mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-10-04 11:22:11 +00:00
Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced.
23 lines
603 B
Text
23 lines
603 B
Text
{
|
|
"name": "vuln-js-repo",
|
|
"version": "1.0.0",
|
|
"lockfileVersion": 3,
|
|
"requires": true,
|
|
"packages": {
|
|
"": {
|
|
"name": "vuln-js-repo",
|
|
"version": "1.0.0",
|
|
"dependencies": { "lodash": "4.17.15", "left-pad": "1.3.0" }
|
|
},
|
|
"node_modules/lodash": {
|
|
"version": "4.17.15",
|
|
"resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.15.tgz",
|
|
"integrity": "sha512-fake"
|
|
},
|
|
"node_modules/left-pad": {
|
|
"version": "1.3.0",
|
|
"resolved": "https://registry.npmjs.org/left-pad/-/left-pad-1.3.0.tgz",
|
|
"integrity": "sha512-fake"
|
|
}
|
|
}
|
|
}
|