Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
84 commits
Select commit Hold shift + click to select a range
9ad77df
Harden production services and standardize PostgreSQL
Sep 3, 2026
582c7e1
Resolve settlement screening and migration release blockers
Sep 3, 2026
199ef6c
Add signed ledger identity authorization coverage
Sep 3, 2026
a8dcfcb
Record ledger test dependency lockfile
Sep 3, 2026
f59ad75
Harden gateway controls and add Parquet archive worker
Sep 4, 2026
c4caf59
feat: add Nigeria-first consumer intelligence platform controls
Sep 4, 2026
22730e6
feat: encrypt outbox and offline field evidence
Sep 4, 2026
ddd1221
feat: enforce encryption key expiry and harden field queues
Sep 4, 2026
2eee35b
security: harden mobile sessions and KYC offline uploads
Sep 4, 2026
ead1ef1
release: add staged promotion and OBS-001 gates
Sep 4, 2026
85ac522
feat: add consumer dispute and provider authorization controls
Sep 4, 2026
ac167e6
fix: enforce consumer dispute integrity and evidence checksums
Sep 4, 2026
589c2bf
feat: close consumer dispute escalation workflow
Sep 4, 2026
7b37aaf
feat: support portable on-prem evidence custody
Sep 4, 2026
ddb9033
feat: add isolated on-prem KMS validation profile
Sep 4, 2026
42ff695
feat: verify on-prem KMS failures and tenant permissions
Sep 4, 2026
fe91b0b
feat: harden institutional, biometric and commercial controls
Sep 4, 2026
db8ebe4
feat: add explainable investigation intelligence controls
Sep 4, 2026
6829393
feat: meter intelligence assessments with durable ledger events
Sep 5, 2026
110e9cd
test: cover intelligence billing concurrency and exhaustion
Sep 5, 2026
d204bbd
feat: reconcile exhausted intelligence ledger charges
Sep 5, 2026
87acc71
test: verify billing reconciliation transitions
Sep 5, 2026
fac2ac5
feat: monitor and benchmark billing reconciliation claims
Sep 5, 2026
2b33645
feat: add tracing recovery and production rbac controls
Sep 5, 2026
512b7be
feat: add trace observability and helm rolling deployments
Sep 5, 2026
7ca8c10
feat: add adverse action and PII envelope controls
Sep 5, 2026
436ce85
feat: harden adverse action delivery workflow
Sep 5, 2026
dc82d37
feat: add Vault Transit PII rotation controls
Sep 5, 2026
e4d4ae5
fix: delegate staged PII key registration
Sep 5, 2026
73016a4
fix: validate dry-run rotation counts independently
Sep 5, 2026
a98b6db
feat: add PII cutover smoke safeguards
Sep 5, 2026
6aa9119
fix: pin Transit provider versions in PII guards
Sep 5, 2026
ef26011
fix: harden PII custody authorization
Sep 5, 2026
edc6943
feat: enforce tenant RLS for PII custody
Sep 5, 2026
86dc6de
test: stress tenant RLS dispatch isolation
Sep 5, 2026
c8f83bd
feat: monitor tenant RLS rotation controls
Sep 5, 2026
4d069ac
test: harden RLS pool contamination cleanup
Sep 5, 2026
ba95026
test: emit RLS rehearsal metric snapshots
Sep 5, 2026
044a208
fix: reject invalid tenant IDs before RLS queries
Sep 5, 2026
66477d3
test: measure RLS dispatch queue latency
Sep 5, 2026
110fdb3
test: measure RLS pool saturation at 512 workers
Sep 5, 2026
33b1e51
feat: harden RLS transaction pooling recovery
Sep 5, 2026
6b72e11
feat: terminalize exhausted PII rotation dispatches
Sep 5, 2026
62dc536
fix: isolate named PII rotation terminalization
Sep 6, 2026
ff34dbc
feat: verify PII forensic audit readback
Sep 6, 2026
71d9fbe
feat: paginate verified PII forensic audits
Sep 6, 2026
78cbd8a
perf: index verified forensic keyset pagination
Sep 6, 2026
81b2147
feat: expire verified forensic cursors
Sep 6, 2026
1281b16
feat: rotate signed forensic cursor keys
Sep 6, 2026
2eed204
test: cover concurrent forensic cursor key rotation
Sep 7, 2026
b3f0d14
feat: stream verified forensic audit exports
Sep 7, 2026
140da90
feat: verify forensic NDJSON export completeness
Sep 7, 2026
055cf01
fix: bound forensic audit PWA memory
Sep 7, 2026
1070a9b
fix: isolate mobile CI dependency install
Sep 7, 2026
3d4e727
fix: harden lakehouse query execution
Sep 7, 2026
d006713
fix: harden headers and random generation
Sep 7, 2026
b0bbca7
test: cover all approved lakehouse plans
Sep 7, 2026
d2d4947
fix: enforce trusted TLS provider endpoints
Sep 7, 2026
80b69e3
feat: centralize Rust outbound transport policy
Sep 7, 2026
f02fa33
fix: apply trusted HTTPS policy to stream services
Sep 8, 2026
51a60c2
style: format event transport policy integration
Sep 8, 2026
b57dd34
fix: centralize remaining service HTTP clients
Sep 8, 2026
81546ab
fix: harden Rust telemetry and dependencies
Sep 8, 2026
0bb6e89
refactor: share screening and ledger transport policy
Sep 8, 2026
05cc6e2
fix: require encrypted event transports
Sep 8, 2026
d02f83c
fix: encapsulate trusted ledger requests
Sep 8, 2026
c1e6127
chore: lock trusted transport dependencies
Sep 8, 2026
2c8361f
chore: lock shared transport serialization
Sep 8, 2026
ff1e2c0
fix: bound velocity gateway payloads
Sep 8, 2026
37156d3
feat: add trusted endpoint CodeQL model pack
Sep 8, 2026
c8dff45
fix: align authoritative mobile client contracts
Sep 8, 2026
fe203a0
fix: collect mobile KYC subject references
Sep 8, 2026
2be7873
fix: send captured mobile KYC payloads
Sep 8, 2026
4ee55ff
chore: gate releases on authoritative mobile client
Sep 8, 2026
def01a3
fix: harden trusted transport requests and payload bounds
Sep 8, 2026
60e5d6b
fix: type and validate authoritative mobile client
Sep 9, 2026
56cb70f
fix: restore mobile CI typing and bound gateway encoding
Sep 9, 2026
d5de37c
fix: hard bound gateway request body allocation
Sep 9, 2026
118782a
fix: prevent stale PWA entry caching
Sep 10, 2026
94b2917
fix: fail closed financial rail controls
Sep 10, 2026
8b8e1fe
fix: harden payment outbox and ledger replay protection
Sep 10, 2026
c1eed45
feat: reconcile payment escalations with four-eyes controls
Sep 10, 2026
e964b5d
test: generate ledger replay nonce per request
Sep 10, 2026
4daa880
test: verify concurrent payment reconciliation controls
Sep 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
34 changes: 34 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# Local dependencies and generated outputs
**/node_modules
dist
**/dist
**/android/.gradle
**/android/app/build
**/ios/build

# Repository metadata and local development files
.git
.github
.devcontainer
.vscode
.idea
*.log
*.tmp
*.swp

# Evidence and local environment material
artifacts
coverage
bis-evidence
.env
.env.*
!.env.example

# Dependency-specific caches
.pnpm-store
.npm
.yarn
__pycache__
*.pyc
.target
target
28 changes: 14 additions & 14 deletions .github/branch-protection.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,20 +4,22 @@
"required_status_checks": {
"strict": true,
"contexts": [
"Node.js CI / test",
"Go CI / test",
"Rust CI / test",
"Python CI / test",
"Security Scan / codeql-analyze",
"Docker Build / build"
"node-tests",
"gateway-race",
"archive-worker",
"mobile-security",
"CodeQL (JavaScript/TypeScript)",
"CodeQL (Go)",
"CodeQL (Python)",
"CodeQL (Rust)"
]
},
"enforce_admins": false,
"enforce_admins": true,
"required_pull_request_reviews": {
"dismissal_restrictions": {},
"dismiss_stale_reviews": true,
"require_code_owner_reviews": true,
"required_approving_review_count": 1
"required_approving_review_count": 2
},
"restrictions": null,
"required_linear_history": true,
Expand All @@ -29,11 +31,9 @@
"allow_fork_syncing": false
},
"notes": [
"Apply via: gh api repos/{owner}/{repo}/branches/main/protection -X PUT --input .github/branch-protection.json",
"Requires admin access to the repository",
"All CI checks must pass before merge",
"At least 1 code owner review required",
"Stale reviews are dismissed on new commits",
"Linear history (no merge commits) required"
"Apply only after the named checks appear on a pull request with: gh api repos/{owner}/{repo}/branches/main/protection -X PUT --input .github/branch-protection.json",
"Requires repository administration and should be reviewed as a change-control operation.",
"The protected production environment in .github/workflows/production-promotion.yml adds a separate manual approval after staging device/KMS and OBS-001 gates pass.",
"No mutable image tag, host-side image build, unreviewed migration, or unapproved production environment deployment is accepted by the promotion workflow."
]
}
45 changes: 45 additions & 0 deletions .github/codeql/bis-rust-models/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# BIS Rust CodeQL transport-security model pack

This model pack teaches CodeQL Rust analyses about two narrow, reviewed boundaries:
a successful `TrustedEndpoint::parse` result is a validated endpoint, and a
`BoundedGatewayPayload::into_bytes` result is a fixed-capacity HTTP body. The
endpoint parser enforces an absolute HTTPS URL, an exact configured host allow-list,
and rejects userinfo, query strings, and fragments.

## Security scope

The model contains exactly two narrow barriers:

```text
<bis_transport_policy::TrustedEndpoint>::parse
-> ReturnValue.Field[core::result::Result::Ok(0)]
-> request-forgery

<fluvio_velocity::BoundedGatewayPayload>::into_bytes
-> ReturnValue
-> resource-exhaustion
```

It does **not** model `with_path_segments` or the gateway payload encoder as a
barrier. Any future request-derived path segment or unbounded serialization path
therefore remains visible to CodeQL. Do not add a broader barrier or neutral model
without a security review and a negative test.

## Publishing

1. Review the model against the current canonical Rust path in the CodeQL
database and bump `version` in `qlpack.yml` for any semantic change.
2. Run the manual-only **Publish BIS CodeQL Rust Model Pack** workflow.
3. Confirm the immutable `munisp/bis-rust-models@<version>` package exists in
the organization GitHub Container Registry.
4. Enable `.github/codeql/codeql-config.published-model-pack.yml` for the
Rust-specific CodeQL initialization, pinning the exact published version.
5. Verify the next CodeQL comparison resolves only the intended trusted-endpoint
SSRF flows and fixed-capacity payload conversion, while still reporting a
deliberately unsafe path-segment or unbounded-serialization regression.

## Rollback

Revert the CodeQL configuration reference to the prior known-good model-pack
version. Do not delete a published immutable package version or dismiss a
security alert merely because analysis configuration changed.
14 changes: 14 additions & 0 deletions .github/codeql/bis-rust-models/models/trusted-endpoint.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
extensions:
- addsTo:
pack: codeql/rust-all
extensible: barrierModel
data:
# TrustedEndpoint::parse rejects non-HTTPS schemes, non-allow-listed hosts,
# userinfo, query strings, and fragments before it returns Ok(endpoint).
# This barrier deliberately does not model with_path_segments so future
# user-controlled path segments remain visible to request-forgery analysis.
- ["<bis_transport_policy::TrustedEndpoint>::parse", "ReturnValue.Field[core::result::Result::Ok(0)]", "request-forgery", "manual"]
# BoundedGatewayPayload owns a fixed 16 KiB array and can only be built
# after every variable-width field and final serialized length are checked.
# Model only its conversion to an HTTP body; do not model the encoder itself.
- ["<fluvio_velocity::BoundedGatewayPayload>::into_bytes", "ReturnValue", "resource-exhaustion", "manual"]
7 changes: 7 additions & 0 deletions .github/codeql/bis-rust-models/qlpack.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
name: munisp/bis-rust-models
version: 0.1.0
library: true
extensionTargets:
codeql/rust-all: '>=0.0.0'
dataExtensions:
- models/**/*.yml
7 changes: 7 additions & 0 deletions .github/codeql/codeql-config.published-model-pack.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Activate this file only after munisp/bis-rust-models@0.1.0 is published
# to the organization GitHub Container Registry and the repository workflow
# is switched to a single Rust-language CodeQL initialization or equivalent
# Rust-specific configuration.
name: BIS CodeQL Configuration
packs:
- munisp/bis-rust-models@0.1.0
87 changes: 71 additions & 16 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,33 +2,34 @@ name: BIS Validation

on:
pull_request:
branches: [main]
branches: [main, hardening/production-readiness]
push:
branches: [main]
branches: [main, hardening/production-readiness]

permissions:
contents: read

jobs:
bff:
name: bff-validation
runs-on: ubuntu-latest
node-tests:
name: node-tests
runs-on: ubuntu-24.04
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_USER: bis_user
POSTGRES_PASSWORD: bis_secure_2026
POSTGRES_DB: bis_db
POSTGRES_USER: bis_ci
POSTGRES_PASSWORD: bis_ci_disposable_password
POSTGRES_DB: bis_ci
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U bis_user -d bis_db"
--health-cmd "pg_isready -U bis_ci -d bis_ci"
--health-interval 10s
--health-timeout 5s
--health-retries 5
--health-retries 10
env:
DATABASE_URL: postgresql://bis_user:bis_secure_2026@localhost:5432/bis_db
DATABASE_URL: postgresql://bis_ci:bis_ci_disposable_password@localhost:5432/bis_ci
BIS_DATABASE_URL: postgresql://bis_ci:bis_ci_disposable_password@localhost:5432/bis_ci
JWT_SECRET: ci-session-secret-not-for-production
KEYCLOAK_URL: https://auth.bis.invalid
KEYCLOAK_REALM: bis
Expand All @@ -42,11 +43,65 @@ jobs:
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Initialize disposable PostgreSQL test schema
run: pnpm drizzle-kit push --force
- name: Apply canonical PostgreSQL migrations
run: pnpm db:migrate
- name: Type-check
run: pnpm check --noEmit
run: pnpm check
- name: Production build
run: pnpm run build
- name: Test
run: pnpm build
- name: Node integration suite
run: pnpm test

gateway-race:
name: gateway-race
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v6
with:
go-version-file: services/gateway/go.mod
cache-dependency-path: services/gateway/go.sum
- name: Gateway control-plane race suite
working-directory: services/gateway
run: go test -race ./...

archive-worker:
name: archive-worker
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v6
with:
go-version-file: services/cold-archive-writer/go.mod
cache-dependency-path: services/cold-archive-writer/go.sum
- name: Archive worker static and race checks
working-directory: services/cold-archive-writer
run: |
go vet ./...
go test -race ./...

mobile-security:
name: mobile-security
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
cache-dependency-path: |
pnpm-lock.yaml
bis-mobile/pnpm-lock.yaml
- name: Reject deprecated mobile client references
run: ./scripts/check-deprecated-mobile-references.sh
- name: Install typed AppRouter dependencies
run: pnpm install --frozen-lockfile
- name: Install authoritative native client dependencies
working-directory: bis-mobile
run: pnpm install --frozen-lockfile --ignore-workspace
- name: Validate authoritative native client
working-directory: bis-mobile
run: |
pnpm typecheck
pnpm lint
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: CodeQL Security Analysis

on:
push:
branches: [main]
branches: [main, hardening/production-readiness]
pull_request:
branches: [main]
branches: [main, hardening/production-readiness]
schedule:
- cron: "17 3 * * 1"

Expand Down
Loading
Loading