Compare commits

..
Author SHA1 Message Date
github-action[bot]andgithub-action[bot] 7441624e8f Create Flex endpoint 2026-06-04 14:22:27 +00:00
3 changed files with 48 additions and 82 deletions
-78
View File
@@ -1,78 +0,0 @@
{
"manifests": {
"acencyril/sentinelle-bundle": {
"manifest": {
"bundles": {
"Acencyril\\SentinelleBundle\\SentinelleBundle": [
"all"
]
},
"copy-from-recipe": {
"config/": "%CONFIG_DIR%/"
},
"env": {
"#1": "Where security alerts are sent.",
"SENTINELLE_ALERT_EMAIL": "admin@example.com",
"#2": "IPs or CIDRs, comma separated, that must never be blocked.",
"#3": "PUT YOUR OWN OUTBOUND ADDRESS HERE before going live:",
"#4": "without it, an automatic block can lock you out of your own site.",
"SENTINELLE_ALLOWLIST": ""
},
"post-install-output": [
" <bg=blue;fg=white>Sentinelle is installed.</> Three things before going live:",
"",
" * Set <comment>SENTINELLE_ALLOWLIST</comment> in your <comment>.env</comment> \u2014 at minimum your own",
" outbound address. Without it, an automatic block can lock you out of",
" your own site.",
"",
" * Create the schema:",
" <comment>php bin/console doctrine:migrations:diff</comment>",
" <comment>php bin/console doctrine:migrations:migrate</comment>",
"",
" * Check it can do its job:",
" <comment>php bin/console sentinelle:check</comment>",
"",
" Sentinelle starts in <comment>dry-run</comment>: it detects, logs and alerts, but blocks",
" nothing. Watch <comment>/admin/activity</comment> for a few days, then set",
" <comment>sentinelle.dry_run</comment> to <comment>false</comment>.",
"",
" And schedule the purge, without which strike counters never reset:",
" <comment>0 4 * * * php bin/console sentinelle:purge</comment>",
""
]
},
"files": {
"config/packages/sentinelle.yaml": {
"contents": [
"sentinelle:",
" # Dry-run: Sentinelle detects, logs and alerts, but blocks NOTHING.",
" # Nobody wires automatic blocking into a production site without knowing",
" # what it will shut out. Watch the dashboard for a few days, ask yourself",
" # \"would I have wanted to block that one?\", then switch it off.",
" dry_run: true",
" alert:",
" recipient: '%env(SENTINELLE_ALERT_EMAIL)%'",
" access:",
" role: ROLE_ADMIN",
" never_block:",
" # At minimum your own outbound address. Private ranges are protected",
" # by default, but yours is not: one wrong move locks you out.",
" ips: '%env(default::SENTINELLE_ALLOWLIST)%'",
""
],
"executable": false
},
"config/routes/sentinelle.yaml": {
"contents": [
"sentinelle:",
" resource: '@SentinelleBundle/config/routes.php'",
" type: php",
""
],
"executable": false
}
},
"ref": "f8fdd404ae3f91c5c64a07c46a00a032767d006b"
}
}
}
+4 -4
View File
@@ -1,8 +1,8 @@
{
"aliases": [],
"recipes": {
"acencyril/sentinelle-bundle": [
"0.3"
"vinceamstoutz/symfony-security-auditor": [
"1.0"
]
},
"recipe-conflicts": [],
@@ -12,9 +12,9 @@
"_links": {
"repository": "github.com/symfony/recipes-contrib",
"origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main",
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/{package_dotted}.{version}.json",
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-1990/{package_dotted}.{version}.json",
"recipe_template_relative": "{package_dotted}.{version}.json",
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/archived/{package_dotted}/{ref}.json",
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-1990/archived/{package_dotted}/{ref}.json",
"archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json"
}
}
@@ -0,0 +1,44 @@
{
"manifests": {
"vinceamstoutz/symfony-security-auditor": {
"manifest": {
"bundles": {
"VinceAmstoutz\\SymfonySecurityAuditor\\SymfonySecurityAuditorBundle": [
"dev",
"test"
]
},
"copy-from-recipe": {
"config/": "%CONFIG_DIR%/"
}
},
"files": {
"config/packages/symfony_security_auditor.yaml": {
"contents": [
"# Full configuration reference (models, scan, audit loop, rate limits, caching):",
"# https://github.com/vinceamstoutz/symfony-security-auditor/blob/main/docs/configuration.md",
"#",
"when@dev: &symfony_security_auditor",
" symfony_security_auditor:",
" model: 'claude-opus-4-8' # Model for both the Attacker and Reviewer roles. Bundle default: claude-opus-4-7.",
" # attacker_model: 'claude-opus-4-8' # Dedicated model for the Attacker role. Falls back to `model` when unset.",
" # reviewer_model: 'claude-haiku-4-5-20251001' # Lighter model for the Reviewer role. Falls back to `model` when unset.",
"",
" # Proactive rate limiting \u2014 adjust the values to your provider plan.",
" # Any single dimension enables it: https://github.com/vinceamstoutz/symfony-security-auditor/blob/main/docs/configuration.md#auditrate_limit--proactive-throttling",
" # audit:",
" # rate_limit: # Example: Anthropic Tier 1 quotas for Claude Opus 4.x (https://platform.claude.com/docs/en/api/rate-limits)",
" # requests_per_minute: 50",
" # input_tokens_per_minute: 500000 # Cached input tokens don't count toward Anthropic's limit.",
" # output_tokens_per_minute: 80000",
"",
"when@test: *symfony_security_auditor",
""
],
"executable": false
}
},
"ref": "87aec5ddb2d71e0b0571c2197f91ed9b28d51af5"
}
}
}