chore: initialize POM 2 repo (docs guards green; release gates recorded NOT RUN pending install)
This commit is contained in:
32
docs/AUDIT.md
Normal file
32
docs/AUDIT.md
Normal file
@@ -0,0 +1,32 @@
|
||||
# Release audit — POM 2.0.0
|
||||
|
||||
Date: 2026-07-12
|
||||
|
||||
## Automated verification
|
||||
|
||||
`npm run verify` performs:
|
||||
|
||||
1. Strict TypeScript check against real OMP packages.
|
||||
2. Production-code behavioral tests.
|
||||
3. Temporary-project runtime smoke test.
|
||||
4. Structural package, resource, agent-frontmatter, and theme-schema checks.
|
||||
5. `npm pack --dry-run`.
|
||||
|
||||
Covered behaviors include stage ordering, active-run gates, evidence requirements, blocker lifecycle, traversal/symlink defense, destructive-command policy, validator behavior, native Hive translation, Swarm graph generation, ZIP member decompression, CRC validation, and malformed archive rejection.
|
||||
|
||||
## Security posture
|
||||
|
||||
- Canonical paths are resolved with `realpath`.
|
||||
- Symbolic-link escapes are rejected.
|
||||
- Empty canonical artifacts are rejected.
|
||||
- Manifest hashes and byte counts are remeasured.
|
||||
- Recursive destructive commands against the project root are blocked by default.
|
||||
- ZIP member names, methods, decompression, sizes, duplicate names, and CRC values are verified.
|
||||
|
||||
The command policy is a guardrail, not an operating-system sandbox. Host approvals and normal filesystem permissions remain authoritative.
|
||||
|
||||
## Known release boundary
|
||||
|
||||
Bun and the `omp` executable are unavailable in this build environment. Therefore `omp plugin doctor` and a live interactive TUI smoke session were not run here. They remain mandatory host acceptance checks after installation.
|
||||
|
||||
`npm audit` currently reports moderate issues in the development/host dependency tree. The release archive does not claim a zero-vulnerability dependency graph; operators should evaluate the host's current dependency advisories.
|
||||
Reference in New Issue
Block a user