This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/checkers/fixtures
Adam Moussa 8e0e17d217 fix(secrev): hide dependency-cve canary manifests from dependency-review
The canary fixtures intentionally pin known-vulnerable deps (jinja2 2.11.2,
lodash 4.17.15) so the checker has something to detect. GitHub's dependency
graph parsed those fixture manifests as real project deps, failing the
dependency-review PR gate (fail-on-severity: high). Store the manifests with a
.fixture suffix so the dependency graph ignores them; the --canary materializer
strips the suffix in its temp work area before scanning, so detection is
unchanged (still 2/2). No advisory allowlist, no change to the shared org
reusable workflow — the real gate stays strict for actual deps.
2026-06-18 15:07:15 -04:00
..
compliance-drift feat(secrev): compliance-drift Plane-1 Tier-1 checker (ALARM-only) 2026-06-18 14:06:31 -04:00
dependency-cve fix(secrev): hide dependency-cve canary manifests from dependency-review 2026-06-18 15:07:15 -04:00