Skip to main content

Distributable monitoring & security sentinel toolkit — uptime checks plus self-propagating-worm detection, remediation, and prevention.

Project description

StayAwakeBot

StayAwakeBot is a distributable (pip install-able) Python monitoring and security toolkit. Under one stayawake namespace it ships two bots over a shared core:

  • Health sentinel — a URL/uptime availability monitor (HTTP status, latency, TLS, keyword checks) that writes JSON/markdown reports.
  • Security sentinel — a supply-chain worm hunter that detects, alerts on, and auto-fixes self-propagating malware (obfuscated loaders, fake fonts, VS Code auto-run tasks, and stealth "evil merges"), opening remediation PRs and gating CI.

Run either bot as a console script locally, or as GitHub Actions workflows that commit reports back to the repository — the same packaged code in both places.

Architecture

Coming soon

Quick start

Prerequisites: Python 3.11+ — see docs/PREREQUISITES.md.

pip install stayawakebot                                            # from PyPI (released versions)

Or the latest from source:

pip install "stayawakebot @ git+https://github.com/Ndevu12/stayAwakeBot@main"

Health check

stayawake-health-check  --config config/urls.yml      

Uptime check (remote-only bot)

saw scan --config config/security.yml --local                       # worm scan (local security CLI)

The distribution is published as stayawakebot. Local security runs through the terse saw command (see the CLI guide).

Gate any repo's CI (GitHub Action)

Add the security sentinel to any repository in one step — no install, no clone:

# .github/workflows/worm-guard.yml
on: [pull_request, push]
jobs:
  worm-guard:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }   # full history so evil merges are detectable
      - uses: Ndevu12/strix@v1             # pin to a SHA in production
        with:
          fail-on-findings: 'true'

Ndevu12/strix ("StayAwakeBot Strix") is the public Action — a thin wrapper that installs the published stayawakebot scanner from PyPI. Pin @<sha> rather than @v1 for tamper-evident runs. See Security baseline.

Run via Docker (no local Python needed)

Prefer not to install a Python toolchain at all? Pull the image and scan a mounted repo:

docker run --rm -v "$PWD:/repo:ro" ghcr.io/ndevu12/stayawakebot \
  saw scan /repo

The exit code is the verdict (0 clean, 1 findings). To keep the report file too, mount a writable dir and run as your own user so the bind-mount is writable:

docker run --rm --user "$(id -u):$(id -g)" -v "$PWD:/repo" \
  ghcr.io/ndevu12/stayawakebot \
  saw scan /repo --reports-dir /repo/reports

Tags: :latest, :X.Y.Z, :X.Y, and :sha-<commit>. The image runs as a non-root user, is built from the same wheel published to PyPI, and ships SLSA provenance + SBOM attestations.

Note: that provenance attests saw's own build. When saw scans a target it is purely behavioral — it never treats a scanned package's SLSA / PEP-740 / sigstore attestation as a trust signal (Shai-Hulud 2.0 shipped valid provenance). See SECURITY_ARCHITECTURE.md → Provenance is not trust.

Documentation

License

stayAwakeBot is dual-licensed (from v0.1.9 onward):

  • AGPL-3.0-or-later — free and open source. You must preserve attribution, and if you modify it and convey it or offer it over a network (e.g. as a hosted service), you must release your corresponding source under the AGPL too.
  • Commercial license — a paid, proprietary-use option for closed-source or proprietary-SaaS use without the AGPL's source-disclosure obligations. Contact the author for terms.

Releases up to and including v0.1.8 were published under the MIT license and remain MIT for those versions.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

stayawakebot-0.1.9.tar.gz (194.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

stayawakebot-0.1.9-py3-none-any.whl (226.6 kB view details)

Uploaded Python 3

File details

Details for the file stayawakebot-0.1.9.tar.gz.

File metadata

  • Download URL: stayawakebot-0.1.9.tar.gz
  • Upload date:
  • Size: 194.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for stayawakebot-0.1.9.tar.gz
Algorithm Hash digest
SHA256 88ba82a25617f41dcc36b13e396c77c37486d6e76de12f58565dbd52977c6c5e
MD5 15f0908f8f0df3711b6a1ebc9d997201
BLAKE2b-256 3d44ef24cfdb64c60d87d75697ca06689f493e2d3dc0aa1d9aaabc30906ff018

See more details on using hashes here.

Provenance

The following attestation bundles were made for stayawakebot-0.1.9.tar.gz:

Publisher: release.yml on Ndevu12/stayAwakeBot

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file stayawakebot-0.1.9-py3-none-any.whl.

File metadata

  • Download URL: stayawakebot-0.1.9-py3-none-any.whl
  • Upload date:
  • Size: 226.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for stayawakebot-0.1.9-py3-none-any.whl
Algorithm Hash digest
SHA256 3a770f4f9cb43d6fd4528a854b50e529ffbc9665f91ff56ded74c6bac8dc3c02
MD5 31a2322be3913cf0a2f80cea87d782cc
BLAKE2b-256 bc64a39b6c8a5027a05dd3e600ce2185185573e574d43a44f7efa726a2d348bf

See more details on using hashes here.

Provenance

The following attestation bundles were made for stayawakebot-0.1.9-py3-none-any.whl:

Publisher: release.yml on Ndevu12/stayAwakeBot

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page