Skip to content

Latest commit

 

History

856 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

SZL Holdings · Doctrine v11 · Λ = Conjecture 1 (advisory, never "green"/theorem) · canonical a-11-oy.com

🧬 .github

org doctrine

DOI ORCID Doctrine SLSA

Hugging Face · Demo · GitHub Org

receipts.in ≡ receipts.out


szl-holdings/.github

License: Apache 2.0 GHAS Code Security Secret Protection DOI SLSA: enabled ORCID

Org-wide governance, reusable workflows, templates, and security policy for SZL Holdings.


What lives here

Path Purpose
profile/README.md Org profile shown at https://github.com/szl-holdings
.github/ISSUE_TEMPLATE/ Default issue templates cascaded to every repo without its own
.github/PULL_REQUEST_TEMPLATE.md Default PR template
.github/workflows/ 22 reusable workflows — see WORKFLOWS.md
.github/dependabot.yml Weekly dependency updates for this repo
.github/CODEOWNERS Org-default ownership
templates/ Copy-paste templates for product repos (README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY)
security.txt RFC 9116 disclosure record (canonical copy; deploy under /.well-known/security.txt)
SECURITY.md · CONTRIBUTING.md · CODE_OF_CONDUCT.md · SUPPORT.md Org-default community docs
CITATION.cff Citation metadata
assets/social/ 1280×640 social-preview banners ready for upload via Settings → General → Social preview

Reusable workflows

Twenty-two SHA-pinned, harden-runner-protected workflows that every product repo can call:

jobs:
  codeql:
    uses: szl-holdings/.github/.github/workflows/reusable-codeql.yml@<commit-sha>

CI & release

Workflow What it does
reusable-node-ci.yml Node lint + typecheck + test + build matrix
reusable-docs-ci.yml Markdown lint + link-check for docs repos
reusable-release-please.yml Conventional-commits release automation

Security & supply chain

Workflow What it does
reusable-codeql.yml CodeQL static analysis (JS, TS, Python)
reusable-dependency-review.yml Block PRs that introduce vulnerable or non-permissive deps
reusable-trivy.yml Trivy filesystem vulnerability scan
reusable-gitleaks.yml Gitleaks secret scanning on every PR / push
reusable-secret-scan.yml TruffleHog verified committed-secret scan
reusable-sbom.yml CycloneDX + SPDX SBOM per release
reusable-scorecard.yml OpenSSF Scorecard re-run + badge publish
reusable-workflow-lint.yml actionlint + zizmor lint on all workflows
pin-check-reusable.yml Enforce 40-char SHA pinning on third-party Actions

Deploy & drift

Workflow What it does
reusable-hf-deploy.yml GitHub → Hugging Face Space deployer (Dockerfile-derived file set)
reusable-hf-candidate-plan.yml Build an exact, provider-free base-to-head HF deployment plan and revalidate the live PR pair
reusable-hf-module-drift-check.yml Detect drift between a repo's source and its live HF Space
reusable-anatomy-map-drift.yml Guard the shared SZL Anatomy map across its surfaces
reusable-bundle-ref-check.yml Verify UDS bundle repository/ref point at published GHCR tags
reusable-lockfile-registry-check.yml Reject lockfiles pinned to sandbox-internal registries

Doctrine honesty guards

Workflow What it does
reusable-overclaim-guard.yml Doctrine overclaim guard (Λ / Conjecture-1 claims)
reusable-energy-provenance-guard.yml Energy-provenance honesty guard (measured-or-UNAVAILABLE)
reusable-receipt-shape-guard.yml Receipt-shape honesty guard for committed attestation data

All Actions are SHA-pinned and wrapped with step-security/harden-runner using a deny-by-default egress policy. See WORKFLOWS.md for inputs, secrets, and per-workflow examples.

Security posture

  • Private vulnerability reporting: security policy
  • Email: security@szlholdings.com
  • Canonical RFC 9116 record: security.txt
  • Org-wide: branch protection rulesets, exact-head provenance checks, CODEOWNERS, OpenSSF Scorecard
  • This repository's live security status is authoritative only in GitHub's Dependabot, secret-scanning, and CodeQL dashboards; organization-wide alert state is not asserted here, and this README does not freeze alert counts.

Tooling for contributors

  • Conventional Commits (feat:, fix:, chore:, docs:, ci:, refactor:, test:)
  • Squash-merge into main; release automation handled by release-please
  • All PRs run reusable security suite before merge

License

Apache-2.0 for this repo. Product repos under SZL Holdings may use different licenses — see each repo's LICENSE.


© 2026 SZL Holdings — github.com/szl-holdings · ORCID 0009-0001-0110-4173


Founder guides (baby-simple, copy-paste)

Two step-by-step Word guides for getting the SZL ecosystem running from zero — hardware to buy, tools to install, accounts to create, secrets to set, and how to sign, build, deploy and test the UDS bundles.

Guide What it covers File
Environment Setup Guide What to buy (3 hardware options), what to install (with links + one command each), accounts, secret keys, and a 10-step first-time setup docs/SZL_ENVIRONMENT_SETUP_GUIDE.docx
UDS Run Guide Sign the 5 unsigned bundles, build Zarf packages, spin up k3d, deploy, verify, cleanup, the 90-second Warhacker demo script, and the founder action queue docs/SZL_UDS_RUN_GUIDE.docx

Mirrored on Hugging Face: SZLHOLDINGS/doctrine-v11 under founder-guides/.


Related repositories in the SZL substrate

The SZL substrate repos cross-link reciprocally. Two live products (a11oy + killinchu) sit on one signed substrate.

  • a11oy — command platform; signed-receipt substrate with built-in reasoning, policy & operator capabilities (TypeScript packages, MCP server)
  • killinchu — drones & vessels field tool; counter-UAS + maritime picture; DSSE receipt per engagement
  • lutar-lean — Lean 4 + Mathlib proofs of the Λ aggregator (749 decl / 14 axioms / 163 sorries; 8 formulas proven {F1,F4,F7,F11,F12,F18,F19,F22}, Λ = Conjecture 1)
  • szl-papers — DOI-pinned thesis lineage (v1 → v23)
  • ouroboros — bounded-recursion runtime
  • platform — composing monorepo for the substrate runtime
  • uds-mesh — UDS span schemas + governance receipts
  • uds-bundles · szl-mesh — signed, airgap-deployable mesh bundle
  • hatun-mcp — doctrine-aware Model Context Protocol server
  • vsp-otel — OpenTelemetry exporter for Λ-axis spans
  • developers · docs-site · szl-cookbook — build-on-SZL hub, docs & recipes
  • szl-trust — public proof portal · khipu-consensus — BFT witnessing

Org page: github.com/szl-holdings · Doctrine v11 · 14 unique axioms · 749 declarations · 163 sorries · DOI 10.5281/zenodo.20434276

SZL Holdings

SZL Holdings

The SZL Holdings orbit mark (szl-brand kanchay/ 1.1.1, CC BY 4.0).

About

SZL Holdings org profile. Product a-11-oy.com · Proof a11oy.net. Doctrine, reusable workflows, community health.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages