Commit graph

21 commits

Author SHA1 Message Date
05732978f9
ci: enable squash auto-merge on ready PRs 2026-08-21 18:56:34 -04:00
Adam Moussa
932e61db69
ci: add merge_group trigger for required ci / ci (#16) 2026-08-21 17:42:39 -04:00
dependabot[bot]
e5ed7acfb7
chore(deps): bump the minor-and-patch group with 4 updates (#15)
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 15:16:02 -04:00
dependabot[bot]
1ec6ac61c0
chore(deps): bump the minor-and-patch group with 4 updates (#14)
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.5 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](9c1ecf9428...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 17:48:22 -04:00
Adam Moussa
60a4c026b4
fix(hooks): fail closed when pre-push scanner missing (#11) 2026-08-06 19:29:04 -04:00
Adam Moussa
51f7905cc7
ci: add org PR policy caller (#10)
Refs: PLAT-62
2026-08-04 11:56:37 -04:00
dependabot[bot]
a82092f4ca
Merge pull request #8 from Sea-Haven-Industries/dependabot/github_actions/minor-and-patch-3e1a0502ab
chore(deps): bump the minor-and-patch group with 3 updates
2026-08-03 13:00:15 -04:00
Adam Moussa
cdffa3066b
Merge pull request #7 from Sea-Haven-Industries/ci/pin-reusables-v1.0.2
ci(deps): pin org reusable workflows to v1.0.2
2026-07-28 18:11:51 -04:00
Adam Moussa
8cad01cf45 style(ci): normalize workflow block spacing 2026-07-28 18:07:56 -04:00
Adam Moussa
db4a98eb62 ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:58:08 -04:00
Adam Moussa
1e121312ee
Fix stale review.sh default path in hook templates (#6)
The 2026-07-09 directory reorg moved this repo under seahaven/, but the
hook templates' default REVIEW_SH path still pointed at the old
location. Every install-hooks.sh --global run since then re-installed
hooks that fail open ("review.sh not found — skipping gate") on every
push. The live hooks on this machine were re-pointed manually
2026-07-15; this fixes the source so the next install doesn't regress.

Refs: INFRA-107
2026-07-15 20:30:50 -04:00
Adam Moussa
58aa07d8be
feat: re-home cross-family reviewer CLI, retire Path B host artifacts (#5)
* feat: add router-less cross-family reviewer CLI (cross_review.py)

Re-homes the archived orchestrator repo's GPT-4.1 cross_reviewer as a
direct OpenAI SDK CLI: verbatim system prompt, same model id, ported
3-attempt exponential-backoff retry. Reads OPENAI_API_KEY from the
environment or the gitignored repo-root .env. Lazy openai import so
--help works without the package.

* feat: create machine-level suppressions dir on --global hook install

install-hooks.sh --global now mkdir -p's
${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and
states the convention: machine-level <dir>/<repo-basename>/suppressions.json
is preferred over repo-local .security-review/suppressions.json, with
review.sh merging both when run without --suppressions.

* docs: describe sh-build-review as cross-family GPT-4.1 pass via cross_review.py

* chore: retire Path B VM host artifacts, repoint xmodel hook to cross_review.py

- delete systemd/ units and DEPLOY-R720.md (VM destroyed; recoverable
  from git history)
- nightly_sweep.sh: retained for reference — header notes the VM-based
  Path B sweep is retired; ENABLE_XMODEL_HOOK now calls this repo's
  cross_review.py instead of the archived orchestrator's run.py
- sweep-targets.txt: drop the stale ~/orchestrator warning block
- README: document the Claude Code web cloud routines
  (repo-scanner-nightly-sweep 08:00 ET, repo-checkers-plane1 07:30 ET,
  ALARM-only to #repo-scanner) and add the cross_review.py section

* docs(iam): repoint cross-family review invocations to cross_review.py

* fix(ci): exclude canary corpus from ruff, add import smoke test

CI has been red repo-wide: the latest ruff wants to reformat the
intentionally-vulnerable canary fixtures (whose line numbers are keyed
in canary-meta/KEY.md), and pytest --collect-only exits 5 with zero
tests. Exclude canary/ via ruff.toml and add a root-level import smoke
test so collection is non-empty and imports cross_review.py.
2026-07-14 19:24:01 -04:00
Adam Moussa
5408649943
feat(scanner): auto-resolve + merge suppressions when --suppressions absent (#4)
review.sh only applied suppressions when handed an explicit --suppressions
FILE, so only the pre-push hook resolved them. Every other entry point (the
Open SWE daily-report automation, nightly sweep, on-demand/CI, agent runs)
called review.sh without it and therefore suppressed nothing, re-surfacing
every already-adjudicated false positive as HIGH.

When --suppressions is not passed, resolve by repo basename and MERGE both
suppression locations (machine-level first, wins id collisions):
  - machine-level: ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review}/<basename>/suppressions.json
  - repo-local:    <repo>/.security-review/suppressions.json
An explicit --suppressions still overrides, so the hook and existing callers
are unaffected. Degrades gracefully off-Mac (repo-local only); fail-safe on an
unparseable file (suppresses nothing → blocks).

SECURITY (/sh-security-review, 2026-07-13): fan-out + proof-or-kill confirmed
one HIGH — the git-tracked repo-local suppressions.json lets anyone who can
commit to a scanned repo suppress a real finding and PASS an automated run
(verified by an actual exploit run; same posture nightly_sweep already had).
ACCEPTED-RISK per Adam on the condition that the automated scanners only ever
target trusted repos (no unreviewed untrusted contributions). Documented in the
auto-resolve block, README trust-model note, and a hard warning in
sweep-targets.txt. Four other candidates downgraded to low/pre-existing.

Verified: machine-level and repo-local both auto-resolve and suppress; explicit
--suppressions override still blocks; simulated off-Mac host keeps repo-local
and correctly re-blocks machine-level-only FPs.
2026-07-13 14:33:27 -04:00
Adam Moussa
9cac679bc3
fix(scanner): skip gitignored cdk.out synth output in checkov scan (INFRA-144) (#3)
checkov scanned cdk.out/<stack>.template.json, which is gitignored generated
synth output. A dev with a stale cdk.out lying around would false-block unrelated
pushes on CKV_AWS_111 raised against CDK-generated roles (LogRetention, asset
publishing) that are not authored source. Broaden the checkov --skip-path from
cdk.out/asset. to the whole cdk.out/ tree so it treats synth output the same as
semgrep (--exclude cdk.out) and cfn-lint (cdk.out prune) already do.

Authored IaC checkov parses (SAM/CFN template.yaml, Terraform) is tracked source
and is still fully scanned; verified a planted wildcard IAM policy in tracked
source still trips CKV_AWS_111 and blocks.
2026-07-08 16:54:01 -04:00
Adam Moussa
643c6139da
Merge pull request #2 from Sea-Haven-Industries/chore/INFRA-50-sha-pin-reusables
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50)
2026-07-06 20:31:53 -04:00
da26a388fe
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) 2026-07-06 18:08:16 -04:00
Adam Moussa
80cdc87d2d
Merge pull request #1 from Sea-Haven-Industries/docs/INFRA-137-readme-badges
docs: add README status badges (INFRA-137)
2026-07-06 17:39:15 -04:00
5600f199e9
docs: add README status badges (INFRA-137) 2026-07-06 17:24:21 -04:00
094a253c37
feat(canary): add anti-complacency recall-floor corpus + repo skip marker
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed,
answer-revealing comments stripped so it measures real detection) and canary-meta/
(KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it).
One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so
it stays a CWE-798 finding without tripping push protection.

Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip
this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as
its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
2026-06-29 12:10:54 -04:00
3cf9bb7652
fix(hooks): point default review.sh path at the standalone security-review repo
The pre-push/pre-commit hooks defaulted SH_REVIEW_SH to the orchestrator checkout
(orchestrator/security-review/review.sh). With the gate re-homed here, default to
$HOME/Documents/repositories/security-review/review.sh so push-time gating does
not lapse when orchestrator is deprecated. Live global hook re-pointed to match.
2026-06-29 11:43:54 -04:00
4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00