Finalize security-review: repo-sourced hooks, two-tier nightly auto-discovery #6

Merged
amoussa1229 merged 16 commits from feature/security-review-two-tier-auto-discovery into main 2026-06-17 19:03:16 +00:00
amoussa1229 commented 2026-06-16 19:01:15 +00:00 (Migrated from github.com)

Summary

Finalizes the Sea Haven security-review system (Phase 3) and ships it. Makes all the
git hooks + the agentic skill reproducibly installable from the repo, removes the parked
CI by design (the hooks + nightly VM sweep are the backstop), and rewrites the nightly
sweep so it covers every org repo with zero per-repo wiring.

Validation

  • bash -n clean on all shell (review.sh, install-hooks.sh, hooks/*, nightly_sweep.sh).
  • ruff check + ruff format --check clean on security-review/.
  • Rotation state-machine, empty-repo-list guard, and Slack redaction offline-tested.
  • Orchestrator passes its own gate (review.sh --scanners-only → block=false, the
    .env.example FP suppressed with justification); the pre-push hook fired on this push and PASSED.
  • Live VM dry-run of the clone-mirror path is the remaining validation (needs the read-only
    GH_TOKEN provisioned on sh-secrev).

Tests

No automated tests changed. The change is shell + docs + JSON + the standalone run_headless.py
(no router/graph code). See Notes re: a pre-existing unrelated test failure.

Notes

  • No CI by design — parked ci/*.yml + CI-BACKSTOP-NOTES.md removed; recover from history if multi-dev.
  • Nightly sweep now: REST discovery (curl + read-only GH_TOKEN) → --depth=1 clean mirrors →
    Tier 1 scanners over every repo ($0 Claude) → Tier 2 agentic round-robin within the $20 ceiling.
  • Pre-existing failing test, unrelated to this PR: test_routing_golden.py routes
    "validate email with regex" to fast_coder vs the golden's implementer. Deterministic (3/3),
    in graph.py router logic this PR does not touch. Flagging for a separate fix — not introduced here.
  • Companion changes outside this repo: testbed Node/.NET canary fixtures (local-only repo); the
    mandatory /sh-security-review rule added to global CLAUDE.md; 3 memory entries updated.
## Summary Finalizes the Sea Haven security-review system (Phase 3) and ships it. Makes all the git hooks + the agentic skill reproducibly installable from the repo, removes the parked CI by design (the hooks + nightly VM sweep are the backstop), and rewrites the nightly sweep so it covers every org repo with **zero per-repo wiring**. ## Validation - `bash -n` clean on all shell (review.sh, install-hooks.sh, hooks/*, nightly_sweep.sh). - `ruff check` + `ruff format --check` clean on `security-review/`. - Rotation state-machine, empty-repo-list guard, and Slack redaction offline-tested. - **Orchestrator passes its own gate** (`review.sh --scanners-only` → `block=false`, the `.env.example` FP suppressed with justification); the pre-push hook fired on this push and PASSED. - Live VM dry-run of the clone-mirror path is the remaining validation (needs the read-only `GH_TOKEN` provisioned on sh-secrev). ## Tests No automated tests changed. The change is shell + docs + JSON + the standalone `run_headless.py` (no router/graph code). See Notes re: a pre-existing unrelated test failure. ## Notes - **No CI by design** — parked `ci/*.yml` + `CI-BACKSTOP-NOTES.md` removed; recover from history if multi-dev. - Nightly sweep now: REST discovery (`curl` + read-only `GH_TOKEN`) → `--depth=1` clean mirrors → Tier 1 scanners over every repo (\$0 Claude) → Tier 2 agentic round-robin within the \$20 ceiling. - **Pre-existing failing test, unrelated to this PR:** `test_routing_golden.py` routes "validate email with regex" to `fast_coder` vs the golden's `implementer`. Deterministic (3/3), in `graph.py` router logic this PR does not touch. Flagging for a separate fix — not introduced here. - Companion changes outside this repo: testbed Node/.NET canary fixtures (local-only repo); the mandatory `/sh-security-review` rule added to global CLAUDE.md; 3 memory entries updated.
This repo is archived. You cannot comment on pull requests.
No description provided.