From a282c79d32a072b7782297733ec24e3fb9a0a8ff Mon Sep 17 00:00:00 2001 From: hexdev Date: Sun, 12 Jul 2026 00:37:38 +0700 Subject: [PATCH] chore: edited config.yaml for universal use cases, +readme.md --- README.md | 31 +++++++++++++++++++++++++++++ config.yaml | 26 +++++++----------------- core/base.py | 2 +- modules/systemd/systemd_security.py | 4 +--- 4 files changed, 40 insertions(+), 23 deletions(-) diff --git a/README.md b/README.md index e69de29..d66ddc2 100644 --- a/README.md +++ b/README.md @@ -0,0 +1,31 @@ +# Hydrogen +**Lightweight, extensible server security auditing — from a single YAML file.** + +Hydrogen runs your security checks concurrently, evaluates severity, and delivers reports wherever you need them — disk, webhook, or your own custom transport. Focused on extensibility, built for your server. + +### Why Hydrogen? +- **Extensible by design** — modules, renderers, and transports are all plugins. Write a Python class, drop it in, it works. +- **Concurrent by default** — checks run in parallel with configurable concurrency. +- **Multiple outputs** — JSON to disk _and_ a webhook to your SIEM? One config line each. +- **CI-native** — `strict_mode` + severity thresholds produce a clean exit code for your pipeline. + +### Quick start +```sh +git clone https://github.com/agonyecho/hydrogen && cd hydrogen +pip install -e . # Installs hydrogen as local package +hydrogen -c config.yaml +``` + +or + +```sh +git clone https://github.com/agonyecho/hydrogen && cd hydrogen +python -m venv venv && source ./venv/bin/activate && pip install -r requirements.txt +python main.py -c config.yaml +``` + +### Docs +- [Configuration](HYDROGEN_CONFIGURATION.md) — every YAML knob explained +- [Writing modules](HYDROGEN_SECURITY_MODULES.md) — `MANIFEST`, `build_worker`, `CONFIG_MODEL` +- [Writing transports](HYDROGEN_TRANSPORTS.md) — deliver reports anywhere +- [Writing renderers](HYDROGEN_RENDERERS.md) — JSON, Markdown, or your own format diff --git a/config.yaml b/config.yaml index 0555d15..aa5b0de 100644 --- a/config.yaml +++ b/config.yaml @@ -1,4 +1,3 @@ -## Script Behavior exclude_categories: [] fail_fast: false dry_run: false @@ -8,30 +7,19 @@ logging: level: INFO output: stdout -plugin_packages: - renderers: - - reporting.exporters - transports: - - reporting.transports - modules: [] +strict_mode: false +allow_failures_below: critical -## Compliance -strict_mode: true # True - exits with code 1, triggering the CI response, False - exits with code: 0. -allow_failures_below: medium - -## Reports reports: outputs: - renderer: type: json transport: - type: webhook - url: http://localhost:5000/webhook - method: POST - payload_mode: rendered + type: file + path: reports/latest + append_extension: true -## Module Specific Configuration -modules: +modules: ssh: enabled: true - test-failure: true + test-failure: false diff --git a/core/base.py b/core/base.py index 1c718c3..465e999 100644 --- a/core/base.py +++ b/core/base.py @@ -59,7 +59,7 @@ class BaseTransport(ABC): class TypedTransport(BaseTransport, Generic[TReportTransport], ABC): - config_model: type[TReportTransport] # type: ignore + config_model: type[TReportTransport] # type: ignore def publish(self, rendered_report: RenderedReport, transport: ResolvedPluginConfig) -> str: if not isinstance(transport.config, self.config_model): diff --git a/modules/systemd/systemd_security.py b/modules/systemd/systemd_security.py index a4efc2b..74cd425 100644 --- a/modules/systemd/systemd_security.py +++ b/modules/systemd/systemd_security.py @@ -142,9 +142,7 @@ class SystemdWorker(BaseWorker): return findings - def _check_unit_permissions( - self, unit: Path, findings: list[AuditFindings] - ) -> None: + def _check_unit_permissions(self, unit: Path, findings: list[AuditFindings]) -> None: stat = unit.stat() if stat.st_uid != 0: findings.append(