Urgent.News

What's breaking now, across thousands of outlets.

Tech

Four supply-chain badges for a one-person open-source project, in a day

I maintain schemagate , an open-source library and MCP server that stops an AI agent from seeing database tables the user isn't allowed to read. It's a security tool, so "trust me" isn't good enough. A security team looking at it reasonably asks: is the project run properly, is the licensing clean, and is the package on PyPI really built from this repository? There are free, public answers to all…

Maintaining schemagate, an open-source library and MCP server that safeguards AI agents from unauthorized database access, requires adherence to several security certifications and compliance standards. To verify the project's integrity, four distinct badges were obtained in a single day.

Firstly, the OpenSSF Best Practices certification was achieved. This self-assessment covers essential aspects such as handling vulnerabilities, testing, and static analysis. By carefully examining the repository, proper links to existing files were provided as evidence, and CodeQL, a static analysis tool, yielded zero alerts. The only unmet criterion was the absence of dynamic analysis, which is suggested but not mandatory at this level. Hence, the project secured a passing grade of 100%.

Next, the OpenSSF Baseline Level 1 certification was secured. This checklist assesses critical security controls, with most requirements already fulfilled. The sole requirement that needed adjustment was the implementation of branch protection, ensuring that commits to the main branch necessitate a successful CI check. By enforcing pull requests and disabling the admin bypass, this criterion was met, resulting in an additional 100% score.

The REUSE compliance (FSFE) certification confirmed that each file within the repository contains machine-readable copyright and license information. This is crucial for legal teams scrutinizing dependencies. By utilizing the reuse lint tool, missing copyright and license details were identified, such as a bundled BLAKE2b implementation and a test fixture derived from the MCP registry's schema. Registration at api.reuse.software followed, after which the checker confirmed compliance for all 238 files.

Lastly, the SLSA Build Level 3 certification addressed the question of whether the PyPI-hosted file was genuinely derived from the repository. The official slsa-github-generator was employed to generate a provenance statement, verifying that the installed files match the original source. After validating the PyPI package's integrity through the slsa-verifier, both the built wheel and source distribution (sdist) successfully passed verification.

It was crucial to align the verification command with the workflow's default branch, as the tag verification process failed. A total of 238 files were confirmed compliant, satisfying the SLSA requirements.

In summary, by diligently following these four steps—OpenSSF Best Practices, Baseline Level 1, REUSE compliance, and SLSA Build Level 3—one can establish a robust security posture for an open-source project like schemagate. Each badge not only emphasizes the importance of security but also streamlines the process for subsequent certifications. The complete documentation is available on the project's README at https://github.com/ashishsinha1602/schemagate.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at dev.to →

More in Tech

NestJS tip: how to try any official sample in seconds

Let's say you want to run one of the official NestJS samples, the ones under the sample folder of the nestjs/nest repository, to see how some feature looks like in a real app.

  • New tool lets you run NestJS samples in seconds
  • Requires Node.js 22 or higher to use npx try-nest@latest
  • Samples list updates automatically from nestjs/nest repo

Your Agent Wrapped the Whole Function in try/catch and Called It Error Handling

The pattern that shows up in every agent PR You paste a stack trace into your agent. Twenty seconds later it comes back with a diff like this: def get_user_profile ( user_id ): try : row = db .

  • Try/catch blocks in functions labeled as error handling.
  • Real error handling requires answering three questions for each caught exception.
  • Blanket except Exception statements fail to address these questions adequately.

Small Business Uptime Explained: 4 EU Signals Across SaaS and Self-Hosted Monitoring

A small property-management app should start with externally hosted uptime checks for its public health endpoint and heartbeat checks for delivery jobs.

  • Start with externally hosted uptime checks for public health endpoints.
  • Transition to self-hosted monitors when data location or control is crucial.
  • Use four signals: reachability, dependency readiness, job completion, and delivery outcome.

How to reduce data consumption on iPhone with simple settings

This iPhone guide covers system and app-level ways to reduce cellular data use. It explains what Low Data Mode changes, how to review usage by app, and how to limit background refresh or disable…

  • Enable Low Data Mode in Settings Cellular Data Mode to reduce data usage.
  • Control background app refresh per app or set to Wi-Fi only via Settings Wi-Fi.
  • Pre-download media for offline use and disable automatic downloads to save data.

KisanConnect Innohacks 4.0

This is a submission for the MLH x DEV Writing Challenge What I Built India has over 100 million farming households, and most of them make their biggest decisions on guesswork: what to plant this…

  • KisanConnect platform aids 100 million Indian farmers
  • App provides personalized crop recommendations
  • Features include disease detection and weather forecasts

More from Saturday 10 October →