Files
pom-omp/docs/AUDIT.md

1.6 KiB

Release audit — POM 2.0.0

Date: 2026-07-12

Automated verification

npm run verify performs:

  1. Strict TypeScript check against real OMP packages.
  2. Production-code behavioral tests.
  3. Temporary-project runtime smoke test.
  4. Structural package, resource, agent-frontmatter, and theme-schema checks.
  5. npm pack --dry-run.

Covered behaviors include stage ordering, active-run gates, evidence requirements, blocker lifecycle, traversal/symlink defense, destructive-command policy, validator behavior, native Hive translation, Swarm graph generation, ZIP member decompression, CRC validation, and malformed archive rejection.

Security posture

  • Canonical paths are resolved with realpath.
  • Symbolic-link escapes are rejected.
  • Empty canonical artifacts are rejected.
  • Manifest hashes and byte counts are remeasured.
  • Recursive destructive commands against the project root are blocked by default.
  • ZIP member names, methods, decompression, sizes, duplicate names, and CRC values are verified.

The command policy is a guardrail, not an operating-system sandbox. Host approvals and normal filesystem permissions remain authoritative.

Known release boundary

Bun and the omp executable are unavailable in this build environment. Therefore omp plugin doctor and a live interactive TUI smoke session were not run here. They remain mandatory host acceptance checks after installation.

npm audit currently reports moderate issues in the development/host dependency tree. The release archive does not claim a zero-vulnerability dependency graph; operators should evaluate the host's current dependency advisories.