ci: add osv-scanner supply-chain gate to push-check (T-353)
`make push-check` now runs a `security` step (ci/osv_scan.sh) that scans pubspec.lock with osv-scanner and fails the push if any resolved dependency has a known advisory. This is a hard, fail-closed gate on top of `dart pub get`'s passive (non-failing) advisory print. Replaces the old manual-review `security` no-op target. Slots in among the instant fail-fast gates, before the coverage suite. Resolves the osv-scanner binary from PATH, falling back to a brew prefix so the gate works under the pre-push hook's leaner PATH; if absent it fails with an install hint (brew install osv-scanner). Native deps (dugite, tree-sitter, wasmtime) are vendored by SHA and reviewed separately on bump (D-42), so they're out of scope for the lockfile scan. Verified clean against the current lockfile (80 packages, no issues). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -309,8 +309,8 @@ clide-cli-clean: ## Remove the compiled C `clide` client.
|
||||
# -- security -------------------------------------------------------------
|
||||
|
||||
.PHONY: security
|
||||
security: ## Dart advisory review.
|
||||
@echo "security: Dart advisories reviewed manually before pubspec.yaml bumps."
|
||||
security: ## Supply-chain gate — osv-scanner over pubspec.lock (fails on a known advisory).
|
||||
ci/osv_scan.sh
|
||||
|
||||
# -- pre-push gate --------------------------------------------------------
|
||||
|
||||
@@ -319,7 +319,7 @@ decisions-validate: ## Parser dry-run over governance/{decisions,questions,rejec
|
||||
pql decisions validate
|
||||
|
||||
.PHONY: push-check
|
||||
push-check: decisions-validate changelog-gate test-coverage coverage-gate test-core ## Pre-push gate (fast — <2 min target). Order is fail-fast: instant gates (decisions, changelog) first, then the coverage suite + gate (the expensive, most-likely-to-fail stage) BEFORE test-core — a coverage miss aborts here instead of after running everything, so a fix doesn't force a full re-run of the rest. test-coverage already runs the a11y suite (test/a11y), so no separate test-a11y pass.
|
||||
push-check: decisions-validate changelog-gate security test-coverage coverage-gate test-core ## Pre-push gate (fast — <2 min target). Order is fail-fast: instant gates (decisions, changelog, security/osv) first, then the coverage suite + gate (the expensive, most-likely-to-fail stage) BEFORE test-core — a coverage miss aborts here instead of after running everything, so a fix doesn't force a full re-run of the rest. test-coverage already runs the a11y suite (test/a11y), so no separate test-a11y pass.
|
||||
|
||||
.PHONY: push-check-full
|
||||
push-check-full: push-check test-integration smoke-bundle ## Pre-release gate (push-check + integration + smoke; slower).
|
||||
|
||||
Reference in New Issue
Block a user