forked from bchanot/claude
feat(install): semgrep pinned install + pin-honored update (security-gate lot 1)
Step 7.5 in install-plugins.sh: pipx install semgrep==<pin> behind a command -v guard (LRN-085 pattern), version echo on skip, login is Pro-rules-only guidance — never run automatically (ctx7 pattern). Step 6.2 in update-all.sh: pin-honored update that displays the version jump (cur → pin) before pipx install --force; latest only when unpinned. plugins.lock.json: semgrep pinned 1.168.0 — semgrep is a BLOCKING gate, a silent upgrade means new BLOCKs on unchanged code (gsd-pin pattern). Dogfooded via extracted real blocks: fresh install, idempotent re-run, pin-match skip, jump display + clean warn on bogus pin. Rulesets p/security-audit + p/secrets fetch anonymously (no login) and detect. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
ff13abfda5
commit
ccfecc9c21
@@ -26,6 +26,12 @@
|
||||
"managed_by": "pipx",
|
||||
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep."
|
||||
},
|
||||
"semgrep": {
|
||||
"source": "pypi:semgrep",
|
||||
"version": "1.168.0",
|
||||
"managed_by": "pipx",
|
||||
"note": "SAST engine for the security gate (security-auditor agent, onboard cso fallback, audit-delta). Rulesets pinned in-agent: p/security-audit + p/secrets (never --config auto). BLOCKING gate -> pin honored by update-all.sh: 'make update' will NOT advance semgrep past it; bump deliberately (new rules = new BLOCKs on unchanged code). Never run 'semgrep login' automatically (Pro rules are optional, guide-only)."
|
||||
},
|
||||
"emil-design-eng": {
|
||||
"source": "https://github.com/emilkowalski/skill",
|
||||
"path": "skills/emil-design-eng/SKILL.md",
|
||||
|
||||
Reference in New Issue
Block a user