cleanup(agent-team): clear 3 SAST mediums + refresh README to built state #15
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#15
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-medium-cleanup"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Quick cleanup to get
mainclean of the non-blocking SAST mediums surfaced during the Plane-1 push.clarifier_llm.py— sha1 → sha256 for the per-turn cache discriminator (CWE-327 false positive; the hash is a non-security cache key, but a modern digest silences the scanner with no downside).github_adapter.py/github_intake.py— inline# nosemgrepon the twourlopenlines (dynamic-urllib-use-detected, CWE-939). The URL is built from a fixed https GitHub API base; the dynamic part is the path/query only, never the scheme, so there is no SSRF/file://surface. Extends the existing# noqa: S310 (trusted api host)judgment to semgrep.Verified:
review.sh --scanners-only --scope agent-teamnow reports 0 mediums / semgrep 0 findings / RESULT PASS; 795 tests pass; ruff clean.Also folds in a README refresh:
agent-team/README.mdwas stale ('FOUNDATION modules only'); updated to the current built state (P1-P4, pipeline diagram, layout, deploy-gated items).