Commit graph

4 commits

Author SHA1 Message Date
a3ab3f5f40 Make security-review hooks and skill installable from the repo
The global pre-push hook, the /sh-security-review prompt, and finding.schema.json
previously lived only in ~/.config/git and ~/.claude (untracked) — unreproducible.
Source them here: add hooks/pre-push, rewrite install-hooks.sh with a --global mode
(lays down both hooks, sets core.hooksPath, links skill+schema into ~/.claude) and a
per-repo mode. Align pre-commit with pre-push (honor skip marker + suppressions). Add
semgrep p/javascript so the scanners cover the org's Node/.NET repos.
2026-06-16 15:00:00 -04:00
18412c7482 Remove parked security-review CI drafts
CI was swapped for the global git hooks + nightly VM sweep (solo dev), so
the parked ci/*.yml and CI-BACKSTOP-NOTES.md were dead weight — a defective
workflow in-tree is a foot-gun. Recover from history if the team grows.
2026-06-16 14:59:42 -04:00
f90f759e12 Tune checkov severity, wire npm audit, add CI backstop + R720 runbook
checkov: high-signal exposure/access checks -> high, best-practice noise -> low
(was 51 undifferentiated mediums). npm audit wired for Node dep CVEs. Report
collapses the low/info tail to a count. Adds ci/security-review.yml (PR backstop)
and DEPLOY-R720.md (Phase 3 host runbook).
2026-06-15 15:57:34 -04:00
7e5ce1f5b2 Add security-review gate (review.sh + scanners + pre-commit hook)
Trigger-agnostic pure-code gate that merges deterministic-scanner findings
(semgrep/gitleaks/checkov/cfn-lint/pip-audit) with agent findings from
/sh-security-review, dedups, applies justification-required suppressions, and
makes the block decision (exit 1 on confirmed critical/high). Phase 2 of the
Sea Haven security-review agent; Path B (CI/headless) wiring lands in Phase 3.
2026-06-15 15:52:15 -04:00