This checklist must be completed before any production deployment or tagged release. All items must reach a documented state (PASS, SKIP with justification, or OPERATOR ACTION REQUIRED).
Install these tools before running make verify-release:
go install golang.org/x/vuln/cmd/govulncheck@latest
go install github.com/zricethezav/gitleaks/v8@latest
# trufflehog: https://github.com/trufflesecurity/trufflehog#installation| Step | Command | Expected result |
|---|---|---|
| 1 | gofmt -l . |
No output (all files formatted) |
| 2 | go vet ./... |
No output (no issues) |
| 3 | go test -timeout 120s ./... |
All tests pass |
| 4 | go test -race -timeout 300s ./... |
All tests pass, no races |
| 5 | go build (all 6 binaries) |
Binaries built to bin/ |
| 6 | govulncheck ./... |
No vulnerabilities |
| 7a | gitleaks detect --config .gitleaks.toml |
No new findings (pre-existing AbuseIPDB entry is allowlisted — see below) |
| 7b | trufflehog git file://. --only-verified |
Pre-existing AbuseIPDB finding — see below |
THIS IS A KNOWN OPEN FINDING. It is NOT suppressed silently.
trufflehog git file://. --only-verified reports a verified AbuseIPDB API key in git history (2 findings, same key):
| # | Commit | File | Note |
|---|---|---|---|
| 1 | 4649a1d |
CUTOVER_RUNBOOK.md:151 |
Original introduction |
| 2 | 2aa3646 |
V1_5_RELEASE_VALIDATION_PIPELINE_REPORT.md |
Prior version of report embedded the raw key value; current version redacted |
Also present in b4a5b17 via the same git blob object.
- Git object:
.git/objects/20/21b218e13e9f1dfa502035a81893ac4b35c280 - trufflehog verdict:
--only-verifiedconfirmed the key responded to a live API check - Sprint introduced: Commit
4649a1dpre-dates V1.4 and V1.5; commit2aa3646was V1.5 report documentation
| Action | Status | Reason |
|---|---|---|
| Automatic key rotation | NOT performed | Standing constraint: "Do not rotate secrets automatically" |
git filter-repo history scrub |
NOT performed | Standing constraint: "Do not rewrite git history unless explicitly requested" |
Silent suppression (.gitleaksignore) |
NOT done | Mission requirement: "Do not silently ignore detected secrets" |
- The raw key value has been redacted from
V1_5_RELEASE_VALIDATION_PIPELINE_REPORT.mdHEAD - All affected commits are explicitly allowlisted in
.gitleaks.tomlwith a full decision record comment (commitsb4a5b17,4649a1d,2aa3646) - The finding is explicitly documented in this checklist
- Rotate the AbuseIPDB API key — DONE. Old key revoked at abuseipdb.com.
New key written to
/etc/security-automation/secrets/abuseipdb_api_key(format:ABUSEIPDB_KEY=<value>,root:root 0600). Note: This is the legacy path. Operator must migrate to canonical path/etc/security-automation-go/secrets/abuseipdb_api_key— see secret path migration in operator runbook. trufflehog--only-verifiednow returnsverified_secrets: 0. - Consider
git filter-repohistory scrub — removes the inactive key from git history. Separate operator decision; not blocking since the key is revoked.
GO — key rotated, trufflehog clean, all pipeline gates pass.
make verify-release exits 0 as of commit fdce6c4.
make build-linux-amd64 # produces bin/linux-amd64/
make build-linux-arm64 # produces bin/linux-arm64/All 6 binaries use modernc.org/sqlite (pure Go) — CGO_ENABLED=0 works on both
architectures without a cross-compiler.
| Binary | amd64 | arm64 |
|---|---|---|
crowdsec-sync |
✓ | ✓ |
cf-allowlist-sync |
✓ | ✓ |
cf-cleanup |
✓ | ✓ |
cf-sync |
✓ | ✓ |
cf-shadow |
✓ | ✓ |
security-automation-mcp |
✓ | ✓ |
make package VERSION=1.5.0- Output:
dist/security-automation-go_1.5.0_amd64.deb - .deb contents: all 6 binaries, 5 systemd units + timer, sysusers.d, tmpfiles.d
- RPM: skipped if
rpmbuildis not installed (installrpm-buildpackage on Fedora/RHEL/SUSE)
After building the .deb:
dpkg-deb --info dist/security-automation-go_1.5.0_amd64.deb
dpkg-deb --contents dist/security-automation-go_1.5.0_amd64.debgovulncheck ./...Current status: PASS — 0 vulnerabilities (exit 0). As of 2026-06-07.
All findings cleared:
- 28 stdlib findings cleared by
toolchain go1.25.11ingo.mod(commit 0430751) - 3 third-party findings cleared by dep updates (commit fdce6c4):
- GO-2026-4985:
otlptracehttp→ v1.43.0 - GO-2026-4394:
otel/sdk→ v1.43.0 - GO-2024-3141:
opa→ v0.68.0
- GO-2026-4985:
make verify-release step 6 exits 0 with no warnings.
CI (build-and-test) govulncheck step has continue-on-error: true retained for defence-in-depth.
Per standing constraints, the following are manual operator steps:
-
systemctl daemon-reload -
systemctl restart cf-sync - Verify
/ui/dashboardloads - Confirm health page at
/healthis GREEN - Rotate AbuseIPDB key — DONE 2026-06-07
| Gate | Status | Notes |
|---|---|---|
| gofmt | PASS | All files formatted |
| go vet | PASS | No issues |
| go test | PASS | All tests pass |
| go test -race | PASS | No data races |
| go build (all 6 binaries) | PASS | amd64 + arm64 |
| govulncheck | PASS — 0 findings | OTEL v1.43.0, OPA v0.68.0, toolchain go1.25.11 |
| gitleaks | PASS | 108 commits, no leaks |
| trufflehog | PASS — 0 verified | Old key revoked 2026-06-07; inactive hash in history is not a finding |
| .deb package | PASS | dist/security-automation-go_1.5.0_amd64.deb |
| RPM package | SKIP | rpmbuild not available on Debian/Ubuntu hosts |
| Key rotation | DONE | New key at /etc/security-automation/secrets/abuseipdb_api_key (legacy path — operator migration to /etc/security-automation-go/secrets/abuseipdb_api_key required) |
Overall: GO — V1.5 release gate fully cleared. make verify-release exits 0.