Skip to content

Refresh security review scope and conditions - #184

Merged
shinpr merged 2 commits into
mainfrom
refine/security-review-scope
Sep 22, 2026
Merged

shinpr merged 2 commits into
mainfrom
refine/security-review-scope

Conversation

@shinpr

@shinpr shinpr commented Sep 22, 2026

Copy link
Copy Markdown
Owner

Summary

  • semi-annual security review of the detection patterns: drop stale entries, narrow over-broad ones, and cover SSRF, object-level authorization, and dependency and pipeline integrity
  • gate the advisory step on the changed component instead of searching the whole technology stack every run
  • resolve the re-review JSON contract contradiction and the unconditional blocked status on committed secrets
  • sync generated plugin bundles and bump the patch version to 0.27.2

Validation

  • pnpm sync:check
  • claude plugin validate .claude-plugin/marketplace.json
  • claude plugin validate dev-workflows
  • claude plugin validate dev-workflows-frontend
  • claude plugin validate dev-workflows-fullstack
  • claude plugin validate dev-skills
  • git diff --check

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@shinpr shinpr self-assigned this Sep 22, 2026
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@shinpr
shinpr merged commit bd41561 into main Sep 22, 2026
1 check passed
@shinpr
shinpr deleted the refine/security-review-scope branch September 22, 2026 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant