Distributable monitoring & security sentinel toolkit — uptime checks plus self-propagating-worm detection, remediation, and prevention.
Project description
StayAwakeBot
StayAwakeBot is a distributable (pip install-able) Python monitoring and security
toolkit. Under one stayawake namespace it ships two bots over a shared core:
- Health sentinel — a URL/uptime availability monitor (HTTP status, latency, TLS, keyword checks) that writes JSON/markdown reports.
- Security sentinel — a supply-chain worm hunter that detects, alerts on, and auto-fixes self-propagating malware (obfuscated loaders, fake fonts, VS Code auto-run tasks, and stealth "evil merges"), opening remediation PRs and gating CI.
Run either bot as a console script locally, or as GitHub Actions workflows that commit reports back to the repository — the same packaged code in both places.
Architecture
Coming soon
Quick start
Prerequisites: Python 3.11+ — see docs/PREREQUISITES.md.
pip install stayawakebot # from PyPI (released versions)
Or the latest from source:
pip install "stayawakebot @ git+https://github.com/Ndevu12/stayAwakeBot@main"
Health check
stayawake-health-check --config config/urls.yml
Uptime check (remote-only bot)
saw scan --config config/security.yml --local # worm scan (local security CLI)
The distribution is published as
stayawakebot. Local security runs through the tersesawcommand (see the CLI guide).
Gate any repo's CI (GitHub Action)
Add the security sentinel to any repository in one step — no install, no clone:
# .github/workflows/worm-guard.yml
on: [pull_request, push]
jobs:
worm-guard:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with: { fetch-depth: 0 } # full history so evil merges are detectable
- uses: Ndevu12/strix@v1 # pin to a SHA in production
with:
fail-on-findings: 'true'
Ndevu12/strix ("StayAwakeBot Strix") is the public Action — a thin wrapper that installs the
published stayawakebot scanner from PyPI. Pin @<sha> rather than @v1 for tamper-evident
runs. See Security baseline.
Run via Docker (no local Python needed)
Prefer not to install a Python toolchain at all? Pull the image and scan a mounted repo:
docker run --rm -v "$PWD:/repo:ro" ghcr.io/ndevu12/stayawakebot \
saw scan /repo
The exit code is the verdict (0 clean, 1 findings). To keep the report file too, mount a
writable dir and run as your own user so the bind-mount is writable:
docker run --rm --user "$(id -u):$(id -g)" -v "$PWD:/repo" \
ghcr.io/ndevu12/stayawakebot \
saw scan /repo --reports-dir /repo/reports
Tags: :latest, :X.Y.Z, :X.Y, and :sha-<commit>. The image runs as a non-root user, is
built from the same wheel published to PyPI, and ships SLSA provenance + SBOM attestations.
Note: that provenance attests
saw's own build. Whensawscans a target it is purely behavioral — it never treats a scanned package's SLSA / PEP-740 / sigstore attestation as a trust signal (Shai-Hulud 2.0 shipped valid provenance). See SECURITY_ARCHITECTURE.md → Provenance is not trust.
Documentation
- CLI command guide — the
sawsecurity commands (scan, run, fix, audit, …) - Usage — install, run both bots, secrets, GitHub Actions, deploy your own
- Configuration & Reports — config file fields and report formats
- Architecture — package layout and design principles
- Security architecture — detection, remediation, prevention
- Security baseline — hardening checklist for any repo
- Releasing — maintainer runbook: tags, PyPI Trusted Publishing, verification
- Contributing — development setup and guidelines
License
stayAwakeBot is dual-licensed (from v0.1.9 onward):
- AGPL-3.0-or-later — free and open source. You must preserve attribution, and if you modify it and convey it or offer it over a network (e.g. as a hosted service), you must release your corresponding source under the AGPL too.
- Commercial license — a paid, proprietary-use option for closed-source or proprietary-SaaS use without the AGPL's source-disclosure obligations. Contact the author for terms.
Releases up to and including v0.1.8 were published under the MIT license and remain MIT for those versions.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file stayawakebot-0.1.11.tar.gz.
File metadata
- Download URL: stayawakebot-0.1.11.tar.gz
- Upload date:
- Size: 202.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
dfda5223851754c3429de94bc77ce21dcc01c0f23067fdbd0c2e9e498dc9df50
|
|
| MD5 |
bebc359904cf822f697a46da2aecbc19
|
|
| BLAKE2b-256 |
63a73f44f26b79265d870123c2019362fa5bba638cffe6074059571fd208a05c
|
Provenance
The following attestation bundles were made for stayawakebot-0.1.11.tar.gz:
Publisher:
release.yml on Ndevu12/stayAwakeBot
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
stayawakebot-0.1.11.tar.gz -
Subject digest:
dfda5223851754c3429de94bc77ce21dcc01c0f23067fdbd0c2e9e498dc9df50 - Sigstore transparency entry: 2149932478
- Sigstore integration time:
-
Permalink:
Ndevu12/stayAwakeBot@17b7c32bbeda53287ebf67dce4fb3bb0a91c5187 -
Branch / Tag:
refs/tags/v0.1.11 - Owner: https://github.com/Ndevu12
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@17b7c32bbeda53287ebf67dce4fb3bb0a91c5187 -
Trigger Event:
push
-
Statement type:
File details
Details for the file stayawakebot-0.1.11-py3-none-any.whl.
File metadata
- Download URL: stayawakebot-0.1.11-py3-none-any.whl
- Upload date:
- Size: 235.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b3dc8e3f804d2ae91a812a271561f16e6b7f1d2f48ed3551f166044876b993e1
|
|
| MD5 |
e90bf6051ba5b1e6450cdde72b099a0b
|
|
| BLAKE2b-256 |
f0d3bbca328f8c595439c1c12e0dcf0e45d693bc60d5f21fcbd397bf6c9163c5
|
Provenance
The following attestation bundles were made for stayawakebot-0.1.11-py3-none-any.whl:
Publisher:
release.yml on Ndevu12/stayAwakeBot
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
stayawakebot-0.1.11-py3-none-any.whl -
Subject digest:
b3dc8e3f804d2ae91a812a271561f16e6b7f1d2f48ed3551f166044876b993e1 - Sigstore transparency entry: 2149932707
- Sigstore integration time:
-
Permalink:
Ndevu12/stayAwakeBot@17b7c32bbeda53287ebf67dce4fb3bb0a91c5187 -
Branch / Tag:
refs/tags/v0.1.11 - Owner: https://github.com/Ndevu12
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@17b7c32bbeda53287ebf67dce4fb3bb0a91c5187 -
Trigger Event:
push
-
Statement type: