feat(secrev): Plane-1 Phase 2 — coordinator + dependency-cve checker #16

Merged
amoussa1229 merged 4 commits from feature/agent-team-plane1-phase2 into main 2026-06-18 19:08:59 +00:00
amoussa1229 commented 2026-06-18 19:03:28 +00:00 (Migrated from github.com)

Plane-1 Phase 2 (design §5/§7) — coordinator + second checker

Builds on the Phase-0 substrate (lib/sweep_substrate.sh) and Phase-1 compliance-drift. Per handoff §B, Phase 2's gate is none (read-only checkers); validated by shellcheck -x + offline --canary/--squeeze-dry-run smoke. Nothing provisioned.

What's in here

  • security-review/checkers/dependency-cve.sh — read-only Tier-1 checker. Scans $MIRROR_DIR mirrors for pinned deps (requirements/poetry/Pipfile/package-lock/yarn/csproj → PyPI/npm/NuGet), cross-refs OSV querybatch (live, no token) or an offline advisory fixture (canary). Mode-600 reports, ALARM-only, fail-safe on missing network/data. Complements Dependabot. Mirrors compliance-drift.sh conventions exactly.
  • security-review/checker_coordinator.sh — the Plane-1 coordinator (design §5). Orchestrates Tier-1 checkers under one shared budget ledger + versioned rotation/coverage state (atomic write-temp-then-rename + schema/content-hash/logical-consistency integrity check, park-on-corrupt, §6.7). Canary-suite-first (COMPLACENCY skip), fan-out under the shared cap with defer-not-drop, COVERAGE alarm past MAX_CYCLE_NIGHTS, cross-checker dedup/prioritize, ALARM-only routing (clean night = silent).
  • fixtures/dependency-cve/ — planted canary (jinja2 2.11.2 + lodash 4.17.15 = 2 vulns) + offline OSV advisory fixture + clean repo.
  • fix(agent-team) — run-team.py now reads SLACK_CHANNEL_ID (was SLACK_CHANNEL), aligning code with the deploy doc + systemd unit (decision locked 2026-06-18; the mismatch would silently empty the live Slack channel).

Acceptance (verified locally)

  • dependency-cve.sh --canary → 2/2 planted vulns, exit 0
  • checker_coordinator.sh --canary → both roles green, exit 0
  • checker_coordinator.sh --squeeze-dry-run → DEFER dependency-cve (not dropped) + COVERAGE ALARM, exit 0 (the Phase-2 acceptance proof)
  • compliance-drift.sh --canary → 6/6, no regression
  • shellcheck -x clean; ruff clean; 47 run-team tests pass

Not in scope (gated/later)

No systemd wiring, no live org dry-run, no provisioning — all deploy-gated. The forced budget-squeeze uses fixtures so the proof is self-contained on a box without $MIRROR_DIR.

## Plane-1 Phase 2 (design §5/§7) — coordinator + second checker Builds on the Phase-0 substrate (`lib/sweep_substrate.sh`) and Phase-1 `compliance-drift`. Per handoff §B, Phase 2's gate is **none** (read-only checkers); validated by `shellcheck -x` + offline `--canary`/`--squeeze-dry-run` smoke. Nothing provisioned. ### What's in here - **`security-review/checkers/dependency-cve.sh`** — read-only Tier-1 checker. Scans `$MIRROR_DIR` mirrors for pinned deps (requirements/poetry/Pipfile/package-lock/yarn/csproj → PyPI/npm/NuGet), cross-refs OSV `querybatch` (live, no token) or an offline advisory fixture (canary). Mode-600 reports, ALARM-only, fail-safe on missing network/data. Complements Dependabot. Mirrors `compliance-drift.sh` conventions exactly. - **`security-review/checker_coordinator.sh`** — the Plane-1 coordinator (design §5). Orchestrates Tier-1 checkers under **one shared budget ledger** + **versioned rotation/coverage state** (atomic write-temp-then-rename + schema/content-hash/logical-consistency integrity check, park-on-corrupt, §6.7). Canary-suite-first (COMPLACENCY skip), fan-out under the shared cap with **defer-not-drop**, **COVERAGE alarm** past `MAX_CYCLE_NIGHTS`, cross-checker dedup/prioritize, ALARM-only routing (clean night = silent). - **`fixtures/dependency-cve/`** — planted canary (jinja2 2.11.2 + lodash 4.17.15 = 2 vulns) + offline OSV advisory fixture + clean repo. - **`fix(agent-team)`** — `run-team.py` now reads `SLACK_CHANNEL_ID` (was `SLACK_CHANNEL`), aligning code with the deploy doc + systemd unit (decision locked 2026-06-18; the mismatch would silently empty the live Slack channel). ### Acceptance (verified locally) - `dependency-cve.sh --canary` → 2/2 planted vulns, exit 0 - `checker_coordinator.sh --canary` → both roles green, exit 0 - `checker_coordinator.sh --squeeze-dry-run` → **DEFER dependency-cve (not dropped) + COVERAGE ALARM**, exit 0 (the Phase-2 acceptance proof) - `compliance-drift.sh --canary` → 6/6, no regression - `shellcheck -x` clean; ruff clean; 47 run-team tests pass ### Not in scope (gated/later) No systemd wiring, no live org dry-run, no provisioning — all deploy-gated. The forced budget-squeeze uses fixtures so the proof is self-contained on a box without `$MIRROR_DIR`.
This repo is archived. You cannot comment on pull requests.
No description provided.