From 00c97bcacb495e55ed8477e24d66151950a610f0 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Tue, 7 Jul 2026 03:42:15 +0200 Subject: [PATCH] job6: supply-chain documentation pass (F-X1, semgrep caveat) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - README + plugins.lock.json graphifyy note: pipx/PyPI install only, never npm/npx — a different publisher (rhanka/graphify) squats the same 'graphifyy' name on npm as a version-shadowing shim with its own conflicting 'graphify' bin (F-X1). - agents/security-auditor.md: one-line caveat that p/* semgrep packs are fetched from the registry at runtime — the CLI version pin does not freeze ruleset content, so a new BLOCK can appear on unchanged code. MCP magic (F-X3): version pin declined by user call (stays @latest in lib/toggle-external.sh). ${VAR} env expansion confirmed unsupported at ~/.claude.json user scope (Claude Code docs — expansion is .mcp.json project-scope only), so the BDR-026 reference-not-plaintext pattern doesn't transfer here; existing mitigations (canonical ~/.claude/.env, gitignore, audit env-field filtering) remain the practical ceiling. ~/.claude.json regenerated out-of-repo via toggle-external.sh disable+ enable magic to pick up the already-rotated MAGIC_API_KEY (no repo diff, no commit for that file — traced in the job6 final report). --- README.md | 5 +++++ agents/security-auditor.md | 4 ++++ plugins.lock.json | 2 +- 3 files changed, 10 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 933944c..61970cb 100644 --- a/README.md +++ b/README.md @@ -84,6 +84,11 @@ ctx7 login # optional: OAuth / API key for higher rate limits Versions are pinned in `plugins.lock.json`. To update: edit the file, then re-run `install-plugins.sh`. +Graphify installs via **pipx/PyPI only, never npm/npx**: a different publisher +squats the same `graphifyy` name on npm (version-shadowing shim re-exporting +a different package, ships its own conflicting `graphify` bin) — see +`plugins.lock.json`'s `graphifyy` note. + --- ## Slash commands diff --git a/agents/security-auditor.md b/agents/security-auditor.md index 5209108..8d7da2b 100644 --- a/agents/security-auditor.md +++ b/agents/security-auditor.md @@ -60,6 +60,10 @@ non-deterministic gate). owasp-top-ten is REQUIRED, not optional: measured 2026-07-03, the two-ruleset baseline missed SQL injection and path traversal entirely on realistic Flask code; owasp-top-ten's taint rules catch them. +Caveat: `p/*` packs are fetched from the registry at RUNTIME — pinning the +`semgrep` CLI version (`plugins.lock.json`) does NOT freeze ruleset content; +a new BLOCK can appear on unchanged code even with the CLI pin untouched. + **Severity mapping** (from `results[].extra.severity` + ruleset origin): | semgrep | origin | → gate severity | blocks? | diff --git a/plugins.lock.json b/plugins.lock.json index 5e261db..4df45b1 100644 --- a/plugins.lock.json +++ b/plugins.lock.json @@ -24,7 +24,7 @@ "source": "pypi:graphifyy", "version": "latest", "managed_by": "pipx", - "note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep." + "note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep. pipx/PyPI ONLY — never npm/npx: a different publisher (rhanka/graphify) squats the same 'graphifyy' name on npm, a version-shadowing shim with its own conflicting 'graphify' bin." }, "semgrep": { "source": "pypi:semgrep",