job6: supply-chain documentation pass (F-X1, semgrep caveat)

- README + plugins.lock.json graphifyy note: pipx/PyPI install only, never
  npm/npx — a different publisher (rhanka/graphify) squats the same
  'graphifyy' name on npm as a version-shadowing shim with its own
  conflicting 'graphify' bin (F-X1).
- agents/security-auditor.md: one-line caveat that p/* semgrep packs are
  fetched from the registry at runtime — the CLI version pin does not
  freeze ruleset content, so a new BLOCK can appear on unchanged code.

MCP magic (F-X3): version pin declined by user call (stays @latest in
lib/toggle-external.sh). ${VAR} env expansion confirmed unsupported at
~/.claude.json user scope (Claude Code docs — expansion is .mcp.json
project-scope only), so the BDR-026 reference-not-plaintext pattern
doesn't transfer here; existing mitigations (canonical ~/.claude/.env,
gitignore, audit env-field filtering) remain the practical ceiling.
~/.claude.json regenerated out-of-repo via toggle-external.sh disable+
enable magic to pick up the already-rotated MAGIC_API_KEY (no repo diff,
no commit for that file — traced in the job6 final report).
This commit is contained in:
Bastien Chanot
2026-07-07 03:42:15 +02:00
parent 2813e55289
commit 00c97bcacb
3 changed files with 10 additions and 1 deletions
+5
View File
@@ -84,6 +84,11 @@ ctx7 login # optional: OAuth / API key for higher rate limits
Versions are pinned in `plugins.lock.json`. To update: edit the file, then re-run `install-plugins.sh`. Versions are pinned in `plugins.lock.json`. To update: edit the file, then re-run `install-plugins.sh`.
Graphify installs via **pipx/PyPI only, never npm/npx**: a different publisher
squats the same `graphifyy` name on npm (version-shadowing shim re-exporting
a different package, ships its own conflicting `graphify` bin) — see
`plugins.lock.json`'s `graphifyy` note.
--- ---
## Slash commands ## Slash commands
+4
View File
@@ -60,6 +60,10 @@ non-deterministic gate). owasp-top-ten is REQUIRED, not optional: measured
2026-07-03, the two-ruleset baseline missed SQL injection and path traversal 2026-07-03, the two-ruleset baseline missed SQL injection and path traversal
entirely on realistic Flask code; owasp-top-ten's taint rules catch them. entirely on realistic Flask code; owasp-top-ten's taint rules catch them.
Caveat: `p/*` packs are fetched from the registry at RUNTIME — pinning the
`semgrep` CLI version (`plugins.lock.json`) does NOT freeze ruleset content;
a new BLOCK can appear on unchanged code even with the CLI pin untouched.
**Severity mapping** (from `results[].extra.severity` + ruleset origin): **Severity mapping** (from `results[].extra.severity` + ruleset origin):
| semgrep | origin | → gate severity | blocks? | | semgrep | origin | → gate severity | blocks? |
+1 -1
View File
@@ -24,7 +24,7 @@
"source": "pypi:graphifyy", "source": "pypi:graphifyy",
"version": "latest", "version": "latest",
"managed_by": "pipx", "managed_by": "pipx",
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep." "note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep. pipx/PyPI ONLY — never npm/npx: a different publisher (rhanka/graphify) squats the same 'graphifyy' name on npm, a version-shadowing shim with its own conflicting 'graphify' bin."
}, },
"semgrep": { "semgrep": {
"source": "pypi:semgrep", "source": "pypi:semgrep",