Skip to content

improve(dependency-scanning): add lockfile registry gates#2811

Closed
bodoo26 wants to merge 1 commit into
UnitOneAI:mainfrom
bodoo26:improve/dependency-scanning-lockfile-registry-gates
Closed

improve(dependency-scanning): add lockfile registry gates#2811
bodoo26 wants to merge 1 commit into
UnitOneAI:mainfrom
bodoo26:improve/dependency-scanning-lockfile-registry-gates

Conversation

@bodoo26

@bodoo26 bodoo26 commented Jun 23, 2026

Copy link
Copy Markdown

Summary

  • add dependency-scanning gates for manifest, lockfile, CI install mode, and build artifact alignment
  • require private registry namespace proof before scoring dependency confusion risk
  • add fixtures for lockfile drift, patched lockfile benign evidence, and missing private registry mapping

Validation

  • ruby scripts/validate_skill_schema.rb
  • ruby scripts/validate_index.rb
  • ruby scripts/test_skill_fixtures.rb
  • ruby scripts/test_remediation_fixtures.rb
  • ruby scripts/generate_quality_scorecard.rb --check
  • git diff --check

Refs #2792

@bodoo26 bodoo26 requested a review from kamalsrini as a code owner June 23, 2026 16:33
@github-actions github-actions Bot added the needs-approved-issue PR has no linked maintainer-approved issue label Jun 23, 2026
@github-actions

Copy link
Copy Markdown

Thanks for the submission! 🙏 SecuritySkills is now issue-first: contributions need a linked issue that a maintainer has marked approved before a PR is opened.

Please open an issue describing the skill, wait for the approved label, then reopen this PR with Closes #<issue> in the description. The PR template lists everything we'll look for (including an independently runnable reproduction).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-approved-issue PR has no linked maintainer-approved issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant