diff --git a/install-plugins.sh b/install-plugins.sh index 2810f4d..60d79e6 100644 --- a/install-plugins.sh +++ b/install-plugins.sh @@ -654,6 +654,35 @@ if command -v graphify &>/dev/null; then fi echo "" +# ============================================================ +# STEP 7.5 — SEMGREP (SAST engine for the security gate) +# ============================================================ +echo "── Step 7.5: Semgrep — SAST security gate ───────────────────" +echo "" +if command -v semgrep &>/dev/null; then + ok "semgrep already installed ($(semgrep --version 2>/dev/null | head -1))" +else + SEMGREP_VER=$(pinned_version "semgrep") + if [ "$SEMGREP_VER" != "latest" ]; then + info "Installing semgrep ${SEMGREP_VER} (pinned in plugins.lock.json)..." + pipx install "semgrep==${SEMGREP_VER}" 2>/dev/null + else + info "Installing semgrep latest (consider pinning in plugins.lock.json)..." + pipx install semgrep 2>/dev/null + fi + if command -v semgrep &>/dev/null; then + ok "semgrep installed ($(semgrep --version 2>/dev/null | head -1))" + else + err "semgrep install failed — run manually: pipx install semgrep" + fi +fi +# Login is Pro-rules only and optional — NEVER run automatically (ctx7 +# pattern: guide, don't block). The gate uses pinned public rulesets. +if command -v semgrep &>/dev/null; then + info "Optional Pro rules: semgrep login (never run automatically)" +fi +echo "" + # ============================================================ # STEP 8 — EMIL DESIGN ENG (UI polish / animation skill) # ============================================================ diff --git a/plugins.lock.json b/plugins.lock.json index ef55a07..f42e496 100644 --- a/plugins.lock.json +++ b/plugins.lock.json @@ -26,6 +26,12 @@ "managed_by": "pipx", "note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep." }, + "semgrep": { + "source": "pypi:semgrep", + "version": "1.168.0", + "managed_by": "pipx", + "note": "SAST engine for the security gate (security-auditor agent, onboard cso fallback, audit-delta). Rulesets pinned in-agent: p/security-audit + p/secrets (never --config auto). BLOCKING gate -> pin honored by update-all.sh: 'make update' will NOT advance semgrep past it; bump deliberately (new rules = new BLOCKs on unchanged code). Never run 'semgrep login' automatically (Pro rules are optional, guide-only)." + }, "emil-design-eng": { "source": "https://github.com/emilkowalski/skill", "path": "skills/emil-design-eng/SKILL.md", diff --git a/update-all.sh b/update-all.sh index 0eed297..09f7b0c 100644 --- a/update-all.sh +++ b/update-all.sh @@ -227,6 +227,47 @@ else info "graphifyy not installed — skipping" fi +# ── 6.2. Update Semgrep (pin-honored — BLOCKING security gate) ── +echo "" +echo "── Updating Semgrep..." +if command -v semgrep &>/dev/null; then + SEMGREP_VER="" + if [ -f "$REPO/plugins.lock.json" ] && command -v python3 &>/dev/null; then + SEMGREP_VER=$(python3 -c " +import json +with open('$REPO/plugins.lock.json') as f: + d = json.load(f) +print(d.get('semgrep',{}).get('version','')) +" 2>/dev/null || true) + fi + + SEMGREP_CUR=$(semgrep --version 2>/dev/null | head -1) + if [ -n "$SEMGREP_VER" ] && [ "$SEMGREP_VER" != "latest" ]; then + if [ "$SEMGREP_CUR" = "$SEMGREP_VER" ]; then + ok "semgrep already at pinned $SEMGREP_VER" + else + # Jump shown explicitly: semgrep is a BLOCKING gate — a version bump + # can add rules that BLOCK unchanged code, so the jump must be a + # visible, deliberate human decision (bump the pin, then update). + info "semgrep ${SEMGREP_CUR:-?} → ${SEMGREP_VER} (pinned in plugins.lock.json)" + if pipx install --force "semgrep==${SEMGREP_VER}" 2>/dev/null; then + ok "semgrep updated to $SEMGREP_VER" + else + warn "semgrep update failed — try: pipx install --force semgrep==${SEMGREP_VER}" + fi + fi + else + info "No pinned version — upgrading to latest" + if pipx upgrade semgrep 2>/dev/null; then + ok "semgrep updated ($(semgrep --version 2>/dev/null | head -1))" + else + warn "semgrep update failed — try: pipx upgrade semgrep" + fi + fi +else + info "semgrep not installed — skipping (run: make plugin)" +fi + # ── 6.5. Update bun ── echo "" echo "── Updating bun..."