This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/checkers
Adam Moussa 0898fb50a9 feat(secrev): dependency-cve Plane-1 Tier-1 checker (OSV, ALARM-only)
Read-only checker on the Phase-0 substrate: scans $MIRROR_DIR mirrors for
pinned deps (requirements/poetry/Pipfile/package-lock/yarn/csproj across
PyPI/npm/NuGet), cross-refs OSV querybatch (live) or an offline advisory
fixture (canary). Mode-600 reports, ALARM-only, --canary asserts 2 planted
vulns (jinja2 2.11.2, lodash 4.17.15). Complements Dependabot. Not provisioned.
2026-06-18 14:57:07 -04:00
..
fixtures feat(secrev): dependency-cve Plane-1 Tier-1 checker (OSV, ALARM-only) 2026-06-18 14:57:07 -04:00
compliance-drift.sh feat(secrev): compliance-drift Plane-1 Tier-1 checker (ALARM-only) 2026-06-18 14:06:31 -04:00
dependency-cve.sh feat(secrev): dependency-cve Plane-1 Tier-1 checker (OSV, ALARM-only) 2026-06-18 14:57:07 -04:00