feat(secrev): Plane-1 Phase 2 — coordinator + dependency-cve checker #16
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#16
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-plane1-phase2"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Plane-1 Phase 2 (design §5/§7) — coordinator + second checker
Builds on the Phase-0 substrate (
lib/sweep_substrate.sh) and Phase-1compliance-drift. Per handoff §B, Phase 2's gate is none (read-only checkers); validated byshellcheck -x+ offline--canary/--squeeze-dry-runsmoke. Nothing provisioned.What's in here
security-review/checkers/dependency-cve.sh— read-only Tier-1 checker. Scans$MIRROR_DIRmirrors for pinned deps (requirements/poetry/Pipfile/package-lock/yarn/csproj → PyPI/npm/NuGet), cross-refs OSVquerybatch(live, no token) or an offline advisory fixture (canary). Mode-600 reports, ALARM-only, fail-safe on missing network/data. Complements Dependabot. Mirrorscompliance-drift.shconventions exactly.security-review/checker_coordinator.sh— the Plane-1 coordinator (design §5). Orchestrates Tier-1 checkers under one shared budget ledger + versioned rotation/coverage state (atomic write-temp-then-rename + schema/content-hash/logical-consistency integrity check, park-on-corrupt, §6.7). Canary-suite-first (COMPLACENCY skip), fan-out under the shared cap with defer-not-drop, COVERAGE alarm pastMAX_CYCLE_NIGHTS, cross-checker dedup/prioritize, ALARM-only routing (clean night = silent).fixtures/dependency-cve/— planted canary (jinja2 2.11.2 + lodash 4.17.15 = 2 vulns) + offline OSV advisory fixture + clean repo.fix(agent-team)—run-team.pynow readsSLACK_CHANNEL_ID(wasSLACK_CHANNEL), aligning code with the deploy doc + systemd unit (decision locked 2026-06-18; the mismatch would silently empty the live Slack channel).Acceptance (verified locally)
dependency-cve.sh --canary→ 2/2 planted vulns, exit 0checker_coordinator.sh --canary→ both roles green, exit 0checker_coordinator.sh --squeeze-dry-run→ DEFER dependency-cve (not dropped) + COVERAGE ALARM, exit 0 (the Phase-2 acceptance proof)compliance-drift.sh --canary→ 6/6, no regressionshellcheck -xclean; ruff clean; 47 run-team tests passNot in scope (gated/later)
No systemd wiring, no live org dry-run, no provisioning — all deploy-gated. The forced budget-squeeze uses fixtures so the proof is self-contained on a box without
$MIRROR_DIR.