Commit graph

11 commits

Author SHA1 Message Date
2165312426
feat: create machine-level suppressions dir on --global hook install
install-hooks.sh --global now mkdir -p's
${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and
states the convention: machine-level <dir>/<repo-basename>/suppressions.json
is preferred over repo-local .security-review/suppressions.json, with
review.sh merging both when run without --suppressions.
2026-07-14 19:05:29 -04:00
e061ef8f80
feat: add router-less cross-family reviewer CLI (cross_review.py)
Re-homes the archived orchestrator repo's GPT-4.1 cross_reviewer as a
direct OpenAI SDK CLI: verbatim system prompt, same model id, ported
3-attempt exponential-backoff retry. Reads OPENAI_API_KEY from the
environment or the gitignored repo-root .env. Lazy openai import so
--help works without the package.
2026-07-14 19:04:57 -04:00
Adam Moussa
5408649943
feat(scanner): auto-resolve + merge suppressions when --suppressions absent (#4)
review.sh only applied suppressions when handed an explicit --suppressions
FILE, so only the pre-push hook resolved them. Every other entry point (the
Open SWE daily-report automation, nightly sweep, on-demand/CI, agent runs)
called review.sh without it and therefore suppressed nothing, re-surfacing
every already-adjudicated false positive as HIGH.

When --suppressions is not passed, resolve by repo basename and MERGE both
suppression locations (machine-level first, wins id collisions):
  - machine-level: ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review}/<basename>/suppressions.json
  - repo-local:    <repo>/.security-review/suppressions.json
An explicit --suppressions still overrides, so the hook and existing callers
are unaffected. Degrades gracefully off-Mac (repo-local only); fail-safe on an
unparseable file (suppresses nothing → blocks).

SECURITY (/sh-security-review, 2026-07-13): fan-out + proof-or-kill confirmed
one HIGH — the git-tracked repo-local suppressions.json lets anyone who can
commit to a scanned repo suppress a real finding and PASS an automated run
(verified by an actual exploit run; same posture nightly_sweep already had).
ACCEPTED-RISK per Adam on the condition that the automated scanners only ever
target trusted repos (no unreviewed untrusted contributions). Documented in the
auto-resolve block, README trust-model note, and a hard warning in
sweep-targets.txt. Four other candidates downgraded to low/pre-existing.

Verified: machine-level and repo-local both auto-resolve and suppress; explicit
--suppressions override still blocks; simulated off-Mac host keeps repo-local
and correctly re-blocks machine-level-only FPs.
2026-07-13 14:33:27 -04:00
Adam Moussa
9cac679bc3
fix(scanner): skip gitignored cdk.out synth output in checkov scan (INFRA-144) (#3)
checkov scanned cdk.out/<stack>.template.json, which is gitignored generated
synth output. A dev with a stale cdk.out lying around would false-block unrelated
pushes on CKV_AWS_111 raised against CDK-generated roles (LogRetention, asset
publishing) that are not authored source. Broaden the checkov --skip-path from
cdk.out/asset. to the whole cdk.out/ tree so it treats synth output the same as
semgrep (--exclude cdk.out) and cfn-lint (cdk.out prune) already do.

Authored IaC checkov parses (SAM/CFN template.yaml, Terraform) is tracked source
and is still fully scanned; verified a planted wildcard IAM policy in tracked
source still trips CKV_AWS_111 and blocks.
2026-07-08 16:54:01 -04:00
Adam Moussa
643c6139da
Merge pull request #2 from Sea-Haven-Industries/chore/INFRA-50-sha-pin-reusables
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50)
2026-07-06 20:31:53 -04:00
da26a388fe
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) 2026-07-06 18:08:16 -04:00
Adam Moussa
80cdc87d2d
Merge pull request #1 from Sea-Haven-Industries/docs/INFRA-137-readme-badges
docs: add README status badges (INFRA-137)
2026-07-06 17:39:15 -04:00
5600f199e9
docs: add README status badges (INFRA-137) 2026-07-06 17:24:21 -04:00
094a253c37
feat(canary): add anti-complacency recall-floor corpus + repo skip marker
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed,
answer-revealing comments stripped so it measures real detection) and canary-meta/
(KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it).
One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so
it stays a CWE-798 finding without tripping push protection.

Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip
this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as
its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
2026-06-29 12:10:54 -04:00
3cf9bb7652
fix(hooks): point default review.sh path at the standalone security-review repo
The pre-push/pre-commit hooks defaulted SH_REVIEW_SH to the orchestrator checkout
(orchestrator/security-review/review.sh). With the gate re-homed here, default to
$HOME/Documents/repositories/security-review/review.sh so push-time gating does
not lapse when orchestrator is deprecated. Live global hook re-pointed to match.
2026-06-29 11:43:54 -04:00
4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00