* fix(agent-team): read SLACK_CHANNEL_ID, aligning code with deploy doc + systemd run-team.py read os.environ['SLACK_CHANNEL'] while DEPLOY-R720.md and the coordinator systemd unit both document SLACK_CHANNEL_ID; the mismatch would silently default the live Slack transport channel to empty. Standardize on SLACK_CHANNEL_ID (decision locked 2026-06-18). * feat(secrev): dependency-cve Plane-1 Tier-1 checker (OSV, ALARM-only) Read-only checker on the Phase-0 substrate: scans $MIRROR_DIR mirrors for pinned deps (requirements/poetry/Pipfile/package-lock/yarn/csproj across PyPI/npm/NuGet), cross-refs OSV querybatch (live) or an offline advisory fixture (canary). Mode-600 reports, ALARM-only, --canary asserts 2 planted vulns (jinja2 2.11.2, lodash 4.17.15). Complements Dependabot. Not provisioned. * feat(secrev): Plane-1 checker coordinator (shared budget, rotation, dedup) Coordinator (design §5/§6.7) orchestrating Tier-1 checkers under one shared budget ledger + versioned rotation/coverage state (atomic write + schema/hash/ logical-consistency integrity, park-on-corrupt). Canary-suite-first (COMPLACENCY skip), fan-out under the shared cap with defer-not-drop, COVERAGE alarm past MAX_CYCLE_NIGHTS, cross-checker dedup/prioritize, ALARM-only routing. --squeeze-dry-run proves deferral-not-drop + COVERAGE alarm. Not provisioned. * fix(secrev): hide dependency-cve canary manifests from dependency-review The canary fixtures intentionally pin known-vulnerable deps (jinja2 2.11.2, lodash 4.17.15) so the checker has something to detect. GitHub's dependency graph parsed those fixture manifests as real project deps, failing the dependency-review PR gate (fail-on-severity: high). Store the manifests with a .fixture suffix so the dependency graph ignores them; the --canary materializer strips the suffix in its temp work area before scanning, so detection is unchanged (still 2/2). No advisory allowlist, no change to the shared org reusable workflow — the real gate stays strict for actual deps.
23 lines
1.1 KiB
JSON
23 lines
1.1 KiB
JSON
{
|
|
"_comment": "Offline advisory fixture for dependency-cve.sh --canary (and --advisories-file). This stands in for the live OSV querybatch API so the canary is fully offline + deterministic. Each entry is keyed by 'ECOSYSTEM|package|version' (ECOSYSTEM matches OSV ecosystem names: PyPI, npm, NuGet) and carries the fields the checker emits in a finding's proof. These mirror REAL advisories (GHSA/CVE ids + summaries + fixed versions) so the fixture is realistic, but the checker NEVER reaches the network in canary mode — it reads only this file.",
|
|
"advisories": {
|
|
"PyPI|jinja2|2.11.2": [
|
|
{
|
|
"id": "GHSA-g3rq-g295-4j3m",
|
|
"summary": "Jinja2 ReDoS in the urlize filter via the urlize regex",
|
|
"severity": "high",
|
|
"cvss": 7.5,
|
|
"fixed_version": "2.11.3"
|
|
}
|
|
],
|
|
"npm|lodash|4.17.15": [
|
|
{
|
|
"id": "GHSA-p6mc-m468-83gw",
|
|
"summary": "Prototype pollution in lodash (zipObjectDeep / set / setWith)",
|
|
"severity": "high",
|
|
"cvss": 7.4,
|
|
"fixed_version": "4.17.19"
|
|
}
|
|
]
|
|
}
|
|
}
|