === "dismiss" || intent === "reopen" ? alertCapability(id) : null;
93 if (!capability) return { ok: false, error: "Unknown action." };
94 const refused = await refusal(context, params, capability);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look95 if (refused) return { ok: false, error: refused };
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily96 if (intent === "dismiss") {
97 const reason = String(form.get("reason") ?? "");
98 if (!DISMISS_REASONS.has(reason)) return { ok: false, error: "Choose a reason." };
99 const comment = String(form.get("comment") ?? "").trim().slice(0, 500);
100 const dismissed = await security.dismiss(user, repo, id, reason as DismissReason, comment);
101 return dismissed.ok ? { ok: true } : { ok: false, error: dismissed.error.message };
102 }
103 if (intent === "reopen") {
104 const reopened = await security.reopen(user, repo, id);
105 return reopened.ok ? { ok: true } : { ok: false, error: reopened.error.message };
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API106 }
107 if (intent === "rescan") {
108 const scanned = await security.rescan(user, repo);
109 return scanned.ok ? { ok: true } : { ok: false, error: scanned.error.message };
110 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily111 const set = await security.setUpkeep(user, repo, form.get("enabled") === "true");
112 return set.ok ? { ok: true } : { ok: false, error: set.error.message };
113}
114
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API115export default function ProjectSecurity({ loaderData, params }: Route.ComponentProps) {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily116 const { overview, fixes, pulls, can } = loaderData;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API117 const base = `/${params.owner}/${params.repo}`;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar118 const action = `${base}/security/vulnerabilities`;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API119 const [search, setSearch] = useSearchParams();
120 const rescan = useFetcher<{ ok: boolean; error?: string }>();
121 const upkeep = useFetcher<{ ok: boolean; error?: string }>();
122 const upkeepOn = upkeep.formData ? upkeep.formData.get("enabled") === "true" : overview.upkeep;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily123 const vulnCounts = countByState(overview.vulnerabilities);
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar124 // A link to one alert shows it wherever it stands.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API125 const focus = search.get("finding");
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar126 const focused = focus ? overview.vulnerabilities.find((vuln) => vuln.id === focus) : undefined;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily127 const state: AlertState = search.get("state") ? parseAlertState(search.get("state")) : (focused?.state ?? "open");
128 const navigate = (change: (next: URLSearchParams) => void) => {
129 const next = new URLSearchParams(search);
130 change(next);
131 next.delete("finding");
132 setSearch(next, { replace: true, preventScrollReset: true });
133 };
134 const setState = (value: AlertState) =>
135 navigate((next) => (value === "open" ? next.delete("state") : next.set("state", value)));
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API136 return (
137 <div className="max-w-5xl">
138 <div className="flex flex-wrap items-start justify-between gap-4">
139 <div>
140 <h2 className="flex items-center gap-2 text-xl font-semibold tracking-tight">
141 <ShieldCheck size={19} className="text-accent" />
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar142 Vulnerabilities
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API143 </h2>
144 <p className="mt-1.5 max-w-2xl text-sm text-muted">
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar145 Every package the lockfiles resolve is checked for known vulnerabilities, on every push to the default branch and
146 daily. With security updates on, g1t opens a pull request to upgrade each one that has a fix.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API147 </p>
148 </div>
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily149 {can.run && (
150 <rescan.Form method="post" action={action}>
151 <input type="hidden" name="intent" value="rescan" />
152 <button
153 type="submit"
154 disabled={rescan.state !== "idle"}
155 className="inline-flex items-center gap-2 rounded-md border border-line px-3 py-1.5 text-sm text-fg/80 transition-colors hover:border-line-strong hover:bg-surface hover:text-fg disabled:opacity-50"
156 >
157 <RefreshCw size={14} className={rescan.state !== "idle" ? "animate-spin" : ""} />
158 {rescan.state !== "idle" ? "Scanning…" : "Re-scan now"}
159 </button>
160 {rescan.data?.error && <p className="mt-1.5 text-xs text-danger">{rescan.data.error}</p>}
161 </rescan.Form>
162 )}
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API163 </div>
164
165 <div className="mt-6">
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar166 <SeverityCountsGrid counts={severityCounts(overview.vulnerabilities)} />
167 <p className="mt-2 text-xs text-faint">Open vulnerability alerts by severity.</p>
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API168 </div>
169
170 <div className="mt-4">
171 <ScanSummary scan={overview.scan} />
172 </div>
173
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar174 <div className="mt-8">
175 <div>
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily176 <StateFilter counts={vulnCounts} value={state} onChange={setState} />
177 <div className="mt-3">
178 <VulnerabilityList
179 vulnerabilities={overview.vulnerabilities.filter((vuln) => vuln.state === state)}
180 state={state}
181 activity={overview.activity}
182 fixes={fixes}
183 pulls={pulls}
184 upkeep={overview.upkeep}
185 base={base}
186 action={action}
187 focus={focus}
188 canDismiss={can.push}
189 />
190 </div>
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar191 </div>
192 </div>
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily193
194 <section className="mt-10" aria-labelledby="security-settings">
195 <h3 id="security-settings" className="text-base font-semibold tracking-tight">
196 Settings
197 </h3>
198 <div className="mt-3 space-y-3">
199 <label className="flex cursor-pointer items-start justify-between gap-4 rounded-xl border border-line bg-surface p-4 transition-colors hover:border-line-strong">
200 <span className="min-w-0">
201 <span className="block text-sm font-medium">Security updates</span>
202 <span className="mt-1 block text-sm text-muted">
203 Open a pull request to upgrade each vulnerable dependency that has a fix. It lands through your branch's
204 required checks.
205 </span>
206 {upkeep.data?.error && <span className="mt-1 block text-xs text-danger">{upkeep.data.error}</span>}
207 </span>
208 <Switch
209 className="mt-0.5"
210 checked={upkeepOn}
211 disabled={upkeep.state !== "idle" || !can.manage_settings}
212 title={whyNot(can, "manage_settings")}
213 onCheckedChange={(checked) => upkeep.submit({ intent: "upkeep", enabled: String(checked) }, { method: "post", action })}
214 />
215 </label>
216 </div>
217 </section>
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API218 </div>
219 );
220}