Add security-review gate (review.sh + scanners + CI backstop) #5
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#5
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "security-review-gate"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Phase 2 of the Sea Haven security-review agent: a trigger-agnostic pure-code gate.
/sh-security-review, dedups, applies justification-required suppressions, and makes the block decision (exit 1 on confirmed critical/high).checkov tuned (high-signal exposure checks -> high, best-practice -> low) and npm audit wired for Node deps. Validated against a local vuln testbed (14/14 recall, verifier kills false claims) and a first real run on payments-dashboard (5 confirmed-high findings). Bash-only subdir; no changes to the Python orchestrator.