Use the TRAMITON_FETCH_TOKEN repo secret (Gitea PAT) to fetch tramiton-core over
HTTPS. Deploy-key path dropped per preference; the PAT has been added to secrets.
Refs #118.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Gitea PATs can't be scoped to a single repo and the ephemeral Actions token
can't clone a private git dependency (verified: "Repository not found" even with
Collaborative Owners + the actions/checkout extraheader form). A read-only Deploy
Key is per-repo least privilege: load it from the TRAMITON_DEPLOY_KEY secret and
let cargo fetch tramiton over SSH (dep URL is already ssh://…:22222).
Refs #118.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The placeholder-username URL form returned "Repository not found". Switch to the
canonical http.extraheader Basic-auth used by actions/checkout
(x-access-token:<token>) to remove the username variable. Definitive test of
whether the Collaborative Owner grant covers a cargo git-dep clone.
Refs #118.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
sharang/tramiton lists sharang as a Collaborative Owner (tramiton → Settings →
Actions), so this repo's Actions can read tramiton. Use ${{ github.token }} in
the git credential rewrite instead of a TRAMITON_FETCH_TOKEN PAT — no secret to
manage. If cargo's git fetch 403s (feature scoped to uses:-actions only), fall
back to a PAT.
Refs #118.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replace the `tramiton detect --json` CLI shell-out with a direct dependency on
tramiton-core (same-company IP), so firmware bare-metal/RTOS classification runs
in-process and the whole tramiton suite is available to onboarding.
- compliance-agent depends on tramiton-core (git, tag v0.4.0).
- classify/firmware.rs: TramitonNative runs tramiton_core::provider::analyze on a
blocking thread and maps its BuildPlan → a minimal FirmwareDetection. Drops the
mirrored JSON structs and the CLI wrapper. FirmwareDetector port + a
deterministic MockFirmwareDetector are kept so unit tests need neither the
tramiton sources nor a firmware tree.
- CI: enable CARGO_NET_GIT_FETCH_WITH_CLI and add a git-auth step so the runner
can fetch the private tramiton repo. Requires a repo secret TRAMITON_FETCH_TOKEN
(Gitea PAT with read access to sharang/tramiton).
Refs #118, #121, #135.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Steps 3-4 of the onboarding plan, plus the sibling-product reconciliation seams.
Ingest (compliance-agent/src/ingest, #120):
- ingest_all / ingest_artifact normalize each artifact to a working path +
metadata. Every blob is SHA-256 hashed (content-addressed store, dedup) —
that digest is also the tramiton reconciliation key.
- git via GitOps reuse; zip archives + mobile packages extracted; firmware
stored as blob; live URL / plaintext / container = metadata only.
- IngestContext decoupled from the full AgentConfig (testable in isolation).
Classify (compliance-agent/src/classify, #121):
- FirmwareDetector port + TramitonCli (shell out `tramiton detect --json`,
parse a mirrored BuildPlan subset — no dependency on the proprietary crate)
+ a deterministic MockFirmwareDetector so CI never needs the binary.
- HeuristicClassifier: artifact-kind priors + source-marker fingerprinting
(web/backend/mobile/desktop/PLC).
- classify_target merges + ranks verdicts into a Classification.
Suite-integration seams (compliance-core, #135/#136/#137):
- Model: ExternalRef/ExternalSystem (reconcile with tramiton/werkpilot/breakpilot),
ComplianceProfile/ComplianceFramework + default_compliance_profile per type.
- Ports: EvidenceProvider (fetch external SBOM/VEX/lock/attestation) and
ControlsProvider (built-in OSCAL vs breakpilot RAG).
- TargetType now derives Hash; AgentConfig gains artifact_store_base_path.
44 unit tests (23 core + 8 ingest + 13 classify). Passes fmt + clippy -D warnings
across agent, dashboard (server + web), and mcp. Additive; legacy paths untouched.
Refs #118, #120, #121, #135, #136, #137.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>