49
.env.example
Normal file
@ -0,0 +1,49 @@
|
||||
# Bandit Runner Environment Variables
|
||||
# Copy this to .env.local and fill in your values
|
||||
|
||||
# =============================================================================
|
||||
# Required for Development
|
||||
# =============================================================================
|
||||
|
||||
# OpenAI API Key (or compatible endpoint)
|
||||
# Get from: https://platform.openai.com/api-keys
|
||||
OPENAI_API_KEY=sk-...
|
||||
|
||||
# =============================================================================
|
||||
# Cloudflare (Required for Production)
|
||||
# =============================================================================
|
||||
|
||||
# Cloudflare Account ID
|
||||
# Find at: https://dash.cloudflare.com/ → Workers & Pages → Overview
|
||||
CLOUDFLARE_ACCOUNT_ID=
|
||||
|
||||
# Cloudflare API Token
|
||||
# Create at: https://dash.cloudflare.com/profile/api-tokens
|
||||
# Permissions needed: Workers Scripts:Edit, D1:Edit, R2:Edit
|
||||
CLOUDFLARE_API_TOKEN=
|
||||
|
||||
# =============================================================================
|
||||
# Optional Configuration
|
||||
# =============================================================================
|
||||
|
||||
# Alternative LLM Endpoint (e.g., OpenRouter, local inference)
|
||||
# LLM_BASE_URL=https://openrouter.ai/api/v1
|
||||
# LLM_API_KEY=
|
||||
|
||||
# Bandit SSH Configuration (defaults shown)
|
||||
# BANDIT_HOST=bandit.labs.overthewire.org
|
||||
# BANDIT_PORT=2220
|
||||
|
||||
# Run Coordinator Settings
|
||||
# MAX_STEPS_PER_RUN=100
|
||||
# TIMEOUT_SECONDS=300
|
||||
|
||||
# =============================================================================
|
||||
# Development Only
|
||||
# =============================================================================
|
||||
|
||||
# Next.js
|
||||
# NEXT_PUBLIC_API_URL=http://localhost:3000
|
||||
|
||||
# Wrangler Local Dev
|
||||
# PORT=8787
|
||||
26
.gitea/issue_templates/bug_report.md
Normal file
@ -0,0 +1,26 @@
|
||||
---
|
||||
name: "🐞 Bug report"
|
||||
about: Report a reproducible problem
|
||||
labels: ["type:fix"]
|
||||
---
|
||||
|
||||
### What happened?
|
||||
<!-- clear, minimal description -->
|
||||
|
||||
### Expected behavior
|
||||
|
||||
### Repro steps
|
||||
1.
|
||||
2.
|
||||
3.
|
||||
|
||||
### Logs / screenshots
|
||||
<!-- attach JSONL snippet or console output -->
|
||||
|
||||
### Environment
|
||||
- Browser:
|
||||
- Node: `node -v`
|
||||
- pnpm: `pnpm -v`
|
||||
- App commit SHA:
|
||||
|
||||
### Extra context
|
||||
15
.gitea/issue_templates/enhancement.md
Normal file
@ -0,0 +1,15 @@
|
||||
---
|
||||
name: "✨ Enhancement"
|
||||
about: Improve an existing capability
|
||||
labels: ["type:docs","type:chore"]
|
||||
---
|
||||
|
||||
### Current behavior
|
||||
|
||||
### Desired behavior
|
||||
|
||||
### Acceptance criteria
|
||||
- [ ] AC1
|
||||
- [ ] AC2
|
||||
|
||||
### Notes / risks
|
||||
23
.gitea/issue_templates/feature_request.md
Normal file
@ -0,0 +1,23 @@
|
||||
---
|
||||
name: "🚀 Feature request"
|
||||
about: Propose a net-new capability
|
||||
labels: ["type:feat"]
|
||||
---
|
||||
|
||||
### Problem this solves
|
||||
|
||||
### Proposed solution (what & why)
|
||||
|
||||
### Non-goals / constraints
|
||||
|
||||
### Acceptance criteria
|
||||
- [ ] AC1
|
||||
- [ ] AC2
|
||||
|
||||
### Alternatives considered
|
||||
|
||||
### Impacted areas
|
||||
- [ ] UI
|
||||
- [ ] RunCoordinator DO
|
||||
- [ ] Scoring/validators
|
||||
- [ ] Storage (D1/R2)
|
||||
29
.gitea/pull_request_template.md
Normal file
@ -0,0 +1,29 @@
|
||||
## Summary
|
||||
<!-- What this PR changes and why -->
|
||||
|
||||
## Type
|
||||
- [ ] feat
|
||||
- [ ] fix
|
||||
- [ ] docs
|
||||
- [ ] chore
|
||||
- [ ] refactor
|
||||
- [ ] test
|
||||
|
||||
## Screenshots / logs
|
||||
<!-- If UI or logs changed, include before/after or snippets -->
|
||||
|
||||
## How to test
|
||||
1.
|
||||
2.
|
||||
3.
|
||||
|
||||
## Checklist
|
||||
- [ ] Tests added/updated (unit or integration)
|
||||
- [ ] Typecheck & lint pass (`pnpm check`)
|
||||
- [ ] Builds locally (`pnpm build`)
|
||||
- [ ] Docs/README/ADR updated if needed
|
||||
- [ ] No secrets committed
|
||||
|
||||
## Linked issues
|
||||
Fixes #
|
||||
Refs #
|
||||
42
.gitea/workflows/ci.yml
Normal file
@ -0,0 +1,42 @@
|
||||
name: CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: ["main"]
|
||||
pull_request:
|
||||
branches: ["main"]
|
||||
|
||||
jobs:
|
||||
build-test:
|
||||
runs-on: ubuntu-latest
|
||||
defaults:
|
||||
run:
|
||||
working-directory: ./bandit-runner-app
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup pnpm
|
||||
uses: pnpm/action-setup@v4
|
||||
with:
|
||||
version: 9
|
||||
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: "20"
|
||||
cache: "pnpm"
|
||||
cache-dependency-path: bandit-runner-app/pnpm-lock.yaml
|
||||
|
||||
- name: Install deps
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
- name: Lint
|
||||
run: pnpm lint
|
||||
|
||||
- name: Typecheck
|
||||
run: npx tsc --noEmit
|
||||
|
||||
- name: Build (OpenNext)
|
||||
run: pnpm build
|
||||
17
.gitea/workflows/pr-lint.yml
Normal file
@ -0,0 +1,17 @@
|
||||
name: PR Title Lint
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, edited, synchronize]
|
||||
|
||||
jobs:
|
||||
pr-title:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check PR title
|
||||
run: |
|
||||
title="$(jq -r '.pull_request.title' < "$GITHUB_EVENT_PATH")"
|
||||
if ! grep -Eq '^(feat|fix|docs|chore|refactor|test)(\(.+\))?: .+' <<<"$title"; then
|
||||
echo "PR title must follow Conventional Commits. Got: $title"
|
||||
exit 1
|
||||
fi
|
||||
54
.gitignore
vendored
@ -130,3 +130,57 @@ dist
|
||||
.yarn/install-state.gz
|
||||
.pnp.*
|
||||
|
||||
# --- Cloudflare / Wrangler
|
||||
.wrangler/
|
||||
.dev.vars
|
||||
.wrangler/state/
|
||||
.wrangler/state/**
|
||||
|
||||
# D1 local databases (Wrangler stores sqlite under .wrangler/state)
|
||||
*.sqlite
|
||||
*.sqlite-journal
|
||||
|
||||
# OpenNext build artifacts
|
||||
.open-next/
|
||||
.open-next/**
|
||||
|
||||
# Vercel local metadata (Next tooling sometimes creates this)
|
||||
.vercel/
|
||||
|
||||
# pnpm store (optional; usually outside project, but ignore if present locally)
|
||||
.pnpm-store/
|
||||
|
||||
# Lockfile hygiene (commit pnpm-lock.yaml; ignore the others)
|
||||
package-lock.json
|
||||
yarn.lock
|
||||
bun.lockb
|
||||
|
||||
# OS/editor junk
|
||||
.DS_Store
|
||||
Thumbs.db
|
||||
*.swp
|
||||
*.swo
|
||||
.idea/
|
||||
.vscode/*
|
||||
!.vscode/extensions.json
|
||||
!.vscode/settings.json
|
||||
!.vscode/tasks.json
|
||||
!.vscode/launch.json
|
||||
|
||||
# Turborepo cache (if you introduce turbo later)
|
||||
.turbo/
|
||||
|
||||
# Playwright / Cypress / Vitest / Jest artifacts
|
||||
playwright-report/
|
||||
test-results/
|
||||
coverage-final.json
|
||||
jest-test-results.json
|
||||
cypress/videos/
|
||||
cypress/screenshots/
|
||||
cypress/downloads/
|
||||
|
||||
# Misc caches
|
||||
.npm/_logs
|
||||
.*.cache
|
||||
.cache-loader/
|
||||
|
||||
|
||||
57
CONTRIBUTING.md
Normal file
@ -0,0 +1,57 @@
|
||||
## Branch Strategy
|
||||
|
||||
We use short-lived topic branches, Conventional Commits, and PRs into `main`.
|
||||
|
||||
### Branch prefixes
|
||||
Create branches using one of:
|
||||
- `feat/<scope>-<short-desc>` – new features (e.g., `feat/runner-do-timeouts`)
|
||||
- `fix/<scope>-<short-desc>` – bug fixes
|
||||
- `docs/<scope>-<short-desc>` – docs only
|
||||
- `chore/<scope>-<short-desc>` – tooling, config, non-product changes
|
||||
- `refactor/<scope>-<short-desc>` – no behavior change
|
||||
- `test/<scope>-<short-desc>` – test-only changes
|
||||
|
||||
### Examples
|
||||
```bash
|
||||
git checkout -b feat/ssh-timeout-handler
|
||||
git checkout -b fix/scoring-edge-case
|
||||
git checkout -b docs/adr-durable-objects
|
||||
git checkout -b chore/update-deps
|
||||
```
|
||||
|
||||
### Commit messages
|
||||
Follow [Conventional Commits](https://www.conventionalcommits.org/):
|
||||
```
|
||||
<type>(<scope>): <subject>
|
||||
|
||||
<body>
|
||||
|
||||
<footer>
|
||||
```
|
||||
|
||||
**Required:**
|
||||
- `<type>`: feat, fix, docs, chore, refactor, test
|
||||
- `<subject>`: imperative mood, lowercase, no period
|
||||
|
||||
**Optional:**
|
||||
- `<scope>`: module or area affected (e.g., runner, scoring, ui)
|
||||
- `<body>`: detailed explanation
|
||||
- `<footer>`: references (e.g., `Fixes #123`, `BREAKING CHANGE: ...`)
|
||||
|
||||
### Pull Request flow
|
||||
1. Create feature branch from `main`
|
||||
2. Make changes with conventional commits
|
||||
3. Push to origin
|
||||
4. Open PR with filled template
|
||||
5. Address review feedback
|
||||
6. Squash-merge to `main` (title must follow convention)
|
||||
|
||||
### Code Quality
|
||||
Before opening a PR:
|
||||
```bash
|
||||
cd bandit-runner-app
|
||||
pnpm install
|
||||
pnpm lint # ESLint
|
||||
npx tsc --noEmit # TypeScript check
|
||||
pnpm build # Verify builds
|
||||
```
|
||||
674
COPYING.txt
Normal file
@ -0,0 +1,674 @@
|
||||
GNU GENERAL PUBLIC LICENSE
|
||||
Version 3, 29 June 2007
|
||||
|
||||
Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
|
||||
Everyone is permitted to copy and distribute verbatim copies
|
||||
of this license document, but changing it is not allowed.
|
||||
|
||||
Preamble
|
||||
|
||||
The GNU General Public License is a free, copyleft license for
|
||||
software and other kinds of works.
|
||||
|
||||
The licenses for most software and other practical works are designed
|
||||
to take away your freedom to share and change the works. By contrast,
|
||||
the GNU General Public License is intended to guarantee your freedom to
|
||||
share and change all versions of a program--to make sure it remains free
|
||||
software for all its users. We, the Free Software Foundation, use the
|
||||
GNU General Public License for most of our software; it applies also to
|
||||
any other work released this way by its authors. You can apply it to
|
||||
your programs, too.
|
||||
|
||||
When we speak of free software, we are referring to freedom, not
|
||||
price. Our General Public Licenses are designed to make sure that you
|
||||
have the freedom to distribute copies of free software (and charge for
|
||||
them if you wish), that you receive source code or can get it if you
|
||||
want it, that you can change the software or use pieces of it in new
|
||||
free programs, and that you know you can do these things.
|
||||
|
||||
To protect your rights, we need to prevent others from denying you
|
||||
these rights or asking you to surrender the rights. Therefore, you have
|
||||
certain responsibilities if you distribute copies of the software, or if
|
||||
you modify it: responsibilities to respect the freedom of others.
|
||||
|
||||
For example, if you distribute copies of such a program, whether
|
||||
gratis or for a fee, you must pass on to the recipients the same
|
||||
freedoms that you received. You must make sure that they, too, receive
|
||||
or can get the source code. And you must show them these terms so they
|
||||
know their rights.
|
||||
|
||||
Developers that use the GNU GPL protect your rights with two steps:
|
||||
(1) assert copyright on the software, and (2) offer you this License
|
||||
giving you legal permission to copy, distribute and/or modify it.
|
||||
|
||||
For the developers' and authors' protection, the GPL clearly explains
|
||||
that there is no warranty for this free software. For both users' and
|
||||
authors' sake, the GPL requires that modified versions be marked as
|
||||
changed, so that their problems will not be attributed erroneously to
|
||||
authors of previous versions.
|
||||
|
||||
Some devices are designed to deny users access to install or run
|
||||
modified versions of the software inside them, although the manufacturer
|
||||
can do so. This is fundamentally incompatible with the aim of
|
||||
protecting users' freedom to change the software. The systematic
|
||||
pattern of such abuse occurs in the area of products for individuals to
|
||||
use, which is precisely where it is most unacceptable. Therefore, we
|
||||
have designed this version of the GPL to prohibit the practice for those
|
||||
products. If such problems arise substantially in other domains, we
|
||||
stand ready to extend this provision to those domains in future versions
|
||||
of the GPL, as needed to protect the freedom of users.
|
||||
|
||||
Finally, every program is threatened constantly by software patents.
|
||||
States should not allow patents to restrict development and use of
|
||||
software on general-purpose computers, but in those that do, we wish to
|
||||
avoid the special danger that patents applied to a free program could
|
||||
make it effectively proprietary. To prevent this, the GPL assures that
|
||||
patents cannot be used to render the program non-free.
|
||||
|
||||
The precise terms and conditions for copying, distribution and
|
||||
modification follow.
|
||||
|
||||
TERMS AND CONDITIONS
|
||||
|
||||
0. Definitions.
|
||||
|
||||
"This License" refers to version 3 of the GNU General Public License.
|
||||
|
||||
"Copyright" also means copyright-like laws that apply to other kinds of
|
||||
works, such as semiconductor masks.
|
||||
|
||||
"The Program" refers to any copyrightable work licensed under this
|
||||
License. Each licensee is addressed as "you". "Licensees" and
|
||||
"recipients" may be individuals or organizations.
|
||||
|
||||
To "modify" a work means to copy from or adapt all or part of the work
|
||||
in a fashion requiring copyright permission, other than the making of an
|
||||
exact copy. The resulting work is called a "modified version" of the
|
||||
earlier work or a work "based on" the earlier work.
|
||||
|
||||
A "covered work" means either the unmodified Program or a work based
|
||||
on the Program.
|
||||
|
||||
To "propagate" a work means to do anything with it that, without
|
||||
permission, would make you directly or secondarily liable for
|
||||
infringement under applicable copyright law, except executing it on a
|
||||
computer or modifying a private copy. Propagation includes copying,
|
||||
distribution (with or without modification), making available to the
|
||||
public, and in some countries other activities as well.
|
||||
|
||||
To "convey" a work means any kind of propagation that enables other
|
||||
parties to make or receive copies. Mere interaction with a user through
|
||||
a computer network, with no transfer of a copy, is not conveying.
|
||||
|
||||
An interactive user interface displays "Appropriate Legal Notices"
|
||||
to the extent that it includes a convenient and prominently visible
|
||||
feature that (1) displays an appropriate copyright notice, and (2)
|
||||
tells the user that there is no warranty for the work (except to the
|
||||
extent that warranties are provided), that licensees may convey the
|
||||
work under this License, and how to view a copy of this License. If
|
||||
the interface presents a list of user commands or options, such as a
|
||||
menu, a prominent item in the list meets this criterion.
|
||||
|
||||
1. Source Code.
|
||||
|
||||
The "source code" for a work means the preferred form of the work
|
||||
for making modifications to it. "Object code" means any non-source
|
||||
form of a work.
|
||||
|
||||
A "Standard Interface" means an interface that either is an official
|
||||
standard defined by a recognized standards body, or, in the case of
|
||||
interfaces specified for a particular programming language, one that
|
||||
is widely used among developers working in that language.
|
||||
|
||||
The "System Libraries" of an executable work include anything, other
|
||||
than the work as a whole, that (a) is included in the normal form of
|
||||
packaging a Major Component, but which is not part of that Major
|
||||
Component, and (b) serves only to enable use of the work with that
|
||||
Major Component, or to implement a Standard Interface for which an
|
||||
implementation is available to the public in source code form. A
|
||||
"Major Component", in this context, means a major essential component
|
||||
(kernel, window system, and so on) of the specific operating system
|
||||
(if any) on which the executable work runs, or a compiler used to
|
||||
produce the work, or an object code interpreter used to run it.
|
||||
|
||||
The "Corresponding Source" for a work in object code form means all
|
||||
the source code needed to generate, install, and (for an executable
|
||||
work) run the object code and to modify the work, including scripts to
|
||||
control those activities. However, it does not include the work's
|
||||
System Libraries, or general-purpose tools or generally available free
|
||||
programs which are used unmodified in performing those activities but
|
||||
which are not part of the work. For example, Corresponding Source
|
||||
includes interface definition files associated with source files for
|
||||
the work, and the source code for shared libraries and dynamically
|
||||
linked subprograms that the work is specifically designed to require,
|
||||
such as by intimate data communication or control flow between those
|
||||
subprograms and other parts of the work.
|
||||
|
||||
The Corresponding Source need not include anything that users
|
||||
can regenerate automatically from other parts of the Corresponding
|
||||
Source.
|
||||
|
||||
The Corresponding Source for a work in source code form is that
|
||||
same work.
|
||||
|
||||
2. Basic Permissions.
|
||||
|
||||
All rights granted under this License are granted for the term of
|
||||
copyright on the Program, and are irrevocable provided the stated
|
||||
conditions are met. This License explicitly affirms your unlimited
|
||||
permission to run the unmodified Program. The output from running a
|
||||
covered work is covered by this License only if the output, given its
|
||||
content, constitutes a covered work. This License acknowledges your
|
||||
rights of fair use or other equivalent, as provided by copyright law.
|
||||
|
||||
You may make, run and propagate covered works that you do not
|
||||
convey, without conditions so long as your license otherwise remains
|
||||
in force. You may convey covered works to others for the sole purpose
|
||||
of having them make modifications exclusively for you, or provide you
|
||||
with facilities for running those works, provided that you comply with
|
||||
the terms of this License in conveying all material for which you do
|
||||
not control copyright. Those thus making or running the covered works
|
||||
for you must do so exclusively on your behalf, under your direction
|
||||
and control, on terms that prohibit them from making any copies of
|
||||
your copyrighted material outside their relationship with you.
|
||||
|
||||
Conveying under any other circumstances is permitted solely under
|
||||
the conditions stated below. Sublicensing is not allowed; section 10
|
||||
makes it unnecessary.
|
||||
|
||||
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
|
||||
|
||||
No covered work shall be deemed part of an effective technological
|
||||
measure under any applicable law fulfilling obligations under article
|
||||
11 of the WIPO copyright treaty adopted on 20 December 1996, or
|
||||
similar laws prohibiting or restricting circumvention of such
|
||||
measures.
|
||||
|
||||
When you convey a covered work, you waive any legal power to forbid
|
||||
circumvention of technological measures to the extent such circumvention
|
||||
is effected by exercising rights under this License with respect to
|
||||
the covered work, and you disclaim any intention to limit operation or
|
||||
modification of the work as a means of enforcing, against the work's
|
||||
users, your or third parties' legal rights to forbid circumvention of
|
||||
technological measures.
|
||||
|
||||
4. Conveying Verbatim Copies.
|
||||
|
||||
You may convey verbatim copies of the Program's source code as you
|
||||
receive it, in any medium, provided that you conspicuously and
|
||||
appropriately publish on each copy an appropriate copyright notice;
|
||||
keep intact all notices stating that this License and any
|
||||
non-permissive terms added in accord with section 7 apply to the code;
|
||||
keep intact all notices of the absence of any warranty; and give all
|
||||
recipients a copy of this License along with the Program.
|
||||
|
||||
You may charge any price or no price for each copy that you convey,
|
||||
and you may offer support or warranty protection for a fee.
|
||||
|
||||
5. Conveying Modified Source Versions.
|
||||
|
||||
You may convey a work based on the Program, or the modifications to
|
||||
produce it from the Program, in the form of source code under the
|
||||
terms of section 4, provided that you also meet all of these conditions:
|
||||
|
||||
a) The work must carry prominent notices stating that you modified
|
||||
it, and giving a relevant date.
|
||||
|
||||
b) The work must carry prominent notices stating that it is
|
||||
released under this License and any conditions added under section
|
||||
7. This requirement modifies the requirement in section 4 to
|
||||
"keep intact all notices".
|
||||
|
||||
c) You must license the entire work, as a whole, under this
|
||||
License to anyone who comes into possession of a copy. This
|
||||
License will therefore apply, along with any applicable section 7
|
||||
additional terms, to the whole of the work, and all its parts,
|
||||
regardless of how they are packaged. This License gives no
|
||||
permission to license the work in any other way, but it does not
|
||||
invalidate such permission if you have separately received it.
|
||||
|
||||
d) If the work has interactive user interfaces, each must display
|
||||
Appropriate Legal Notices; however, if the Program has interactive
|
||||
interfaces that do not display Appropriate Legal Notices, your
|
||||
work need not make them do so.
|
||||
|
||||
A compilation of a covered work with other separate and independent
|
||||
works, which are not by their nature extensions of the covered work,
|
||||
and which are not combined with it such as to form a larger program,
|
||||
in or on a volume of a storage or distribution medium, is called an
|
||||
"aggregate" if the compilation and its resulting copyright are not
|
||||
used to limit the access or legal rights of the compilation's users
|
||||
beyond what the individual works permit. Inclusion of a covered work
|
||||
in an aggregate does not cause this License to apply to the other
|
||||
parts of the aggregate.
|
||||
|
||||
6. Conveying Non-Source Forms.
|
||||
|
||||
You may convey a covered work in object code form under the terms
|
||||
of sections 4 and 5, provided that you also convey the
|
||||
machine-readable Corresponding Source under the terms of this License,
|
||||
in one of these ways:
|
||||
|
||||
a) Convey the object code in, or embodied in, a physical product
|
||||
(including a physical distribution medium), accompanied by the
|
||||
Corresponding Source fixed on a durable physical medium
|
||||
customarily used for software interchange.
|
||||
|
||||
b) Convey the object code in, or embodied in, a physical product
|
||||
(including a physical distribution medium), accompanied by a
|
||||
written offer, valid for at least three years and valid for as
|
||||
long as you offer spare parts or customer support for that product
|
||||
model, to give anyone who possesses the object code either (1) a
|
||||
copy of the Corresponding Source for all the software in the
|
||||
product that is covered by this License, on a durable physical
|
||||
medium customarily used for software interchange, for a price no
|
||||
more than your reasonable cost of physically performing this
|
||||
conveying of source, or (2) access to copy the
|
||||
Corresponding Source from a network server at no charge.
|
||||
|
||||
c) Convey individual copies of the object code with a copy of the
|
||||
written offer to provide the Corresponding Source. This
|
||||
alternative is allowed only occasionally and noncommercially, and
|
||||
only if you received the object code with such an offer, in accord
|
||||
with subsection 6b.
|
||||
|
||||
d) Convey the object code by offering access from a designated
|
||||
place (gratis or for a charge), and offer equivalent access to the
|
||||
Corresponding Source in the same way through the same place at no
|
||||
further charge. You need not require recipients to copy the
|
||||
Corresponding Source along with the object code. If the place to
|
||||
copy the object code is a network server, the Corresponding Source
|
||||
may be on a different server (operated by you or a third party)
|
||||
that supports equivalent copying facilities, provided you maintain
|
||||
clear directions next to the object code saying where to find the
|
||||
Corresponding Source. Regardless of what server hosts the
|
||||
Corresponding Source, you remain obligated to ensure that it is
|
||||
available for as long as needed to satisfy these requirements.
|
||||
|
||||
e) Convey the object code using peer-to-peer transmission, provided
|
||||
you inform other peers where the object code and Corresponding
|
||||
Source of the work are being offered to the general public at no
|
||||
charge under subsection 6d.
|
||||
|
||||
A separable portion of the object code, whose source code is excluded
|
||||
from the Corresponding Source as a System Library, need not be
|
||||
included in conveying the object code work.
|
||||
|
||||
A "User Product" is either (1) a "consumer product", which means any
|
||||
tangible personal property which is normally used for personal, family,
|
||||
or household purposes, or (2) anything designed or sold for incorporation
|
||||
into a dwelling. In determining whether a product is a consumer product,
|
||||
doubtful cases shall be resolved in favor of coverage. For a particular
|
||||
product received by a particular user, "normally used" refers to a
|
||||
typical or common use of that class of product, regardless of the status
|
||||
of the particular user or of the way in which the particular user
|
||||
actually uses, or expects or is expected to use, the product. A product
|
||||
is a consumer product regardless of whether the product has substantial
|
||||
commercial, industrial or non-consumer uses, unless such uses represent
|
||||
the only significant mode of use of the product.
|
||||
|
||||
"Installation Information" for a User Product means any methods,
|
||||
procedures, authorization keys, or other information required to install
|
||||
and execute modified versions of a covered work in that User Product from
|
||||
a modified version of its Corresponding Source. The information must
|
||||
suffice to ensure that the continued functioning of the modified object
|
||||
code is in no case prevented or interfered with solely because
|
||||
modification has been made.
|
||||
|
||||
If you convey an object code work under this section in, or with, or
|
||||
specifically for use in, a User Product, and the conveying occurs as
|
||||
part of a transaction in which the right of possession and use of the
|
||||
User Product is transferred to the recipient in perpetuity or for a
|
||||
fixed term (regardless of how the transaction is characterized), the
|
||||
Corresponding Source conveyed under this section must be accompanied
|
||||
by the Installation Information. But this requirement does not apply
|
||||
if neither you nor any third party retains the ability to install
|
||||
modified object code on the User Product (for example, the work has
|
||||
been installed in ROM).
|
||||
|
||||
The requirement to provide Installation Information does not include a
|
||||
requirement to continue to provide support service, warranty, or updates
|
||||
for a work that has been modified or installed by the recipient, or for
|
||||
the User Product in which it has been modified or installed. Access to a
|
||||
network may be denied when the modification itself materially and
|
||||
adversely affects the operation of the network or violates the rules and
|
||||
protocols for communication across the network.
|
||||
|
||||
Corresponding Source conveyed, and Installation Information provided,
|
||||
in accord with this section must be in a format that is publicly
|
||||
documented (and with an implementation available to the public in
|
||||
source code form), and must require no special password or key for
|
||||
unpacking, reading or copying.
|
||||
|
||||
7. Additional Terms.
|
||||
|
||||
"Additional permissions" are terms that supplement the terms of this
|
||||
License by making exceptions from one or more of its conditions.
|
||||
Additional permissions that are applicable to the entire Program shall
|
||||
be treated as though they were included in this License, to the extent
|
||||
that they are valid under applicable law. If additional permissions
|
||||
apply only to part of the Program, that part may be used separately
|
||||
under those permissions, but the entire Program remains governed by
|
||||
this License without regard to the additional permissions.
|
||||
|
||||
When you convey a copy of a covered work, you may at your option
|
||||
remove any additional permissions from that copy, or from any part of
|
||||
it. (Additional permissions may be written to require their own
|
||||
removal in certain cases when you modify the work.) You may place
|
||||
additional permissions on material, added by you to a covered work,
|
||||
for which you have or can give appropriate copyright permission.
|
||||
|
||||
Notwithstanding any other provision of this License, for material you
|
||||
add to a covered work, you may (if authorized by the copyright holders of
|
||||
that material) supplement the terms of this License with terms:
|
||||
|
||||
a) Disclaiming warranty or limiting liability differently from the
|
||||
terms of sections 15 and 16 of this License; or
|
||||
|
||||
b) Requiring preservation of specified reasonable legal notices or
|
||||
author attributions in that material or in the Appropriate Legal
|
||||
Notices displayed by works containing it; or
|
||||
|
||||
c) Prohibiting misrepresentation of the origin of that material, or
|
||||
requiring that modified versions of such material be marked in
|
||||
reasonable ways as different from the original version; or
|
||||
|
||||
d) Limiting the use for publicity purposes of names of licensors or
|
||||
authors of the material; or
|
||||
|
||||
e) Declining to grant rights under trademark law for use of some
|
||||
trade names, trademarks, or service marks; or
|
||||
|
||||
f) Requiring indemnification of licensors and authors of that
|
||||
material by anyone who conveys the material (or modified versions of
|
||||
it) with contractual assumptions of liability to the recipient, for
|
||||
any liability that these contractual assumptions directly impose on
|
||||
those licensors and authors.
|
||||
|
||||
All other non-permissive additional terms are considered "further
|
||||
restrictions" within the meaning of section 10. If the Program as you
|
||||
received it, or any part of it, contains a notice stating that it is
|
||||
governed by this License along with a term that is a further
|
||||
restriction, you may remove that term. If a license document contains
|
||||
a further restriction but permits relicensing or conveying under this
|
||||
License, you may add to a covered work material governed by the terms
|
||||
of that license document, provided that the further restriction does
|
||||
not survive such relicensing or conveying.
|
||||
|
||||
If you add terms to a covered work in accord with this section, you
|
||||
must place, in the relevant source files, a statement of the
|
||||
additional terms that apply to those files, or a notice indicating
|
||||
where to find the applicable terms.
|
||||
|
||||
Additional terms, permissive or non-permissive, may be stated in the
|
||||
form of a separately written license, or stated as exceptions;
|
||||
the above requirements apply either way.
|
||||
|
||||
8. Termination.
|
||||
|
||||
You may not propagate or modify a covered work except as expressly
|
||||
provided under this License. Any attempt otherwise to propagate or
|
||||
modify it is void, and will automatically terminate your rights under
|
||||
this License (including any patent licenses granted under the third
|
||||
paragraph of section 11).
|
||||
|
||||
However, if you cease all violation of this License, then your
|
||||
license from a particular copyright holder is reinstated (a)
|
||||
provisionally, unless and until the copyright holder explicitly and
|
||||
finally terminates your license, and (b) permanently, if the copyright
|
||||
holder fails to notify you of the violation by some reasonable means
|
||||
prior to 60 days after the cessation.
|
||||
|
||||
Moreover, your license from a particular copyright holder is
|
||||
reinstated permanently if the copyright holder notifies you of the
|
||||
violation by some reasonable means, this is the first time you have
|
||||
received notice of violation of this License (for any work) from that
|
||||
copyright holder, and you cure the violation prior to 30 days after
|
||||
your receipt of the notice.
|
||||
|
||||
Termination of your rights under this section does not terminate the
|
||||
licenses of parties who have received copies or rights from you under
|
||||
this License. If your rights have been terminated and not permanently
|
||||
reinstated, you do not qualify to receive new licenses for the same
|
||||
material under section 10.
|
||||
|
||||
9. Acceptance Not Required for Having Copies.
|
||||
|
||||
You are not required to accept this License in order to receive or
|
||||
run a copy of the Program. Ancillary propagation of a covered work
|
||||
occurring solely as a consequence of using peer-to-peer transmission
|
||||
to receive a copy likewise does not require acceptance. However,
|
||||
nothing other than this License grants you permission to propagate or
|
||||
modify any covered work. These actions infringe copyright if you do
|
||||
not accept this License. Therefore, by modifying or propagating a
|
||||
covered work, you indicate your acceptance of this License to do so.
|
||||
|
||||
10. Automatic Licensing of Downstream Recipients.
|
||||
|
||||
Each time you convey a covered work, the recipient automatically
|
||||
receives a license from the original licensors, to run, modify and
|
||||
propagate that work, subject to this License. You are not responsible
|
||||
for enforcing compliance by third parties with this License.
|
||||
|
||||
An "entity transaction" is a transaction transferring control of an
|
||||
organization, or substantially all assets of one, or subdividing an
|
||||
organization, or merging organizations. If propagation of a covered
|
||||
work results from an entity transaction, each party to that
|
||||
transaction who receives a copy of the work also receives whatever
|
||||
licenses to the work the party's predecessor in interest had or could
|
||||
give under the previous paragraph, plus a right to possession of the
|
||||
Corresponding Source of the work from the predecessor in interest, if
|
||||
the predecessor has it or can get it with reasonable efforts.
|
||||
|
||||
You may not impose any further restrictions on the exercise of the
|
||||
rights granted or affirmed under this License. For example, you may
|
||||
not impose a license fee, royalty, or other charge for exercise of
|
||||
rights granted under this License, and you may not initiate litigation
|
||||
(including a cross-claim or counterclaim in a lawsuit) alleging that
|
||||
any patent claim is infringed by making, using, selling, offering for
|
||||
sale, or importing the Program or any portion of it.
|
||||
|
||||
11. Patents.
|
||||
|
||||
A "contributor" is a copyright holder who authorizes use under this
|
||||
License of the Program or a work on which the Program is based. The
|
||||
work thus licensed is called the contributor's "contributor version".
|
||||
|
||||
A contributor's "essential patent claims" are all patent claims
|
||||
owned or controlled by the contributor, whether already acquired or
|
||||
hereafter acquired, that would be infringed by some manner, permitted
|
||||
by this License, of making, using, or selling its contributor version,
|
||||
but do not include claims that would be infringed only as a
|
||||
consequence of further modification of the contributor version. For
|
||||
purposes of this definition, "control" includes the right to grant
|
||||
patent sublicenses in a manner consistent with the requirements of
|
||||
this License.
|
||||
|
||||
Each contributor grants you a non-exclusive, worldwide, royalty-free
|
||||
patent license under the contributor's essential patent claims, to
|
||||
make, use, sell, offer for sale, import and otherwise run, modify and
|
||||
propagate the contents of its contributor version.
|
||||
|
||||
In the following three paragraphs, a "patent license" is any express
|
||||
agreement or commitment, however denominated, not to enforce a patent
|
||||
(such as an express permission to practice a patent or covenant not to
|
||||
sue for patent infringement). To "grant" such a patent license to a
|
||||
party means to make such an agreement or commitment not to enforce a
|
||||
patent against the party.
|
||||
|
||||
If you convey a covered work, knowingly relying on a patent license,
|
||||
and the Corresponding Source of the work is not available for anyone
|
||||
to copy, free of charge and under the terms of this License, through a
|
||||
publicly available network server or other readily accessible means,
|
||||
then you must either (1) cause the Corresponding Source to be so
|
||||
available, or (2) arrange to deprive yourself of the benefit of the
|
||||
patent license for this particular work, or (3) arrange, in a manner
|
||||
consistent with the requirements of this License, to extend the patent
|
||||
license to downstream recipients. "Knowingly relying" means you have
|
||||
actual knowledge that, but for the patent license, your conveying the
|
||||
covered work in a country, or your recipient's use of the covered work
|
||||
in a country, would infringe one or more identifiable patents in that
|
||||
country that you have reason to believe are valid.
|
||||
|
||||
If, pursuant to or in connection with a single transaction or
|
||||
arrangement, you convey, or propagate by procuring conveyance of, a
|
||||
covered work, and grant a patent license to some of the parties
|
||||
receiving the covered work authorizing them to use, propagate, modify
|
||||
or convey a specific copy of the covered work, then the patent license
|
||||
you grant is automatically extended to all recipients of the covered
|
||||
work and works based on it.
|
||||
|
||||
A patent license is "discriminatory" if it does not include within
|
||||
the scope of its coverage, prohibits the exercise of, or is
|
||||
conditioned on the non-exercise of one or more of the rights that are
|
||||
specifically granted under this License. You may not convey a covered
|
||||
work if you are a party to an arrangement with a third party that is
|
||||
in the business of distributing software, under which you make payment
|
||||
to the third party based on the extent of your activity of conveying
|
||||
the work, and under which the third party grants, to any of the
|
||||
parties who would receive the covered work from you, a discriminatory
|
||||
patent license (a) in connection with copies of the covered work
|
||||
conveyed by you (or copies made from those copies), or (b) primarily
|
||||
for and in connection with specific products or compilations that
|
||||
contain the covered work, unless you entered into that arrangement,
|
||||
or that patent license was granted, prior to 28 March 2007.
|
||||
|
||||
Nothing in this License shall be construed as excluding or limiting
|
||||
any implied license or other defenses to infringement that may
|
||||
otherwise be available to you under applicable patent law.
|
||||
|
||||
12. No Surrender of Others' Freedom.
|
||||
|
||||
If conditions are imposed on you (whether by court order, agreement or
|
||||
otherwise) that contradict the conditions of this License, they do not
|
||||
excuse you from the conditions of this License. If you cannot convey a
|
||||
covered work so as to satisfy simultaneously your obligations under this
|
||||
License and any other pertinent obligations, then as a consequence you may
|
||||
not convey it at all. For example, if you agree to terms that obligate you
|
||||
to collect a royalty for further conveying from those to whom you convey
|
||||
the Program, the only way you could satisfy both those terms and this
|
||||
License would be to refrain entirely from conveying the Program.
|
||||
|
||||
13. Use with the GNU Affero General Public License.
|
||||
|
||||
Notwithstanding any other provision of this License, you have
|
||||
permission to link or combine any covered work with a work licensed
|
||||
under version 3 of the GNU Affero General Public License into a single
|
||||
combined work, and to convey the resulting work. The terms of this
|
||||
License will continue to apply to the part which is the covered work,
|
||||
but the special requirements of the GNU Affero General Public License,
|
||||
section 13, concerning interaction through a network will apply to the
|
||||
combination as such.
|
||||
|
||||
14. Revised Versions of this License.
|
||||
|
||||
The Free Software Foundation may publish revised and/or new versions of
|
||||
the GNU General Public License from time to time. Such new versions will
|
||||
be similar in spirit to the present version, but may differ in detail to
|
||||
address new problems or concerns.
|
||||
|
||||
Each version is given a distinguishing version number. If the
|
||||
Program specifies that a certain numbered version of the GNU General
|
||||
Public License "or any later version" applies to it, you have the
|
||||
option of following the terms and conditions either of that numbered
|
||||
version or of any later version published by the Free Software
|
||||
Foundation. If the Program does not specify a version number of the
|
||||
GNU General Public License, you may choose any version ever published
|
||||
by the Free Software Foundation.
|
||||
|
||||
If the Program specifies that a proxy can decide which future
|
||||
versions of the GNU General Public License can be used, that proxy's
|
||||
public statement of acceptance of a version permanently authorizes you
|
||||
to choose that version for the Program.
|
||||
|
||||
Later license versions may give you additional or different
|
||||
permissions. However, no additional obligations are imposed on any
|
||||
author or copyright holder as a result of your choosing to follow a
|
||||
later version.
|
||||
|
||||
15. Disclaimer of Warranty.
|
||||
|
||||
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
|
||||
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
|
||||
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
|
||||
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
|
||||
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
|
||||
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
|
||||
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
||||
|
||||
16. Limitation of Liability.
|
||||
|
||||
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
||||
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
|
||||
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
|
||||
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
|
||||
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
|
||||
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
|
||||
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
|
||||
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGES.
|
||||
|
||||
17. Interpretation of Sections 15 and 16.
|
||||
|
||||
If the disclaimer of warranty and limitation of liability provided
|
||||
above cannot be given local legal effect according to their terms,
|
||||
reviewing courts shall apply local law that most closely approximates
|
||||
an absolute waiver of all civil liability in connection with the
|
||||
Program, unless a warranty or assumption of liability accompanies a
|
||||
copy of the Program in return for a fee.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
How to Apply These Terms to Your New Programs
|
||||
|
||||
If you develop a new program, and you want it to be of the greatest
|
||||
possible use to the public, the best way to achieve this is to make it
|
||||
free software which everyone can redistribute and change under these terms.
|
||||
|
||||
To do so, attach the following notices to the program. It is safest
|
||||
to attach them to the start of each source file to most effectively
|
||||
state the exclusion of warranty; and each file should have at least
|
||||
the "copyright" line and a pointer to where the full notice is found.
|
||||
|
||||
<one line to give the program's name and a brief idea of what it does.>
|
||||
Copyright (C) <year> <name of author>
|
||||
|
||||
This program is free software: you can redistribute it and/or modify
|
||||
it under the terms of the GNU General Public License as published by
|
||||
the Free Software Foundation, either version 3 of the License, or
|
||||
(at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License
|
||||
along with this program. If not, see <https://www.gnu.org/licenses/>.
|
||||
|
||||
Also add information on how to contact you by electronic and paper mail.
|
||||
|
||||
If the program does terminal interaction, make it output a short
|
||||
notice like this when it starts in an interactive mode:
|
||||
|
||||
<program> Copyright (C) <year> <name of author>
|
||||
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
||||
This is free software, and you are welcome to redistribute it
|
||||
under certain conditions; type `show c' for details.
|
||||
|
||||
The hypothetical commands `show w' and `show c' should show the appropriate
|
||||
parts of the General Public License. Of course, your program's commands
|
||||
might be different; for a GUI interface, you would use an "about box".
|
||||
|
||||
You should also get your employer (if you work as a programmer) or school,
|
||||
if any, to sign a "copyright disclaimer" for the program, if necessary.
|
||||
For more information on this, and how to apply and follow the GNU GPL, see
|
||||
<https://www.gnu.org/licenses/>.
|
||||
|
||||
The GNU General Public License does not permit incorporating your program
|
||||
into proprietary programs. If your program is a subroutine library, you
|
||||
may consider it more useful to permit linking proprietary applications with
|
||||
the library. If this is what you want to do, use the GNU Lesser General
|
||||
Public License instead of this License. But first, please read
|
||||
<https://www.gnu.org/licenses/why-not-lgpl.html>.
|
||||
317
README.md
@ -1,3 +1,316 @@
|
||||
# bandit-runner
|
||||
<a id="readme-top"></a>
|
||||
|
||||
<!-- PROJECT SHIELDS -->
|
||||
[![Contributors][contributors-shield]][contributors-url]
|
||||
[![Forks][forks-shield]][forks-url]
|
||||
[![Stargazers][stars-shield]][stars-url]
|
||||
[![Issues][issues-shield]][issues-url]
|
||||
[![GPLv3 License][license-shield]][license-url]
|
||||
[![Conventional Commits][conventional-commits-badge]](https://conventionalcommits.org)
|
||||
[![LinkedIn][linkedin-shield]][linkedin-url]
|
||||
|
||||
<!-- PROJECT LOGO -->
|
||||
<br />
|
||||
<div align="center">
|
||||
<a href="https://git.biohazardvfx.com/Nicholai/bandit-runner">
|
||||
<img src="public/bandit-logo.png" alt="Logo" width="100" height="100">
|
||||
</a>
|
||||
|
||||
<h3 align="center">Bandit Runner</h3>
|
||||
|
||||
<p align="center">
|
||||
A deterministic AI testing rig for LLMs-as-agents — built on Next.js, OpenNext, and Cloudflare Workers.
|
||||
<br />
|
||||
<a href="https://git.biohazardvfx.com/Nicholai/bandit-runner"><strong>Explore the docs »</strong></a>
|
||||
<br />
|
||||
<br />
|
||||
<a href="#">View Demo</a>
|
||||
·
|
||||
<a href="https://git.biohazardvfx.com/Nicholai/bandit-runner/issues/new?labels=bug">Report Bug</a>
|
||||
·
|
||||
<a href="https://git.biohazardvfx.com/Nicholai/bandit-runner/issues/new?labels=enhancement">Request Feature</a>
|
||||
</p>
|
||||
</div>
|
||||
|
||||
---
|
||||
|
||||
<!-- TABLE OF CONTENTS -->
|
||||
<details>
|
||||
<summary>Table of Contents</summary>
|
||||
<ol>
|
||||
<li><a href="#about-the-project">About The Project</a>
|
||||
<ul>
|
||||
<li><a href="#core-concepts">Core Concepts</a></li>
|
||||
<li><a href="#built-with">Built With</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="#getting-started">Getting Started</a>
|
||||
<ul>
|
||||
<li><a href="#prerequisites">Prerequisites</a></li>
|
||||
<li><a href="#installation">Installation</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="#usage">Usage</a></li>
|
||||
<li><a href="#architecture">Architecture</a></li>
|
||||
<li><a href="#roadmap">Roadmap</a></li>
|
||||
<li><a href="#contributing">Contributing</a></li>
|
||||
<li><a href="#license">License</a></li>
|
||||
<li><a href="#contact">Contact</a></li>
|
||||
<li><a href="#acknowledgments">Acknowledgments</a></li>
|
||||
</ol>
|
||||
</details>
|
||||
|
||||
---
|
||||
|
||||
## About The Project
|
||||
|
||||
[![Product Screenshot][product-screenshot]](#)
|
||||
|
||||
**Bandit Runner** is a public, deterministic evaluation harness for large language models.
|
||||
It transforms AI models into autonomous operators tasked with completing the **OverTheWire Bandit** wargame via SSH — entirely on Cloudflare Workers.
|
||||
|
||||
**Why it matters**
|
||||
- Provides a real-world, hands-on benchmark for autonomous reasoning and command execution.
|
||||
- Tests tool use (SSH), planning, error handling, and persistence under real network conditions.
|
||||
- Generates reproducible, privacy-safe logs for research or public leaderboards.
|
||||
|
||||
### Core Concepts
|
||||
- **Agent Role:** Each run instantiates an LLM as “BanditRunner” — a scripted, deterministic persona following a strict system prompt and command allow-list.
|
||||
- **Environment:** Next.js frontend + OpenNext build → Cloudflare Workers backend (Durable Objects + D1 + R2).
|
||||
- **Security:** Hard-scoped to `bandit.labs.overthewire.org:2220`.
|
||||
All discovered passwords are redacted in logs and sealed in short-lived encrypted blobs.
|
||||
- **Goal:** Advance from Level 0 → final level autonomously while documenting every decision.
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
### Built With
|
||||
|
||||
* [![Next.js][Next.js]][Next-url]
|
||||
* [![React][React.js]][React-url]
|
||||
* [![Cloudflare][Cloudflare-badge]][Cloudflare-url]
|
||||
* [![OpenNext][OpenNext-badge]][OpenNext-url]
|
||||
* [![Shadcn/UI][Shadcn-badge]][Shadcn-url]
|
||||
* [![TypeScript][TypeScript-badge]][TypeScript-url]
|
||||
* [![Drizzle ORM][Drizzle-badge]][Drizzle-url]
|
||||
* [![pnpm][pnpm-badge]][pnpm-url]
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## Getting Started
|
||||
|
||||
### Prerequisites
|
||||
|
||||
You need:
|
||||
* **Node.js ≥ 20**
|
||||
* **pnpm**
|
||||
```bash
|
||||
npm i -g pnpm
|
||||
```
|
||||
|
||||
* **Wrangler 3 CLI**
|
||||
|
||||
```bash
|
||||
npm i -g wrangler
|
||||
```
|
||||
* A Cloudflare account with access to:
|
||||
|
||||
* Durable Objects
|
||||
* D1 Database
|
||||
* R2 Storage
|
||||
|
||||
### Installation
|
||||
|
||||
1. Clone the repo
|
||||
|
||||
```bash
|
||||
git clone https://git.biohazardvfx.com/Nicholai/bandit-runner.git
|
||||
cd bandit-runner
|
||||
```
|
||||
2. Install dependencies
|
||||
|
||||
```bash
|
||||
pnpm install
|
||||
```
|
||||
3. Copy and configure environment
|
||||
|
||||
```bash
|
||||
cp .env.example .env.local
|
||||
```
|
||||
4. Build and run locally
|
||||
|
||||
```bash
|
||||
pnpm dev
|
||||
# or
|
||||
wrangler dev
|
||||
```
|
||||
5. Deploy preview
|
||||
|
||||
```bash
|
||||
pnpm build
|
||||
wrangler deploy --env preview
|
||||
```
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## Usage
|
||||
|
||||
Once deployed, visit `/runs/new` to start a new evaluation.
|
||||
Provide a model endpoint (OpenAI, OpenRouter, or self-hosted) and initiate a Bandit Run.
|
||||
|
||||
Each run:
|
||||
|
||||
* Spawns a Durable Object → “Run Coordinator”
|
||||
* Connects to `bandit.labs.overthewire.org:2220`
|
||||
* Executes controlled `ssh.connect` / `ssh.exec` / `ssh.close` operations
|
||||
* Streams JSONL logs and commentary to the Live Viewer
|
||||
|
||||
Developers can extend:
|
||||
|
||||
* Scoring rules (`lib/scoring/verdicts.ts`)
|
||||
* Level validators (`lib/scoring/validators.ts`)
|
||||
* Model interfaces (`lib/ssh/tool-adapter.ts`)
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## Architecture
|
||||
|
||||
```text
|
||||
Next.js (App Router)
|
||||
│
|
||||
├── UI (Shadcn/UI)
|
||||
│ ├─ LiveLog
|
||||
│ └─ LevelCard
|
||||
│
|
||||
├── Edge API Routes (OpenNext)
|
||||
│ ├─ /api/startRun
|
||||
│ ├─ /api/toolInvoke
|
||||
│ └─ /api/stream
|
||||
│
|
||||
└── Cloudflare Worker
|
||||
├─ Durable Object: RunCoordinator
|
||||
│ ├─ TCP connect() to Bandit
|
||||
│ ├─ State machine (levels, caps, timers)
|
||||
│ └─ Writes logs → R2
|
||||
├─ D1 (metadata)
|
||||
└─ R2 (artifacts)
|
||||
```
|
||||
|
||||
*See `docs/ADR-001-architecture.md` for the detailed decision record.*
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## Roadmap
|
||||
|
||||
* [x] Core runner architecture
|
||||
* [x] JSONL log streaming
|
||||
* [x] SSH tool scaffolding
|
||||
* [ ] Add live leaderboard
|
||||
* [ ] Add mock SSH server for tests
|
||||
* [ ] Expand scoring heuristics
|
||||
* [ ] Implement model-agnostic adapter layer
|
||||
* [ ] Public demo page
|
||||
|
||||
See the [open issues](https://git.biohazardvfx.com/Nicholai/bandit-runner/issues) for the full roadmap.
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## Contributing
|
||||
|
||||
Contributions are welcome.
|
||||
|
||||
1. Fork the Project
|
||||
2. Create your Feature Branch (`git checkout -b feat/amazing`)
|
||||
3. Commit (`pnpm commit`) using Conventional Commits
|
||||
4. Push (`git push origin feat/amazing`)
|
||||
5. Open a Pull Request
|
||||
|
||||
### Top Contributors
|
||||
|
||||
<a href="https://git.biohazardvfx.com/Nicholai/bandit-runner/graphs/contributors">
|
||||
<img src="https://contrib.rocks/image?repo=Nicholai/bandit-runner" alt="Contributors" />
|
||||
</a>
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## License
|
||||
|
||||
Distributed under the **GNU GPLv3** License.
|
||||
See `LICENSE` for details.
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## Contact
|
||||
|
||||
**Nicholai Vogel**
|
||||
[Website](https://nicholai.work) • [LinkedIn](https://linkedin.com/in/nicholai-vogel) • [Instagram](https://instagram.com/nicholai.exe)
|
||||
|
||||
Project Link: [https://git.biohazardvfx.com/Nicholai/bandit-runner](https://git.biohazardvfx.com/Nicholai/bandit-runner)
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
## Acknowledgments
|
||||
|
||||
* [OverTheWire Bandit](https://overthewire.org/wargames/bandit/) — for the wargame challenge itself
|
||||
* [Cloudflare Workers Docs](https://developers.cloudflare.com/workers/)
|
||||
* [OpenNext](https://opennext.js.org/)
|
||||
* [Shadcn/UI](https://ui.shadcn.com)
|
||||
* [Drizzle ORM](https://orm.drizzle.team)
|
||||
* [Choose a License](https://choosealicense.com)
|
||||
* [Img Shields](https://shields.io)
|
||||
* [Contrib.rocks](https://contrib.rocks)
|
||||
|
||||
<p align="right">(<a href="#readme-top">back to top</a>)</p>
|
||||
|
||||
---
|
||||
|
||||
<!-- MARKDOWN LINKS & IMAGES -->
|
||||
|
||||
[contributors-shield]: https://img.shields.io/github/contributors/Nicholai/bandit-runner.svg?style=for-the-badge
|
||||
[contributors-url]: https://git.biohazardvfx.com/Nicholai/bandit-runner/graphs/contributors
|
||||
[forks-shield]: https://img.shields.io/github/forks/Nicholai/bandit-runner.svg?style=for-the-badge
|
||||
[forks-url]: https://git.biohazardvfx.com/Nicholai/bandit-runner/network/members
|
||||
[stars-shield]: https://img.shields.io/github/stars/Nicholai/bandit-runner.svg?style=for-the-badge
|
||||
[stars-url]: https://git.biohazardvfx.com/Nicholai/bandit-runner/stargazers
|
||||
[issues-shield]: https://img.shields.io/github/issues/Nicholai/bandit-runner.svg?style=for-the-badge
|
||||
[issues-url]: https://git.biohazardvfx.com/Nicholai/bandit-runner/issues
|
||||
[license-shield]: https://img.shields.io/github/license/Nicholai/bandit-runner.svg?style=for-the-badge
|
||||
[license-url]: https://git.biohazardvfx.com/Nicholai/bandit-runner/blob/main/COPYING.txt
|
||||
[linkedin-shield]: https://img.shields.io/badge/-LinkedIn-black.svg?style=for-the-badge&logo=linkedin&colorB=555
|
||||
[linkedin-url]: https://linkedin.com/in/nicholai-vogel
|
||||
[product-screenshot]: public/screenshot.png
|
||||
[Next.js]: https://img.shields.io/badge/Next.js-000000?style=for-the-badge&logo=nextdotjs&logoColor=white
|
||||
[Next-url]: https://nextjs.org/
|
||||
[React.js]: https://img.shields.io/badge/React-20232A?style=for-the-badge&logo=react&logoColor=61DAFB
|
||||
[React-url]: https://react.dev/
|
||||
[Cloudflare-badge]: https://img.shields.io/badge/Cloudflare%20Workers-F38020?style=for-the-badge&logo=cloudflare&logoColor=white
|
||||
[Cloudflare-url]: https://developers.cloudflare.com/workers/
|
||||
[OpenNext-badge]: https://img.shields.io/badge/OpenNext-18181B?style=for-the-badge&logo=vercel&logoColor=white
|
||||
[OpenNext-url]: https://opennext.js.org/
|
||||
[Shadcn-badge]: https://img.shields.io/badge/Shadcn%2FUI-000000?style=for-the-badge&logo=react&logoColor=white
|
||||
[Shadcn-url]: https://ui.shadcn.com
|
||||
[TypeScript-badge]: https://img.shields.io/badge/TypeScript-3178C6?style=for-the-badge&logo=typescript&logoColor=white
|
||||
[TypeScript-url]: https://www.typescriptlang.org/
|
||||
[Drizzle-badge]: https://img.shields.io/badge/Drizzle%20ORM-3E63DD?style=for-the-badge&logo=sqlite&logoColor=white
|
||||
[Drizzle-url]: https://orm.drizzle.team
|
||||
[pnpm-badge]: https://img.shields.io/badge/pnpm-F69220?style=for-the-badge&logo=pnpm&logoColor=white
|
||||
[pnpm-url]: https://pnpm.io
|
||||
[conventional-commits-badge]: https://img.shields.io/badge/Conventional%20Commits-1.0.0-%23FE5196?style=for-the-badge&logo=conventionalcommits&logoColor=white
|
||||
|
||||
LLM test rig that runs OverTheWire Bandit end-to-end on Cloudflare Workers, with a strict SSH tool, scoring, and public run logs.
|
||||
45
bandit-runner-app/.gitignore
vendored
Normal file
@ -0,0 +1,45 @@
|
||||
# See https://help.github.com/articles/ignoring-files/ for more about ignoring files.
|
||||
|
||||
# dependencies
|
||||
/node_modules
|
||||
/.pnp
|
||||
.pnp.js
|
||||
.yarn/install-state.gz
|
||||
|
||||
# testing
|
||||
/coverage
|
||||
|
||||
# next.js
|
||||
/.next/
|
||||
/out/
|
||||
|
||||
# production
|
||||
/build
|
||||
|
||||
# misc
|
||||
.DS_Store
|
||||
*.pem
|
||||
|
||||
# debug
|
||||
npm-debug.log*
|
||||
yarn-debug.log*
|
||||
yarn-error.log*
|
||||
|
||||
# local env files
|
||||
.env*.local
|
||||
|
||||
# vercel
|
||||
.vercel
|
||||
|
||||
# typescript
|
||||
*.tsbuildinfo
|
||||
next-env.d.ts
|
||||
|
||||
# OpenNext
|
||||
/.open-next
|
||||
|
||||
# wrangler files
|
||||
.wrangler
|
||||
.dev.vars*
|
||||
!.dev.vars.example
|
||||
!.env.example
|
||||
5
bandit-runner-app/.vscode/settings.json
vendored
Normal file
@ -0,0 +1,5 @@
|
||||
{
|
||||
"files.associations": {
|
||||
"wrangler.json": "jsonc"
|
||||
}
|
||||
}
|
||||
36
bandit-runner-app/README.md
Normal file
@ -0,0 +1,36 @@
|
||||
This is a [Next.js](https://nextjs.org) project bootstrapped with [`create-next-app`](https://nextjs.org/docs/app/api-reference/cli/create-next-app).
|
||||
|
||||
## Getting Started
|
||||
|
||||
First, run the development server:
|
||||
|
||||
```bash
|
||||
npm run dev
|
||||
# or
|
||||
yarn dev
|
||||
# or
|
||||
pnpm dev
|
||||
# or
|
||||
bun dev
|
||||
```
|
||||
|
||||
Open [http://localhost:3000](http://localhost:3000) with your browser to see the result.
|
||||
|
||||
You can start editing the page by modifying `app/page.tsx`. The page auto-updates as you edit the file.
|
||||
|
||||
This project uses [`next/font`](https://nextjs.org/docs/app/building-your-application/optimizing/fonts) to automatically optimize and load [Geist](https://vercel.com/font), a new font family for Vercel.
|
||||
|
||||
## Learn More
|
||||
|
||||
To learn more about Next.js, take a look at the following resources:
|
||||
|
||||
- [Next.js Documentation](https://nextjs.org/docs) - learn about Next.js features and API.
|
||||
- [Learn Next.js](https://nextjs.org/learn) - an interactive Next.js tutorial.
|
||||
|
||||
You can check out [the Next.js GitHub repository](https://github.com/vercel/next.js) - your feedback and contributions are welcome!
|
||||
|
||||
## Deploy on Vercel
|
||||
|
||||
The easiest way to deploy your Next.js app is to use the [Vercel Platform](https://vercel.com/new?utm_medium=default-template&filter=next.js&utm_source=create-next-app&utm_campaign=create-next-app-readme) from the creators of Next.js.
|
||||
|
||||
Check out our [Next.js deployment documentation](https://nextjs.org/docs/app/building-your-application/deploying) for more details.
|
||||
8346
bandit-runner-app/cloudflare-env.d.ts
vendored
Normal file
16
bandit-runner-app/eslint.config.mjs
Normal file
@ -0,0 +1,16 @@
|
||||
import { dirname } from "path";
|
||||
import { fileURLToPath } from "url";
|
||||
import { FlatCompat } from "@eslint/eslintrc";
|
||||
|
||||
const __filename = fileURLToPath(import.meta.url);
|
||||
const __dirname = dirname(__filename);
|
||||
|
||||
const compat = new FlatCompat({
|
||||
baseDirectory: __dirname,
|
||||
});
|
||||
|
||||
const eslintConfig = [
|
||||
...compat.extends("next/core-web-vitals", "next/typescript"),
|
||||
];
|
||||
|
||||
export default eslintConfig;
|
||||
11
bandit-runner-app/next.config.ts
Normal file
@ -0,0 +1,11 @@
|
||||
import type { NextConfig } from "next";
|
||||
|
||||
const nextConfig: NextConfig = {
|
||||
/* config options here */
|
||||
};
|
||||
|
||||
export default nextConfig;
|
||||
|
||||
// added by create cloudflare to enable calling `getCloudflareContext()` in `next dev`
|
||||
import { initOpenNextCloudflareForDev } from '@opennextjs/cloudflare';
|
||||
initOpenNextCloudflareForDev();
|
||||
9
bandit-runner-app/open-next.config.ts
Normal file
@ -0,0 +1,9 @@
|
||||
import { defineCloudflareConfig } from "@opennextjs/cloudflare";
|
||||
|
||||
export default defineCloudflareConfig({
|
||||
// Uncomment to enable R2 cache,
|
||||
// It should be imported as:
|
||||
// `import r2IncrementalCache from "@opennextjs/cloudflare/overrides/incremental-cache/r2-incremental-cache";`
|
||||
// See https://opennext.js.org/cloudflare/caching for more details
|
||||
// incrementalCache: r2IncrementalCache,
|
||||
});
|
||||
32
bandit-runner-app/package.json
Normal file
@ -0,0 +1,32 @@
|
||||
{
|
||||
"name": "bandit-runner-app",
|
||||
"version": "0.1.0",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"dev": "next dev --turbopack",
|
||||
"build": "next build",
|
||||
"start": "next start",
|
||||
"lint": "next lint",
|
||||
"deploy": "opennextjs-cloudflare build && opennextjs-cloudflare deploy",
|
||||
"preview": "opennextjs-cloudflare build && opennextjs-cloudflare preview",
|
||||
"cf-typegen": "wrangler types --env-interface CloudflareEnv ./cloudflare-env.d.ts"
|
||||
},
|
||||
"dependencies": {
|
||||
"@opennextjs/cloudflare": "^1.3.0",
|
||||
"next": "15.4.6",
|
||||
"react": "19.1.0",
|
||||
"react-dom": "19.1.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@eslint/eslintrc": "^3",
|
||||
"@tailwindcss/postcss": "^4",
|
||||
"@types/node": "^20.19.19",
|
||||
"@types/react": "^19",
|
||||
"@types/react-dom": "^19",
|
||||
"eslint": "^9",
|
||||
"eslint-config-next": "15.4.6",
|
||||
"tailwindcss": "^4",
|
||||
"typescript": "^5",
|
||||
"wrangler": "^4.42.1"
|
||||
}
|
||||
}
|
||||
8161
bandit-runner-app/pnpm-lock.yaml
generated
Normal file
5
bandit-runner-app/postcss.config.mjs
Normal file
@ -0,0 +1,5 @@
|
||||
const config = {
|
||||
plugins: ["@tailwindcss/postcss"],
|
||||
};
|
||||
|
||||
export default config;
|
||||
3
bandit-runner-app/public/_headers
Normal file
@ -0,0 +1,3 @@
|
||||
# https://developers.cloudflare.com/workers/static-assets/headers
|
||||
/_next/static/*
|
||||
Cache-Control: public,max-age=31536000,immutable
|
||||
1
bandit-runner-app/public/file.svg
Normal file
@ -0,0 +1 @@
|
||||
<svg fill="none" viewBox="0 0 16 16" xmlns="http://www.w3.org/2000/svg"><path d="M14.5 13.5V5.41a1 1 0 0 0-.3-.7L9.8.29A1 1 0 0 0 9.08 0H1.5v13.5A2.5 2.5 0 0 0 4 16h8a2.5 2.5 0 0 0 2.5-2.5m-1.5 0v-7H8v-5H3v12a1 1 0 0 0 1 1h8a1 1 0 0 0 1-1M9.5 5V2.12L12.38 5zM5.13 5h-.62v1.25h2.12V5zm-.62 3h7.12v1.25H4.5zm.62 3h-.62v1.25h7.12V11z" clip-rule="evenodd" fill="#666" fill-rule="evenodd"/></svg>
|
||||
|
After Width: | Height: | Size: 391 B |
1
bandit-runner-app/public/globe.svg
Normal file
@ -0,0 +1 @@
|
||||
<svg fill="none" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 16 16"><g clip-path="url(#a)"><path fill-rule="evenodd" clip-rule="evenodd" d="M10.27 14.1a6.5 6.5 0 0 0 3.67-3.45q-1.24.21-2.7.34-.31 1.83-.97 3.1M8 16A8 8 0 1 0 8 0a8 8 0 0 0 0 16m.48-1.52a7 7 0 0 1-.96 0H7.5a4 4 0 0 1-.84-1.32q-.38-.89-.63-2.08a40 40 0 0 0 3.92 0q-.25 1.2-.63 2.08a4 4 0 0 1-.84 1.31zm2.94-4.76q1.66-.15 2.95-.43a7 7 0 0 0 0-2.58q-1.3-.27-2.95-.43a18 18 0 0 1 0 3.44m-1.27-3.54a17 17 0 0 1 0 3.64 39 39 0 0 1-4.3 0 17 17 0 0 1 0-3.64 39 39 0 0 1 4.3 0m1.1-1.17q1.45.13 2.69.34a6.5 6.5 0 0 0-3.67-3.44q.65 1.26.98 3.1M8.48 1.5l.01.02q.41.37.84 1.31.38.89.63 2.08a40 40 0 0 0-3.92 0q.25-1.2.63-2.08a4 4 0 0 1 .85-1.32 7 7 0 0 1 .96 0m-2.75.4a6.5 6.5 0 0 0-3.67 3.44 29 29 0 0 1 2.7-.34q.31-1.83.97-3.1M4.58 6.28q-1.66.16-2.95.43a7 7 0 0 0 0 2.58q1.3.27 2.95.43a18 18 0 0 1 0-3.44m.17 4.71q-1.45-.12-2.69-.34a6.5 6.5 0 0 0 3.67 3.44q-.65-1.27-.98-3.1" fill="#666"/></g><defs><clipPath id="a"><path fill="#fff" d="M0 0h16v16H0z"/></clipPath></defs></svg>
|
||||
|
After Width: | Height: | Size: 1.0 KiB |
1
bandit-runner-app/public/next.svg
Normal file
@ -0,0 +1 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 394 80"><path fill="#000" d="M262 0h68.5v12.7h-27.2v66.6h-13.6V12.7H262V0ZM149 0v12.7H94v20.4h44.3v12.6H94v21h55v12.6H80.5V0h68.7zm34.3 0h-17.8l63.8 79.4h17.9l-32-39.7 32-39.6h-17.9l-23 28.6-23-28.6zm18.3 56.7-9-11-27.1 33.7h17.8l18.3-22.7z"/><path fill="#000" d="M81 79.3 17 0H0v79.3h13.6V17l50.2 62.3H81Zm252.6-.4c-1 0-1.8-.4-2.5-1s-1.1-1.6-1.1-2.6.3-1.8 1-2.5 1.6-1 2.6-1 1.8.3 2.5 1a3.4 3.4 0 0 1 .6 4.3 3.7 3.7 0 0 1-3 1.8zm23.2-33.5h6v23.3c0 2.1-.4 4-1.3 5.5a9.1 9.1 0 0 1-3.8 3.5c-1.6.8-3.5 1.3-5.7 1.3-2 0-3.7-.4-5.3-1s-2.8-1.8-3.7-3.2c-.9-1.3-1.4-3-1.4-5h6c.1.8.3 1.6.7 2.2s1 1.2 1.6 1.5c.7.4 1.5.5 2.4.5 1 0 1.8-.2 2.4-.6a4 4 0 0 0 1.6-1.8c.3-.8.5-1.8.5-3V45.5zm30.9 9.1a4.4 4.4 0 0 0-2-3.3 7.5 7.5 0 0 0-4.3-1.1c-1.3 0-2.4.2-3.3.5-.9.4-1.6 1-2 1.6a3.5 3.5 0 0 0-.3 4c.3.5.7.9 1.3 1.2l1.8 1 2 .5 3.2.8c1.3.3 2.5.7 3.7 1.2a13 13 0 0 1 3.2 1.8 8.1 8.1 0 0 1 3 6.5c0 2-.5 3.7-1.5 5.1a10 10 0 0 1-4.4 3.5c-1.8.8-4.1 1.2-6.8 1.2-2.6 0-4.9-.4-6.8-1.2-2-.8-3.4-2-4.5-3.5a10 10 0 0 1-1.7-5.6h6a5 5 0 0 0 3.5 4.6c1 .4 2.2.6 3.4.6 1.3 0 2.5-.2 3.5-.6 1-.4 1.8-1 2.4-1.7a4 4 0 0 0 .8-2.4c0-.9-.2-1.6-.7-2.2a11 11 0 0 0-2.1-1.4l-3.2-1-3.8-1c-2.8-.7-5-1.7-6.6-3.2a7.2 7.2 0 0 1-2.4-5.7 8 8 0 0 1 1.7-5 10 10 0 0 1 4.3-3.5c2-.8 4-1.2 6.4-1.2 2.3 0 4.4.4 6.2 1.2 1.8.8 3.2 2 4.3 3.4 1 1.4 1.5 3 1.5 5h-5.8z"/></svg>
|
||||
|
After Width: | Height: | Size: 1.3 KiB |
1
bandit-runner-app/public/vercel.svg
Normal file
@ -0,0 +1 @@
|
||||
<svg fill="none" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1155 1000"><path d="m577.3 0 577.4 1000H0z" fill="#fff"/></svg>
|
||||
|
After Width: | Height: | Size: 128 B |
1
bandit-runner-app/public/window.svg
Normal file
@ -0,0 +1 @@
|
||||
<svg fill="none" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 16 16"><path fill-rule="evenodd" clip-rule="evenodd" d="M1.5 2.5h13v10a1 1 0 0 1-1 1h-11a1 1 0 0 1-1-1zM0 1h16v11.5a2.5 2.5 0 0 1-2.5 2.5h-11A2.5 2.5 0 0 1 0 12.5zm3.75 4.5a.75.75 0 1 0 0-1.5.75.75 0 0 0 0 1.5M7 4.75a.75.75 0 1 1-1.5 0 .75.75 0 0 1 1.5 0m1.75.75a.75.75 0 1 0 0-1.5.75.75 0 0 0 0 1.5" fill="#666"/></svg>
|
||||
|
After Width: | Height: | Size: 385 B |
BIN
bandit-runner-app/src/app/favicon.ico
Normal file
|
After Width: | Height: | Size: 25 KiB |
26
bandit-runner-app/src/app/globals.css
Normal file
@ -0,0 +1,26 @@
|
||||
@import "tailwindcss";
|
||||
|
||||
:root {
|
||||
--background: #ffffff;
|
||||
--foreground: #171717;
|
||||
}
|
||||
|
||||
@theme inline {
|
||||
--color-background: var(--background);
|
||||
--color-foreground: var(--foreground);
|
||||
--font-sans: var(--font-geist-sans);
|
||||
--font-mono: var(--font-geist-mono);
|
||||
}
|
||||
|
||||
@media (prefers-color-scheme: dark) {
|
||||
:root {
|
||||
--background: #0a0a0a;
|
||||
--foreground: #ededed;
|
||||
}
|
||||
}
|
||||
|
||||
body {
|
||||
background: var(--background);
|
||||
color: var(--foreground);
|
||||
font-family: Arial, Helvetica, sans-serif;
|
||||
}
|
||||
34
bandit-runner-app/src/app/layout.tsx
Normal file
@ -0,0 +1,34 @@
|
||||
import type { Metadata } from "next";
|
||||
import { Geist, Geist_Mono } from "next/font/google";
|
||||
import "./globals.css";
|
||||
|
||||
const geistSans = Geist({
|
||||
variable: "--font-geist-sans",
|
||||
subsets: ["latin"],
|
||||
});
|
||||
|
||||
const geistMono = Geist_Mono({
|
||||
variable: "--font-geist-mono",
|
||||
subsets: ["latin"],
|
||||
});
|
||||
|
||||
export const metadata: Metadata = {
|
||||
title: "Create Next App",
|
||||
description: "Generated by create next app",
|
||||
};
|
||||
|
||||
export default function RootLayout({
|
||||
children,
|
||||
}: Readonly<{
|
||||
children: React.ReactNode;
|
||||
}>) {
|
||||
return (
|
||||
<html lang="en">
|
||||
<body
|
||||
className={`${geistSans.variable} ${geistMono.variable} antialiased`}
|
||||
>
|
||||
{children}
|
||||
</body>
|
||||
</html>
|
||||
);
|
||||
}
|
||||
103
bandit-runner-app/src/app/page.tsx
Normal file
@ -0,0 +1,103 @@
|
||||
import Image from "next/image";
|
||||
|
||||
export default function Home() {
|
||||
return (
|
||||
<div className="font-sans grid grid-rows-[20px_1fr_20px] items-center justify-items-center min-h-screen p-8 pb-20 gap-16 sm:p-20">
|
||||
<main className="flex flex-col gap-[32px] row-start-2 items-center sm:items-start">
|
||||
<Image
|
||||
className="dark:invert"
|
||||
src="/next.svg"
|
||||
alt="Next.js logo"
|
||||
width={180}
|
||||
height={38}
|
||||
priority
|
||||
/>
|
||||
<ol className="font-mono list-inside list-decimal text-sm/6 text-center sm:text-left">
|
||||
<li className="mb-2 tracking-[-.01em]">
|
||||
Get started by editing{" "}
|
||||
<code className="bg-black/[.05] dark:bg-white/[.06] font-mono font-semibold px-1 py-0.5 rounded">
|
||||
src/app/page.tsx
|
||||
</code>
|
||||
.
|
||||
</li>
|
||||
<li className="tracking-[-.01em]">
|
||||
Save and see your changes instantly.
|
||||
</li>
|
||||
</ol>
|
||||
|
||||
<div className="flex gap-4 items-center flex-col sm:flex-row">
|
||||
<a
|
||||
className="rounded-full border border-solid border-transparent transition-colors flex items-center justify-center bg-foreground text-background gap-2 hover:bg-[#383838] dark:hover:bg-[#ccc] font-medium text-sm sm:text-base h-10 sm:h-12 px-4 sm:px-5 sm:w-auto"
|
||||
href="https://vercel.com/new?utm_source=create-next-app&utm_medium=appdir-template-tw&utm_campaign=create-next-app"
|
||||
target="_blank"
|
||||
rel="noopener noreferrer"
|
||||
>
|
||||
<Image
|
||||
className="dark:invert"
|
||||
src="/vercel.svg"
|
||||
alt="Vercel logomark"
|
||||
width={20}
|
||||
height={20}
|
||||
/>
|
||||
Deploy now
|
||||
</a>
|
||||
<a
|
||||
className="rounded-full border border-solid border-black/[.08] dark:border-white/[.145] transition-colors flex items-center justify-center hover:bg-[#f2f2f2] dark:hover:bg-[#1a1a1a] hover:border-transparent font-medium text-sm sm:text-base h-10 sm:h-12 px-4 sm:px-5 w-full sm:w-auto md:w-[158px]"
|
||||
href="https://nextjs.org/docs?utm_source=create-next-app&utm_medium=appdir-template-tw&utm_campaign=create-next-app"
|
||||
target="_blank"
|
||||
rel="noopener noreferrer"
|
||||
>
|
||||
Read our docs
|
||||
</a>
|
||||
</div>
|
||||
</main>
|
||||
<footer className="row-start-3 flex gap-[24px] flex-wrap items-center justify-center">
|
||||
<a
|
||||
className="flex items-center gap-2 hover:underline hover:underline-offset-4"
|
||||
href="https://nextjs.org/learn?utm_source=create-next-app&utm_medium=appdir-template-tw&utm_campaign=create-next-app"
|
||||
target="_blank"
|
||||
rel="noopener noreferrer"
|
||||
>
|
||||
<Image
|
||||
aria-hidden
|
||||
src="/file.svg"
|
||||
alt="File icon"
|
||||
width={16}
|
||||
height={16}
|
||||
/>
|
||||
Learn
|
||||
</a>
|
||||
<a
|
||||
className="flex items-center gap-2 hover:underline hover:underline-offset-4"
|
||||
href="https://vercel.com/templates?framework=next.js&utm_source=create-next-app&utm_medium=appdir-template-tw&utm_campaign=create-next-app"
|
||||
target="_blank"
|
||||
rel="noopener noreferrer"
|
||||
>
|
||||
<Image
|
||||
aria-hidden
|
||||
src="/window.svg"
|
||||
alt="Window icon"
|
||||
width={16}
|
||||
height={16}
|
||||
/>
|
||||
Examples
|
||||
</a>
|
||||
<a
|
||||
className="flex items-center gap-2 hover:underline hover:underline-offset-4"
|
||||
href="https://nextjs.org?utm_source=create-next-app&utm_medium=appdir-template-tw&utm_campaign=create-next-app"
|
||||
target="_blank"
|
||||
rel="noopener noreferrer"
|
||||
>
|
||||
<Image
|
||||
aria-hidden
|
||||
src="/globe.svg"
|
||||
alt="Globe icon"
|
||||
width={16}
|
||||
height={16}
|
||||
/>
|
||||
Go to nextjs.org →
|
||||
</a>
|
||||
</footer>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
31
bandit-runner-app/tsconfig.json
Normal file
@ -0,0 +1,31 @@
|
||||
{
|
||||
"compilerOptions": {
|
||||
"target": "ES2017",
|
||||
"lib": ["dom", "dom.iterable", "esnext"],
|
||||
"allowJs": true,
|
||||
"skipLibCheck": true,
|
||||
"strict": true,
|
||||
"noEmit": true,
|
||||
"esModuleInterop": true,
|
||||
"module": "esnext",
|
||||
"moduleResolution": "bundler",
|
||||
"resolveJsonModule": true,
|
||||
"isolatedModules": true,
|
||||
"jsx": "preserve",
|
||||
"incremental": true,
|
||||
"plugins": [
|
||||
{
|
||||
"name": "next"
|
||||
}
|
||||
],
|
||||
"paths": {
|
||||
"@/*": ["./src/*"]
|
||||
},
|
||||
"types": [
|
||||
"./cloudflare-env.d.ts",
|
||||
"node"
|
||||
]
|
||||
},
|
||||
"include": ["next-env.d.ts", "**/*.ts", "**/*.tsx", ".next/types/**/*.ts"],
|
||||
"exclude": ["node_modules"]
|
||||
}
|
||||
51
bandit-runner-app/wrangler.jsonc
Normal file
@ -0,0 +1,51 @@
|
||||
/**
|
||||
* For more details on how to configure Wrangler, refer to:
|
||||
* https://developers.cloudflare.com/workers/wrangler/configuration/
|
||||
*/
|
||||
{
|
||||
"$schema": "node_modules/wrangler/config-schema.json",
|
||||
"name": "bandit-runner-app",
|
||||
"main": ".open-next/worker.js",
|
||||
"compatibility_date": "2025-03-01",
|
||||
"compatibility_flags": [
|
||||
"nodejs_compat",
|
||||
"global_fetch_strictly_public"
|
||||
],
|
||||
"assets": {
|
||||
"binding": "ASSETS",
|
||||
"directory": ".open-next/assets"
|
||||
},
|
||||
"observability": {
|
||||
"enabled": true
|
||||
}
|
||||
/**
|
||||
* Smart Placement
|
||||
* Docs: https://developers.cloudflare.com/workers/configuration/smart-placement/#smart-placement
|
||||
*/
|
||||
// "placement": { "mode": "smart" }
|
||||
/**
|
||||
* Bindings
|
||||
* Bindings allow your Worker to interact with resources on the Cloudflare Developer Platform, including
|
||||
* databases, object storage, AI inference, real-time communication and more.
|
||||
* https://developers.cloudflare.com/workers/runtime-apis/bindings/
|
||||
*/
|
||||
/**
|
||||
* Environment Variables
|
||||
* https://developers.cloudflare.com/workers/wrangler/configuration/#environment-variables
|
||||
*/
|
||||
// "vars": { "MY_VARIABLE": "production_value" }
|
||||
/**
|
||||
* Note: Use secrets to store sensitive data.
|
||||
* https://developers.cloudflare.com/workers/configuration/secrets/
|
||||
*/
|
||||
/**
|
||||
* Static Assets
|
||||
* https://developers.cloudflare.com/workers/static-assets/binding/
|
||||
*/
|
||||
// "assets": { "directory": "./public/", "binding": "ASSETS" }
|
||||
/**
|
||||
* Service Bindings (communicate between multiple Workers)
|
||||
* https://developers.cloudflare.com/workers/wrangler/configuration/#service-bindings
|
||||
*/
|
||||
// "services": [{ "binding": "MY_SERVICE", "service": "my-service" }]
|
||||
}
|
||||
41
docs/bandit-runner.md
Normal file
@ -0,0 +1,41 @@
|
||||
# ADR 001: Bandit Runner architecture on Next.js + Cloudflare Workers
|
||||
|
||||
Status: Proposed
|
||||
Date: 2025-10-08
|
||||
Decision drivers:
|
||||
- Run long-lived evals safely on Workers with Durable Objects
|
||||
- Deterministic scoring and anti-abuse
|
||||
- Cheap to run, easy to reason about
|
||||
|
||||
Context:
|
||||
- We need an LLM test rig that controls SSH to OverTheWire Bandit only
|
||||
- Workers runtime supports outbound TCP via connect()
|
||||
- We require per-run state, timeouts, logs, and verification before advancing levels
|
||||
|
||||
Options:
|
||||
A) Next.js on Workers + Durable Objects + D1 + R2
|
||||
B) Same but relay SSH via a tiny TCP proxy you control
|
||||
C) Traditional Node server on Fly/Render with WebSockets, no Workers
|
||||
|
||||
Decision:
|
||||
- Choose A as primary. Keep B as fallback if SSH libs are incompatible with Workers runtime.
|
||||
|
||||
Implications:
|
||||
- DO holds the socket and run state. API routes are thin. UI subscribes via WebSocket.
|
||||
- Storage split: D1 for metadata, R2 for JSONL logs and artifacts.
|
||||
- Strict command and network allow-lists enforced inside DO.
|
||||
|
||||
Security:
|
||||
- Hardcode target host and port
|
||||
- Redact secrets in UI, store raw in sealed R2 object with short TTL
|
||||
- Rate limit run creation, per-level caps
|
||||
|
||||
Operations:
|
||||
- One DO namespace per env
|
||||
- Migrations via wrangler for D1
|
||||
- Logpush or JSONL export for analysis
|
||||
|
||||
Follow-ups:
|
||||
- ADR 002: SSH client choice for Workers
|
||||
- ADR 003: Scoring and validator rules per level
|
||||
- ADR 004: Data retention policy
|
||||
390
docs/setup-audit-report.md
Normal file
@ -0,0 +1,390 @@
|
||||
# Repository Setup Audit Report
|
||||
**Project:** Bandit Runner
|
||||
**Date:** October 9, 2025
|
||||
**Auditor:** AI Assistant (using Gitea + Context7 Documentation)
|
||||
|
||||
---
|
||||
|
||||
## Executive Summary
|
||||
|
||||
Your repository follows most best practices for modern software development with **Conventional Commits**, proper **Gitea Actions workflows**, and good documentation. However, several critical issues were identified and **have been fixed** during this audit.
|
||||
|
||||
---
|
||||
|
||||
## ✅ What You're Doing Right
|
||||
|
||||
### 1. **Conventional Commits Implementation**
|
||||
- ✅ Branch naming strategy follows conventions (`feat/`, `fix/`, etc.)
|
||||
- ✅ PR title linting enforces Conventional Commits format
|
||||
- ✅ Clear type definitions (feat, fix, docs, chore, refactor, test)
|
||||
- ✅ Conventional Commits badge added to README
|
||||
|
||||
**Reference:** [Conventional Commits Specification](https://conventionalcommits.org/)
|
||||
|
||||
### 2. **Issue & PR Templates**
|
||||
- ✅ Bug report template with proper structure
|
||||
- ✅ Feature request template with acceptance criteria
|
||||
- ✅ Enhancement template for improvements
|
||||
- ✅ Pull request template with comprehensive checklist
|
||||
- ✅ All templates use proper labels
|
||||
|
||||
### 3. **Documentation**
|
||||
- ✅ Comprehensive README with badges, installation, and architecture
|
||||
- ✅ GPLv3 License properly included (`COPYING.txt`)
|
||||
- ✅ Project logo and branding
|
||||
- ✅ Clear contact information and acknowledgments
|
||||
- ✅ CONTRIBUTING.md with branch strategy (now enhanced)
|
||||
|
||||
### 4. **`.gitignore` Configuration**
|
||||
- ✅ Comprehensive Node.js patterns
|
||||
- ✅ Cloudflare/Wrangler-specific ignores
|
||||
- ✅ OpenNext build artifacts excluded
|
||||
- ✅ Proper lockfile hygiene (commits pnpm, ignores npm/yarn)
|
||||
- ✅ Test and coverage artifacts ignored
|
||||
|
||||
### 5. **Tech Stack**
|
||||
- ✅ Next.js 15.4.6 (latest stable)
|
||||
- ✅ React 19.1.0
|
||||
- ✅ TypeScript with proper configuration
|
||||
- ✅ pnpm as package manager
|
||||
- ✅ ESLint for code quality
|
||||
- ✅ Cloudflare Workers deployment target
|
||||
|
||||
---
|
||||
|
||||
## ⚠️ Issues Found & Fixed
|
||||
|
||||
### 1. **CI Workflow Configuration** ✅ FIXED
|
||||
|
||||
**File:** `.gitea/workflows/ci.yml`
|
||||
|
||||
#### Issues:
|
||||
- ❌ Working directory not specified (runs from repo root instead of `bandit-runner-app/`)
|
||||
- ❌ Incorrect script name: `pnpm eslint .` → should be `pnpm lint`
|
||||
- ❌ Missing test script (workflow expects `pnpm test` which doesn't exist)
|
||||
- ❌ Redundant pnpm setup (both cache and action-setup)
|
||||
- ❌ TypeScript typecheck command not wrapped properly
|
||||
|
||||
#### Fixes Applied:
|
||||
```yaml
|
||||
# Added working directory
|
||||
defaults:
|
||||
run:
|
||||
working-directory: ./bandit-runner-app
|
||||
|
||||
# Fixed script names
|
||||
- run: pnpm lint # was: pnpm eslint . --max-warnings=0
|
||||
- run: npx tsc --noEmit # was: pnpm tsc -p tsconfig.json --noEmit
|
||||
|
||||
# Removed test step (can be added when tests are implemented)
|
||||
|
||||
# Fixed pnpm setup order (pnpm action first, then Node with cache)
|
||||
```
|
||||
|
||||
**Best Practice Reference:**
|
||||
- [GitHub Actions Starter Workflows](https://github.com/actions/starter-workflows)
|
||||
- Working directory: Essential for monorepo/subdirectory structures
|
||||
|
||||
### 2. **Missing `.env.example`** ✅ FIXED
|
||||
|
||||
**Issue:**
|
||||
- README references `cp .env.example .env.local` (line 140)
|
||||
- File didn't exist, breaking onboarding flow
|
||||
|
||||
**Fix Applied:**
|
||||
Created comprehensive `.env.example` with:
|
||||
- OpenAI API key placeholder
|
||||
- Cloudflare account/token configuration
|
||||
- Optional LLM endpoints
|
||||
- Bandit SSH settings
|
||||
- Development-specific variables
|
||||
- Clear comments and sections
|
||||
|
||||
**Best Practice:** Always provide `.env.example` for environment variable documentation.
|
||||
|
||||
### 3. **Incomplete CONTRIBUTING.md** ✅ FIXED
|
||||
|
||||
**Issue:**
|
||||
- File ended abruptly mid-sentence ("Examples:")
|
||||
- No actual examples provided
|
||||
- Missing commit message format details
|
||||
- No PR workflow instructions
|
||||
|
||||
**Fixes Applied:**
|
||||
- ✅ Added complete branch naming examples
|
||||
- ✅ Added Conventional Commits message format
|
||||
- ✅ Included PR workflow steps
|
||||
- ✅ Added code quality checklist
|
||||
- ✅ Clear instructions for running linting and typechecking
|
||||
|
||||
### 4. **Package Manager Lockfile** ✅ FIXED
|
||||
|
||||
**Issue:**
|
||||
- Project uses pnpm (per scripts and CI)
|
||||
- Only `package-lock.json` (npm) existed
|
||||
- `.gitignore` specifies pnpm-lock.yaml should be committed
|
||||
- CI workflow expected `pnpm-lock.yaml`
|
||||
|
||||
**Fix Applied:**
|
||||
- ✅ Generated `pnpm-lock.yaml` using `pnpm install --lockfile-only`
|
||||
- ✅ Updated CI workflow to use correct lockfile path
|
||||
|
||||
**Action Required:** Delete `package-lock.json` from the repository:
|
||||
```bash
|
||||
cd bandit-runner-app
|
||||
rm package-lock.json
|
||||
git add -u
|
||||
git commit -m "chore: remove npm lockfile, using pnpm"
|
||||
```
|
||||
|
||||
### 5. **README Badge Enhancement** ✅ FIXED
|
||||
|
||||
**Addition:**
|
||||
- ✅ Added Conventional Commits badge
|
||||
- ✅ Fixed license badge text (was "MIT", now "GPLv3")
|
||||
|
||||
---
|
||||
|
||||
## 📋 Recommended Next Steps
|
||||
|
||||
### 1. **Add Testing Infrastructure** (HIGH PRIORITY)
|
||||
|
||||
Your CI workflow is ready for tests, but no test framework exists yet.
|
||||
|
||||
**Recommendations:**
|
||||
```bash
|
||||
cd bandit-runner-app
|
||||
|
||||
# Option A: Vitest (recommended for Next.js)
|
||||
pnpm add -D vitest @vitejs/plugin-react @testing-library/react @testing-library/jest-dom
|
||||
|
||||
# Option B: Jest (traditional)
|
||||
pnpm add -D jest @types/jest jest-environment-jsdom @testing-library/react @testing-library/jest-dom
|
||||
```
|
||||
|
||||
Add to `package.json`:
|
||||
```json
|
||||
"scripts": {
|
||||
"test": "vitest run",
|
||||
"test:watch": "vitest"
|
||||
}
|
||||
```
|
||||
|
||||
Then re-enable in `.gitea/workflows/ci.yml`:
|
||||
```yaml
|
||||
- name: Unit tests
|
||||
run: pnpm test
|
||||
```
|
||||
|
||||
### 2. **Add Code Coverage** (MEDIUM PRIORITY)
|
||||
|
||||
```bash
|
||||
pnpm add -D @vitest/coverage-v8
|
||||
```
|
||||
|
||||
Add to CI workflow:
|
||||
```yaml
|
||||
- name: Coverage
|
||||
run: pnpm test --coverage
|
||||
|
||||
- name: Upload coverage
|
||||
uses: codecov/codecov-action@v3
|
||||
with:
|
||||
file: ./coverage/coverage-final.json
|
||||
```
|
||||
|
||||
### 3. **Add Pre-commit Hooks** (RECOMMENDED)
|
||||
|
||||
Enforce quality before commits:
|
||||
|
||||
```bash
|
||||
pnpm add -D husky lint-staged
|
||||
|
||||
# Initialize husky
|
||||
pnpm exec husky init
|
||||
```
|
||||
|
||||
Add to `package.json`:
|
||||
```json
|
||||
"lint-staged": {
|
||||
"*.{ts,tsx}": [
|
||||
"eslint --fix",
|
||||
"prettier --write"
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
Create `.husky/pre-commit`:
|
||||
```bash
|
||||
#!/bin/sh
|
||||
cd bandit-runner-app
|
||||
pnpm lint-staged
|
||||
```
|
||||
|
||||
### 4. **Add Commitlint** (RECOMMENDED)
|
||||
|
||||
Enforce Conventional Commits locally:
|
||||
|
||||
```bash
|
||||
pnpm add -D @commitlint/cli @commitlint/config-conventional
|
||||
```
|
||||
|
||||
Create `commitlint.config.js`:
|
||||
```js
|
||||
module.exports = { extends: ['@commitlint/config-conventional'] };
|
||||
```
|
||||
|
||||
Add to `.husky/commit-msg`:
|
||||
```bash
|
||||
#!/bin/sh
|
||||
cd bandit-runner-app
|
||||
npx --no -- commitlint --edit $1
|
||||
```
|
||||
|
||||
### 5. **Add Dependabot/Renovate** (OPTIONAL)
|
||||
|
||||
Automated dependency updates. For Gitea, configure Renovate:
|
||||
|
||||
Create `.gitea/renovate.json`:
|
||||
```json
|
||||
{
|
||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||
"extends": ["config:base"],
|
||||
"schedule": ["before 5am on monday"],
|
||||
"labels": ["dependencies"],
|
||||
"packageRules": [
|
||||
{
|
||||
"matchUpdateTypes": ["minor", "patch"],
|
||||
"automerge": true
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
### 6. **Add Architecture Decision Records** (RECOMMENDED)
|
||||
|
||||
You reference `docs/ADR-001-architecture.md` in README (line 205) but it doesn't exist yet.
|
||||
|
||||
**Template:**
|
||||
```bash
|
||||
mkdir -p docs/adr
|
||||
```
|
||||
|
||||
Create `docs/adr/001-cloudflare-workers-architecture.md`:
|
||||
```markdown
|
||||
# ADR-001: Cloudflare Workers Architecture
|
||||
|
||||
## Status
|
||||
Accepted
|
||||
|
||||
## Context
|
||||
Need to run Next.js app on edge with Durable Objects...
|
||||
|
||||
## Decision
|
||||
Use OpenNext + Cloudflare Workers...
|
||||
|
||||
## Consequences
|
||||
Positive: Fast edge execution, low latency...
|
||||
Negative: Learning curve, debugging complexity...
|
||||
```
|
||||
|
||||
### 7. **Add GitHub/Gitea Workflow Badges** (OPTIONAL)
|
||||
|
||||
Show CI status in README:
|
||||
|
||||
```markdown
|
||||
[](https://git.biohazardvfx.com/Nicholai/bandit-runner/actions?workflow=ci.yml)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 🔍 Compliance Checklist
|
||||
|
||||
Based on **Gitea Actions** and **Conventional Commits** best practices:
|
||||
|
||||
| Category | Item | Status |
|
||||
|----------|------|--------|
|
||||
| **Version Control** | `.gitignore` comprehensive | ✅ |
|
||||
| | Proper lockfile (pnpm-lock.yaml) | ✅ |
|
||||
| | License file present | ✅ |
|
||||
| **CI/CD** | Workflow syntax valid | ✅ |
|
||||
| | Working directory specified | ✅ |
|
||||
| | Dependency caching enabled | ✅ |
|
||||
| | Linting in CI | ✅ |
|
||||
| | Type checking in CI | ✅ |
|
||||
| | Tests in CI | ⚠️ (framework not set up) |
|
||||
| **Documentation** | README complete | ✅ |
|
||||
| | CONTRIBUTING.md complete | ✅ |
|
||||
| | `.env.example` present | ✅ |
|
||||
| | License properly declared | ✅ |
|
||||
| **Code Quality** | Conventional Commits enforced | ✅ |
|
||||
| | PR template present | ✅ |
|
||||
| | Issue templates present | ✅ |
|
||||
| | ESLint configured | ✅ |
|
||||
| | TypeScript configured | ✅ |
|
||||
| | Pre-commit hooks | ❌ (recommended) |
|
||||
| **Dependencies** | Package manager consistent | ✅ |
|
||||
| | Dependency updates automated | ❌ (optional) |
|
||||
|
||||
---
|
||||
|
||||
## 📚 Resources & References
|
||||
|
||||
### Official Documentation
|
||||
- **Conventional Commits:** https://conventionalcommits.org/
|
||||
- **Gitea Actions:** https://docs.gitea.com/usage/actions/overview
|
||||
- **GitHub Actions (compatible):** https://docs.github.com/actions
|
||||
- **pnpm:** https://pnpm.io/
|
||||
- **Next.js:** https://nextjs.org/docs
|
||||
- **OpenNext:** https://opennext.js.org/
|
||||
- **Cloudflare Workers:** https://developers.cloudflare.com/workers/
|
||||
|
||||
### Tools Used in This Audit
|
||||
- **Context7 MCP:** Retrieved best practices from Conventional Commits and GitHub Actions Starter Workflows
|
||||
- **Gitea MCP:** (Available but not needed for this self-hosted instance)
|
||||
- **Static Analysis:** File structure, workflow syntax, documentation completeness
|
||||
|
||||
---
|
||||
|
||||
## 🎯 Summary
|
||||
|
||||
Your repository setup is **solid and follows modern best practices**. The issues found were primarily **configuration mismatches** between the CI workflow expectations and actual project structure, which have all been fixed.
|
||||
|
||||
### Changes Made:
|
||||
1. ✅ Fixed `.gitea/workflows/ci.yml` (working directory, script names, dependencies)
|
||||
2. ✅ Created `.env.example` with comprehensive documentation
|
||||
3. ✅ Enhanced `CONTRIBUTING.md` with complete workflow
|
||||
4. ✅ Generated `pnpm-lock.yaml` for proper dependency locking
|
||||
5. ✅ Added Conventional Commits badge to README
|
||||
6. ✅ Fixed license badge text
|
||||
|
||||
### Immediate Action Required:
|
||||
```bash
|
||||
# Remove conflicting npm lockfile
|
||||
rm bandit-runner-app/package-lock.json
|
||||
|
||||
# Stage all changes
|
||||
git add .
|
||||
|
||||
# Commit with conventional format
|
||||
git commit -m "chore: fix ci workflow, add env example, enhance contributing guide
|
||||
|
||||
- Fix CI workflow working directory and script names
|
||||
- Add comprehensive .env.example file
|
||||
- Complete CONTRIBUTING.md with examples and workflow
|
||||
- Generate pnpm-lock.yaml for proper dependency locking
|
||||
- Add Conventional Commits badge to README
|
||||
- Remove npm lockfile in favor of pnpm"
|
||||
```
|
||||
|
||||
### Next Sprint:
|
||||
1. Add testing framework (Vitest recommended)
|
||||
2. Set up pre-commit hooks (Husky + lint-staged)
|
||||
3. Add commitlint for local commit validation
|
||||
4. Create missing ADR documents
|
||||
|
||||
---
|
||||
|
||||
**Audit Complete** ✅
|
||||
All critical issues have been resolved. Your repository now follows Gitea and industry best practices.
|
||||
|
||||
BIN
public/bandit-logo.png
Normal file
|
After Width: | Height: | Size: 1.3 MiB |
100
scripts/seed-labels.sh
Executable file
@ -0,0 +1,100 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
# Config via env
|
||||
GITEA_URL="${GITEA_URL:-https://git.biohazardvfx.com}"
|
||||
OWNER="${OWNER:-Nicholai}"
|
||||
REPO="${REPO:-bandit-runner}"
|
||||
: "${TOKEN:?Set TOKEN env var with a Gitea API token}"
|
||||
|
||||
# curl wrapper: returns body on stdout, sets HTTP_CODE global
|
||||
api() { # $1=METHOD $2=/path $3=[json-body]
|
||||
local m="$1" p="$2" body="${3:-}" tmp http
|
||||
tmp="$(mktemp)"
|
||||
if [[ -n "$body" ]]; then
|
||||
http="$(curl -fsS -o "$tmp" -w '%{http_code}' -X "$m" \
|
||||
"${GITEA_URL%/}/api/v1${p}" \
|
||||
-H "Authorization: token $TOKEN" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$body")" || { rm -f "$tmp"; echo "curl failed $m $p" >&2; exit 1; }
|
||||
else
|
||||
http="$(curl -fsS -o "$tmp" -w '%{http_code}' -X "$m" \
|
||||
"${GITEA_URL%/}/api/v1${p}" \
|
||||
-H "Authorization: token $TOKEN" \
|
||||
-H "Content-Type: application/json")" || { rm -f "$tmp"; echo "curl failed $m $p" >&2; exit 1; }
|
||||
fi
|
||||
HTTP_CODE="$http"
|
||||
cat "$tmp"
|
||||
rm -f "$tmp"
|
||||
}
|
||||
|
||||
# Get existing labels once (map name->id)
|
||||
declare -A LABEL_IDS
|
||||
load_labels() {
|
||||
local body; body="$(api GET "/repos/$OWNER/$REPO/labels")"
|
||||
if [[ "$HTTP_CODE" != "200" ]]; then
|
||||
echo "List labels failed: HTTP $HTTP_CODE" >&2; echo "$body" >&2; exit 1
|
||||
fi
|
||||
# requires jq
|
||||
while IFS=$'\t' read -r id name; do
|
||||
LABEL_IDS["$name"]="$id"
|
||||
done < <(jq -r '.[] | "\(.id)\t\(.name)"' <<<"$body")
|
||||
}
|
||||
|
||||
json() { # name color desc -> compact JSON
|
||||
jq -c -n --arg n "$1" --arg c "$2" --arg d "$3" '{name:$n, color:$c, description:$d}'
|
||||
}
|
||||
|
||||
# Gitea accepts hex with or without leading '#'. We'll strip '#'.
|
||||
hex() { echo "${1#\#}"; }
|
||||
|
||||
upsert() { # name color desc
|
||||
local n="$1" c="$(hex "$2")" d="$3" payload code body id
|
||||
id="${LABEL_IDS[$n]:-}"
|
||||
payload="$(json "$n" "$c" "$d")"
|
||||
if [[ -n "$id" ]]; then
|
||||
body="$(api PATCH "/repos/$OWNER/$REPO/labels/$id" "$payload")"
|
||||
code="$HTTP_CODE"
|
||||
if [[ "$code" != "200" ]]; then echo "Update $n failed: HTTP $code $body" >&2; exit 1; fi
|
||||
echo "updated: $n (#$c)"
|
||||
else
|
||||
body="$(api POST "/repos/$OWNER/$REPO/labels" "$payload")"
|
||||
code="$HTTP_CODE"
|
||||
if [[ "$code" == "201" ]]; then
|
||||
echo "created: $n (#$c)"
|
||||
elif [[ "$code" == "422" ]]; then
|
||||
# race/exists: reload ids, patch
|
||||
load_labels
|
||||
id="${LABEL_IDS[$n]:-}"
|
||||
[[ -z "$id" ]] && { echo "cannot find $n after 422"; exit 1; }
|
||||
body="$(api PATCH "/repos/$OWNER/$REPO/labels/$id" "$payload")"
|
||||
[[ "$HTTP_CODE" == "200" ]] || { echo "update after 422 failed: $body"; exit 1; }
|
||||
echo "updated: $n (#$c)"
|
||||
else
|
||||
echo "create $n failed: HTTP $code $body" >&2; exit 1
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
# ---- run ----
|
||||
command -v jq >/dev/null || { echo "jq not found"; exit 1; }
|
||||
load_labels
|
||||
|
||||
upsert "type:feat" "#3b82f6" "new feature"
|
||||
upsert "type:fix" "#ef4444" "bug fix"
|
||||
upsert "type:docs" "#10b981" "documentation"
|
||||
upsert "type:chore" "#64748b" "internal chore"
|
||||
|
||||
upsert "area:ui" "#a855f7" "frontend UI"
|
||||
upsert "area:runner" "#f59e0b" "run coordination"
|
||||
upsert "area:infra" "#0ea5e9" "infra and deploy"
|
||||
upsert "area:tooling" "#14b8a6" "dev tooling"
|
||||
|
||||
upsert "prio:high" "#dc2626" "high priority"
|
||||
upsert "prio:med" "#d97706" "medium priority"
|
||||
upsert "prio:low" "#16a34a" "low priority"
|
||||
|
||||
upsert "status:blocked" "#111827" "blocked"
|
||||
upsert "status:ready" "#22c55e" "ready to pick up"
|
||||
upsert "status:in-progress" "#2563eb" "in progress"
|
||||
echo "done."
|
||||