forked from bchanot/claude
feat(install): semgrep pinned install + pin-honored update (security-gate lot 1)
Step 7.5 in install-plugins.sh: pipx install semgrep==<pin> behind a command -v guard (LRN-085 pattern), version echo on skip, login is Pro-rules-only guidance — never run automatically (ctx7 pattern). Step 6.2 in update-all.sh: pin-honored update that displays the version jump (cur → pin) before pipx install --force; latest only when unpinned. plugins.lock.json: semgrep pinned 1.168.0 — semgrep is a BLOCKING gate, a silent upgrade means new BLOCKs on unchanged code (gsd-pin pattern). Dogfooded via extracted real blocks: fresh install, idempotent re-run, pin-match skip, jump display + clean warn on bogus pin. Rulesets p/security-audit + p/secrets fetch anonymously (no login) and detect. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
ff13abfda5
commit
ccfecc9c21
@@ -654,6 +654,35 @@ if command -v graphify &>/dev/null; then
|
|||||||
fi
|
fi
|
||||||
echo ""
|
echo ""
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# STEP 7.5 — SEMGREP (SAST engine for the security gate)
|
||||||
|
# ============================================================
|
||||||
|
echo "── Step 7.5: Semgrep — SAST security gate ───────────────────"
|
||||||
|
echo ""
|
||||||
|
if command -v semgrep &>/dev/null; then
|
||||||
|
ok "semgrep already installed ($(semgrep --version 2>/dev/null | head -1))"
|
||||||
|
else
|
||||||
|
SEMGREP_VER=$(pinned_version "semgrep")
|
||||||
|
if [ "$SEMGREP_VER" != "latest" ]; then
|
||||||
|
info "Installing semgrep ${SEMGREP_VER} (pinned in plugins.lock.json)..."
|
||||||
|
pipx install "semgrep==${SEMGREP_VER}" 2>/dev/null
|
||||||
|
else
|
||||||
|
info "Installing semgrep latest (consider pinning in plugins.lock.json)..."
|
||||||
|
pipx install semgrep 2>/dev/null
|
||||||
|
fi
|
||||||
|
if command -v semgrep &>/dev/null; then
|
||||||
|
ok "semgrep installed ($(semgrep --version 2>/dev/null | head -1))"
|
||||||
|
else
|
||||||
|
err "semgrep install failed — run manually: pipx install semgrep"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
# Login is Pro-rules only and optional — NEVER run automatically (ctx7
|
||||||
|
# pattern: guide, don't block). The gate uses pinned public rulesets.
|
||||||
|
if command -v semgrep &>/dev/null; then
|
||||||
|
info "Optional Pro rules: semgrep login (never run automatically)"
|
||||||
|
fi
|
||||||
|
echo ""
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# STEP 8 — EMIL DESIGN ENG (UI polish / animation skill)
|
# STEP 8 — EMIL DESIGN ENG (UI polish / animation skill)
|
||||||
# ============================================================
|
# ============================================================
|
||||||
|
|||||||
@@ -26,6 +26,12 @@
|
|||||||
"managed_by": "pipx",
|
"managed_by": "pipx",
|
||||||
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep."
|
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep."
|
||||||
},
|
},
|
||||||
|
"semgrep": {
|
||||||
|
"source": "pypi:semgrep",
|
||||||
|
"version": "1.168.0",
|
||||||
|
"managed_by": "pipx",
|
||||||
|
"note": "SAST engine for the security gate (security-auditor agent, onboard cso fallback, audit-delta). Rulesets pinned in-agent: p/security-audit + p/secrets (never --config auto). BLOCKING gate -> pin honored by update-all.sh: 'make update' will NOT advance semgrep past it; bump deliberately (new rules = new BLOCKs on unchanged code). Never run 'semgrep login' automatically (Pro rules are optional, guide-only)."
|
||||||
|
},
|
||||||
"emil-design-eng": {
|
"emil-design-eng": {
|
||||||
"source": "https://github.com/emilkowalski/skill",
|
"source": "https://github.com/emilkowalski/skill",
|
||||||
"path": "skills/emil-design-eng/SKILL.md",
|
"path": "skills/emil-design-eng/SKILL.md",
|
||||||
|
|||||||
@@ -227,6 +227,47 @@ else
|
|||||||
info "graphifyy not installed — skipping"
|
info "graphifyy not installed — skipping"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# ── 6.2. Update Semgrep (pin-honored — BLOCKING security gate) ──
|
||||||
|
echo ""
|
||||||
|
echo "── Updating Semgrep..."
|
||||||
|
if command -v semgrep &>/dev/null; then
|
||||||
|
SEMGREP_VER=""
|
||||||
|
if [ -f "$REPO/plugins.lock.json" ] && command -v python3 &>/dev/null; then
|
||||||
|
SEMGREP_VER=$(python3 -c "
|
||||||
|
import json
|
||||||
|
with open('$REPO/plugins.lock.json') as f:
|
||||||
|
d = json.load(f)
|
||||||
|
print(d.get('semgrep',{}).get('version',''))
|
||||||
|
" 2>/dev/null || true)
|
||||||
|
fi
|
||||||
|
|
||||||
|
SEMGREP_CUR=$(semgrep --version 2>/dev/null | head -1)
|
||||||
|
if [ -n "$SEMGREP_VER" ] && [ "$SEMGREP_VER" != "latest" ]; then
|
||||||
|
if [ "$SEMGREP_CUR" = "$SEMGREP_VER" ]; then
|
||||||
|
ok "semgrep already at pinned $SEMGREP_VER"
|
||||||
|
else
|
||||||
|
# Jump shown explicitly: semgrep is a BLOCKING gate — a version bump
|
||||||
|
# can add rules that BLOCK unchanged code, so the jump must be a
|
||||||
|
# visible, deliberate human decision (bump the pin, then update).
|
||||||
|
info "semgrep ${SEMGREP_CUR:-?} → ${SEMGREP_VER} (pinned in plugins.lock.json)"
|
||||||
|
if pipx install --force "semgrep==${SEMGREP_VER}" 2>/dev/null; then
|
||||||
|
ok "semgrep updated to $SEMGREP_VER"
|
||||||
|
else
|
||||||
|
warn "semgrep update failed — try: pipx install --force semgrep==${SEMGREP_VER}"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
info "No pinned version — upgrading to latest"
|
||||||
|
if pipx upgrade semgrep 2>/dev/null; then
|
||||||
|
ok "semgrep updated ($(semgrep --version 2>/dev/null | head -1))"
|
||||||
|
else
|
||||||
|
warn "semgrep update failed — try: pipx upgrade semgrep"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
info "semgrep not installed — skipping (run: make plugin)"
|
||||||
|
fi
|
||||||
|
|
||||||
# ── 6.5. Update bun ──
|
# ── 6.5. Update bun ──
|
||||||
echo ""
|
echo ""
|
||||||
echo "── Updating bun..."
|
echo "── Updating bun..."
|
||||||
|
|||||||
Reference in New Issue
Block a user