forked from bchanot/claude
job6: supply-chain documentation pass (F-X1, semgrep caveat)
- README + plugins.lock.json graphifyy note: pipx/PyPI install only, never
npm/npx — a different publisher (rhanka/graphify) squats the same
'graphifyy' name on npm as a version-shadowing shim with its own
conflicting 'graphify' bin (F-X1).
- agents/security-auditor.md: one-line caveat that p/* semgrep packs are
fetched from the registry at runtime — the CLI version pin does not
freeze ruleset content, so a new BLOCK can appear on unchanged code.
MCP magic (F-X3): version pin declined by user call (stays @latest in
lib/toggle-external.sh). ${VAR} env expansion confirmed unsupported at
~/.claude.json user scope (Claude Code docs — expansion is .mcp.json
project-scope only), so the BDR-026 reference-not-plaintext pattern
doesn't transfer here; existing mitigations (canonical ~/.claude/.env,
gitignore, audit env-field filtering) remain the practical ceiling.
~/.claude.json regenerated out-of-repo via toggle-external.sh disable+
enable magic to pick up the already-rotated MAGIC_API_KEY (no repo diff,
no commit for that file — traced in the job6 final report).
This commit is contained in:
+1
-1
@@ -24,7 +24,7 @@
|
||||
"source": "pypi:graphifyy",
|
||||
"version": "latest",
|
||||
"managed_by": "pipx",
|
||||
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep."
|
||||
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep. pipx/PyPI ONLY — never npm/npx: a different publisher (rhanka/graphify) squats the same 'graphifyy' name on npm, a version-shadowing shim with its own conflicting 'graphify' bin."
|
||||
},
|
||||
"semgrep": {
|
||||
"source": "pypi:semgrep",
|
||||
|
||||
Reference in New Issue
Block a user