Add security-review gate (review.sh + scanners + CI backstop) #5

Merged
amoussa1229 merged 2 commits from security-review-gate into main 2026-06-15 19:59:00 +00:00
amoussa1229 commented 2026-06-15 19:57:48 +00:00 (Migrated from github.com)

Phase 2 of the Sea Haven security-review agent: a trigger-agnostic pure-code gate.

  • review.sh merges deterministic scanner findings (semgrep/gitleaks/checkov/cfn-lint/pip-audit/npm-audit) with agent findings from /sh-security-review, dedups, applies justification-required suppressions, and makes the block decision (exit 1 on confirmed critical/high).
  • pre-commit hook + installer (fast scanners-only local feedback).
  • ci/security-review.yml — unbypassable PR backstop running the same review.sh.
  • DEPLOY-R720.md — Phase 3 host runbook (not yet deployed).

checkov tuned (high-signal exposure checks -> high, best-practice -> low) and npm audit wired for Node deps. Validated against a local vuln testbed (14/14 recall, verifier kills false claims) and a first real run on payments-dashboard (5 confirmed-high findings). Bash-only subdir; no changes to the Python orchestrator.

Phase 2 of the Sea Haven security-review agent: a trigger-agnostic pure-code gate. - **review.sh** merges deterministic scanner findings (semgrep/gitleaks/checkov/cfn-lint/pip-audit/npm-audit) with agent findings from `/sh-security-review`, dedups, applies justification-required suppressions, and makes the block decision (exit 1 on confirmed critical/high). - **pre-commit hook** + installer (fast scanners-only local feedback). - **ci/security-review.yml** — unbypassable PR backstop running the same review.sh. - **DEPLOY-R720.md** — Phase 3 host runbook (not yet deployed). checkov tuned (high-signal exposure checks -> high, best-practice -> low) and npm audit wired for Node deps. Validated against a local vuln testbed (14/14 recall, verifier kills false claims) and a first real run on payments-dashboard (5 confirmed-high findings). Bash-only subdir; no changes to the Python orchestrator.
This repo is archived. You cannot comment on pull requests.
No description provided.