Skip to content

Improve dependency override governance gates#1953

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/dependency-override-governance-fixtures-1649
Open

Improve dependency override governance gates#1953
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/dependency-override-governance-fixtures-1649

Conversation

@DENGXUELIN

Copy link
Copy Markdown

Summary

  • add dependency override/replacement governance gates for npm/Yarn/pnpm, Go replace, Rust [patch], Maven/Gradle substitutions, and Python constraints/direct URLs
  • add an override/replacement review table to the dependency scan output template
  • add vulnerable and benign fixtures covering risky git/local-path/downgrade rewrites and governed fixed-version overrides

Why this is different from existing #1649 attempts

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence balance check for SKILL.md and both fixture files
  • ASCII check for touched files
  • content marker check for DEP-OVERRIDE-*, override review output, risky git override, governed mitigation, and Cargo override references
  • git merge-tree --write-tree origin/main HEAD

Closes #1649

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] dependency-scanning: add override and replacement governance gates

1 participant