cleanup(agent-team): clear 3 SAST mediums + refresh README to built state #15

Merged
amoussa1229 merged 2 commits from feature/agent-team-medium-cleanup into main 2026-06-18 18:21:44 +00:00
amoussa1229 commented 2026-06-18 18:16:57 +00:00 (Migrated from github.com)

Quick cleanup to get main clean of the non-blocking SAST mediums surfaced during the Plane-1 push.

  • clarifier_llm.py — sha1 → sha256 for the per-turn cache discriminator (CWE-327 false positive; the hash is a non-security cache key, but a modern digest silences the scanner with no downside).
  • github_adapter.py / github_intake.py — inline # nosemgrep on the two urlopen lines (dynamic-urllib-use-detected, CWE-939). The URL is built from a fixed https GitHub API base; the dynamic part is the path/query only, never the scheme, so there is no SSRF/file:// surface. Extends the existing # noqa: S310 (trusted api host) judgment to semgrep.

Verified: review.sh --scanners-only --scope agent-team now reports 0 mediums / semgrep 0 findings / RESULT PASS; 795 tests pass; ruff clean.

Quick cleanup to get `main` clean of the non-blocking SAST mediums surfaced during the Plane-1 push. - **`clarifier_llm.py`** — sha1 → **sha256** for the per-turn cache discriminator (CWE-327 false positive; the hash is a non-security cache key, but a modern digest silences the scanner with no downside). - **`github_adapter.py` / `github_intake.py`** — inline `# nosemgrep` on the two `urlopen` lines (`dynamic-urllib-use-detected`, CWE-939). The URL is built from a **fixed https GitHub API base**; the dynamic part is the path/query only, never the scheme, so there is no SSRF/`file://` surface. Extends the existing `# noqa: S310 (trusted api host)` judgment to semgrep. Verified: `review.sh --scanners-only --scope agent-team` now reports **0 mediums / semgrep 0 findings / RESULT PASS**; 795 tests pass; ruff clean.
amoussa1229 commented 2026-06-18 18:19:32 +00:00 (Migrated from github.com)

Also folds in a README refresh: agent-team/README.md was stale ('FOUNDATION modules only'); updated to the current built state (P1-P4, pipeline diagram, layout, deploy-gated items).

Also folds in a README refresh: `agent-team/README.md` was stale ('FOUNDATION modules only'); updated to the current built state (P1-P4, pipeline diagram, layout, deploy-gated items).
This repo is archived. You cannot comment on pull requests.
No description provided.