security-review/requirements.txt

7 lines
281 B
Text
Raw Normal View History

feat: re-home cross-family reviewer CLI, retire Path B host artifacts (#5) * feat: add router-less cross-family reviewer CLI (cross_review.py) Re-homes the archived orchestrator repo's GPT-4.1 cross_reviewer as a direct OpenAI SDK CLI: verbatim system prompt, same model id, ported 3-attempt exponential-backoff retry. Reads OPENAI_API_KEY from the environment or the gitignored repo-root .env. Lazy openai import so --help works without the package. * feat: create machine-level suppressions dir on --global hook install install-hooks.sh --global now mkdir -p's ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and states the convention: machine-level <dir>/<repo-basename>/suppressions.json is preferred over repo-local .security-review/suppressions.json, with review.sh merging both when run without --suppressions. * docs: describe sh-build-review as cross-family GPT-4.1 pass via cross_review.py * chore: retire Path B VM host artifacts, repoint xmodel hook to cross_review.py - delete systemd/ units and DEPLOY-R720.md (VM destroyed; recoverable from git history) - nightly_sweep.sh: retained for reference — header notes the VM-based Path B sweep is retired; ENABLE_XMODEL_HOOK now calls this repo's cross_review.py instead of the archived orchestrator's run.py - sweep-targets.txt: drop the stale ~/orchestrator warning block - README: document the Claude Code web cloud routines (repo-scanner-nightly-sweep 08:00 ET, repo-checkers-plane1 07:30 ET, ALARM-only to #repo-scanner) and add the cross_review.py section * docs(iam): repoint cross-family review invocations to cross_review.py * fix(ci): exclude canary corpus from ruff, add import smoke test CI has been red repo-wide: the latest ruff wants to reformat the intentionally-vulnerable canary fixtures (whose line numbers are keyed in canary-meta/KEY.md), and pytest --collect-only exits 5 with zero tests. Exclude canary/ via ruff.toml and add a root-level import smoke test so collection is non-empty and imports cross_review.py.
2026-07-14 19:24:01 -04:00
# Headless agentic runner (run_headless.py). Scanners (semgrep, gitleaks,
# checkov, cfn-lint, pip-audit) and npm are external binaries, installed separately
feat: re-home cross-family reviewer CLI, retire Path B host artifacts (#5) * feat: add router-less cross-family reviewer CLI (cross_review.py) Re-homes the archived orchestrator repo's GPT-4.1 cross_reviewer as a direct OpenAI SDK CLI: verbatim system prompt, same model id, ported 3-attempt exponential-backoff retry. Reads OPENAI_API_KEY from the environment or the gitignored repo-root .env. Lazy openai import so --help works without the package. * feat: create machine-level suppressions dir on --global hook install install-hooks.sh --global now mkdir -p's ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and states the convention: machine-level <dir>/<repo-basename>/suppressions.json is preferred over repo-local .security-review/suppressions.json, with review.sh merging both when run without --suppressions. * docs: describe sh-build-review as cross-family GPT-4.1 pass via cross_review.py * chore: retire Path B VM host artifacts, repoint xmodel hook to cross_review.py - delete systemd/ units and DEPLOY-R720.md (VM destroyed; recoverable from git history) - nightly_sweep.sh: retained for reference — header notes the VM-based Path B sweep is retired; ENABLE_XMODEL_HOOK now calls this repo's cross_review.py instead of the archived orchestrator's run.py - sweep-targets.txt: drop the stale ~/orchestrator warning block - README: document the Claude Code web cloud routines (repo-scanner-nightly-sweep 08:00 ET, repo-checkers-plane1 07:30 ET, ALARM-only to #repo-scanner) and add the cross_review.py section * docs(iam): repoint cross-family review invocations to cross_review.py * fix(ci): exclude canary corpus from ruff, add import smoke test CI has been red repo-wide: the latest ruff wants to reformat the intentionally-vulnerable canary fixtures (whose line numbers are keyed in canary-meta/KEY.md), and pytest --collect-only exits 5 with zero tests. Exclude canary/ via ruff.toml and add a root-level import smoke test so collection is non-empty and imports cross_review.py.
2026-07-14 19:24:01 -04:00
# (see README).
claude-agent-sdk
feat: re-home cross-family reviewer CLI, retire Path B host artifacts (#5) * feat: add router-less cross-family reviewer CLI (cross_review.py) Re-homes the archived orchestrator repo's GPT-4.1 cross_reviewer as a direct OpenAI SDK CLI: verbatim system prompt, same model id, ported 3-attempt exponential-backoff retry. Reads OPENAI_API_KEY from the environment or the gitignored repo-root .env. Lazy openai import so --help works without the package. * feat: create machine-level suppressions dir on --global hook install install-hooks.sh --global now mkdir -p's ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and states the convention: machine-level <dir>/<repo-basename>/suppressions.json is preferred over repo-local .security-review/suppressions.json, with review.sh merging both when run without --suppressions. * docs: describe sh-build-review as cross-family GPT-4.1 pass via cross_review.py * chore: retire Path B VM host artifacts, repoint xmodel hook to cross_review.py - delete systemd/ units and DEPLOY-R720.md (VM destroyed; recoverable from git history) - nightly_sweep.sh: retained for reference — header notes the VM-based Path B sweep is retired; ENABLE_XMODEL_HOOK now calls this repo's cross_review.py instead of the archived orchestrator's run.py - sweep-targets.txt: drop the stale ~/orchestrator warning block - README: document the Claude Code web cloud routines (repo-scanner-nightly-sweep 08:00 ET, repo-checkers-plane1 07:30 ET, ALARM-only to #repo-scanner) and add the cross_review.py section * docs(iam): repoint cross-family review invocations to cross_review.py * fix(ci): exclude canary corpus from ruff, add import smoke test CI has been red repo-wide: the latest ruff wants to reformat the intentionally-vulnerable canary fixtures (whose line numbers are keyed in canary-meta/KEY.md), and pytest --collect-only exits 5 with zero tests. Exclude canary/ via ruff.toml and add a root-level import smoke test so collection is non-empty and imports cross_review.py.
2026-07-14 19:24:01 -04:00
# Cross-family reviewer CLI (cross_review.py) — direct OpenAI SDK, no langchain.
openai