项目文件夹

文件
wehub-resource-sync 23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:02:19 +08:00

273 行
11 KiB
JavaScript
可执行文件

此文件含有模棱两可的 Unicode 字符
此文件含有可能会与其他字符混淆的 Unicode 字符。 如果您是想特意这样的,可以安全地忽略该警告。 使用 Escape 按钮显示他们。
#!/usr/bin/env node
// audit-trend.mjs — diff two oia-audit records to detect drift over time.
//
// The iter-7 oia-audit composite worker stores timestamped records under
// the `metaharness-audit` memory namespace. This script reads two such
// records and surfaces the delta:
// - composite worst severity change (clean → low, low → medium, etc.)
// - per-component (oia / threat-model / mcp-scan) status change
// - new HIGH-severity findings introduced
// - findings cleared
//
// Pairs with iter-7's oia-audit + iter-8's weekly cron — accumulated
// records enable drift detection without ad-hoc tooling.
//
// USAGE
// node scripts/audit-trend.mjs --baseline audit-<ts1>.json --current audit-<ts2>.json
// node scripts/audit-trend.mjs --baseline-key audit-2026-06-01... --current-key audit-2026-06-15...
// # pulls both from memory namespace `metaharness-audit`
// node scripts/audit-trend.mjs ... --alert-on-worsening
// node scripts/audit-trend.mjs ... --format json
//
// EXIT CODES
// 0 ok (no worsening, or --alert-on-worsening not set)
// 1 --alert-on-worsening AND composite severity worsened
// 2 config error or input not found
import { readFileSync, existsSync } from 'node:fs';
import { spawnSync } from 'node:child_process';
// iter 38 — structural-distance drift via ADR-152 §3.1 production module.
// Falls back to null if either record predates iter-38 oia-audit (no
// fingerprint field) — graceful degradation, never throws.
import { similarity } from './_similarity.mjs';
// iter 63 — shared SEVERITY_RANK from _harness.mjs (was a local literal
// missing info/warn/error/critical, which caused NaN-compare hazards).
import { SEVERITY_RANK, rankSeverity } from './_harness.mjs';
// iter 63 — SEVERITY_RANK moved to _harness.mjs (imported above)
const NS = process.env.AUDIT_TREND_NAMESPACE || 'metaharness-audit';
const CLI_PKG = process.env.CLI_CORE === '1'
? '@claude-flow/cli-core@alpha'
: '@claude-flow/cli@latest';
const ARGS = (() => {
const a = {
baseline: null, current: null,
baselineKey: null, currentKey: null,
alertOnWorsening: false, format: 'table',
// iter 38 — structural-distance gate (ADR-152 §3.1 dep)
alertOnDistanceBelow: null,
};
for (let i = 2; i < process.argv.length; i++) {
const v = process.argv[i];
if (v === '--baseline') a.baseline = process.argv[++i];
else if (v === '--current') a.current = process.argv[++i];
else if (v === '--baseline-key') a.baselineKey = process.argv[++i];
else if (v === '--current-key') a.currentKey = process.argv[++i];
else if (v === '--alert-on-worsening') a.alertOnWorsening = true;
else if (v === '--alert-on-distance-below') a.alertOnDistanceBelow = Number(process.argv[++i]);
else if (v === '--format') a.format = process.argv[++i];
}
return a;
})();
function memRetrieve(key) {
const r = spawnSync('npx', [
CLI_PKG, 'memory', 'retrieve',
'--namespace', NS, '--key', key,
], { stdio: ['ignore', 'pipe', 'pipe'], encoding: 'utf-8', shell: process.platform === 'win32' });
if (r.status !== 0) return null;
const m = /\{[\s\S]*\}/.exec(r.stdout || '');
if (!m) return null;
try { return JSON.parse(m[0]); } catch { return null; }
}
function loadRecord(label, filePath, memKey) {
if (filePath) {
if (!existsSync(filePath)) {
console.error(`audit-trend: ${label} file not found: ${filePath}`);
process.exit(2);
}
try { return JSON.parse(readFileSync(filePath, 'utf-8')); }
catch (e) {
console.error(`audit-trend: ${label} file invalid JSON: ${e.message}`);
process.exit(2);
}
}
if (memKey) {
const rec = memRetrieve(memKey);
if (!rec) {
console.error(`audit-trend: ${label} key not found in namespace ${NS}: ${memKey}`);
process.exit(2);
}
return rec;
}
console.error(`audit-trend: --${label} or --${label}-key is required`);
process.exit(2);
}
function main() {
const baseline = loadRecord('baseline', ARGS.baseline, ARGS.baselineKey);
const current = loadRecord('current', ARGS.current, ARGS.currentKey);
// Sanity: both must look like oia-audit records (composite + components).
if (!baseline.composite || !current.composite) {
console.error('audit-trend: snapshots must contain `composite` (from oia-audit.mjs)');
process.exit(2);
}
const baseWorst = String(baseline.composite.worst || 'clean').toLowerCase();
const currWorst = String(current.composite.worst || 'clean').toLowerCase();
// iter 63 — safe rankSeverity() eliminates NaN-compare when either
// severity is unknown (was a latent bug in audit-trend's drift verdict).
const deltaRank = rankSeverity(currWorst) - rankSeverity(baseWorst);
const worsened = deltaRank > 0;
const improved = deltaRank < 0;
// Per-component status change. Each `components.{oiaManifest, threatModel,
// mcpScan}` has degraded:bool + exitCode + (for threat-model) json.worst.
const componentDelta = (label, b, c) => {
if (!b || !c) return { label, delta: 'missing' };
if (b.degraded !== c.degraded) {
return { label, delta: c.degraded ? 'became degraded' : 'recovered from degraded' };
}
if (b.exitCode !== c.exitCode) {
return { label, delta: `exit code ${b.exitCode}${c.exitCode}` };
}
return { label, delta: 'unchanged' };
};
const components = {
oiaManifest: componentDelta('oia-manifest', baseline.components?.oiaManifest, current.components?.oiaManifest),
threatModel: componentDelta('threat-model', baseline.components?.threatModel, current.components?.threatModel),
mcpScan: componentDelta('mcp-scan', baseline.components?.mcpScan, current.components?.mcpScan),
};
// mcp-scan findings — what was introduced vs cleared.
const baseFindings = Array.isArray(baseline.components?.mcpScan?.json?.findings)
? baseline.components.mcpScan.json.findings : [];
const currFindings = Array.isArray(current.components?.mcpScan?.json?.findings)
? current.components.mcpScan.json.findings : [];
const fingerprint = (f) => `${f.severity}:${f.id ?? '-'}:${f.server ?? '-'}:${f.tool ?? '-'}:${(f.message ?? '').slice(0, 80)}`;
const baseSet = new Set(baseFindings.map(fingerprint));
const currSet = new Set(currFindings.map(fingerprint));
const introduced = currFindings.filter((f) => !baseSet.has(fingerprint(f)));
const cleared = baseFindings.filter((f) => !currSet.has(fingerprint(f)));
// iter 38 — structural distance via ADR-152 §3.1 similarity().
// Both records need a fingerprint (score+genome) — iter-38 oia-audit
// adds it; older records skip with verdict 'unavailable'.
let structuralDistance = null;
if (baseline.fingerprint?.score && baseline.fingerprint?.genome
&& current.fingerprint?.score && current.fingerprint?.genome) {
const sim = similarity(baseline.fingerprint, current.fingerprint);
structuralDistance = {
overall: sim.overall,
// Distance is the complement of similarity in [0,1]
distance: Number((1 - sim.overall).toFixed(4)),
components: sim.components,
verdict: sim.overall >= 0.95 ? 'near-identical'
: sim.overall >= 0.80 ? 'minor-drift'
: sim.overall >= 0.50 ? 'moderate-drift'
: 'major-drift',
};
} else {
structuralDistance = {
verdict: 'unavailable',
reason: 'one or both records predate iter-38 oia-audit fingerprint bundling',
};
}
// Distance alert is independent of severity worsening — a harness can
// structurally drift while keeping the same worst-severity verdict.
const distanceAlertTriggered = ARGS.alertOnDistanceBelow != null
&& structuralDistance.overall != null
&& structuralDistance.overall < ARGS.alertOnDistanceBelow;
const payload = {
baseline: {
startedAt: baseline.startedAt,
composite: baseline.composite,
},
current: {
startedAt: current.startedAt,
composite: current.composite,
},
delta: {
worst: { baseline: baseWorst, current: currWorst, rankDelta: deltaRank,
verdict: worsened ? 'worsened' : (improved ? 'improved' : 'unchanged') },
components,
findings: {
introducedCount: introduced.length,
clearedCount: cleared.length,
introduced: introduced.slice(0, 20), // truncate for output sanity
cleared: cleared.slice(0, 20),
},
// iter 38 — structural distance via ADR-152 §3.1
structuralDistance,
},
alert: (ARGS.alertOnWorsening || ARGS.alertOnDistanceBelow != null) ? {
triggered: worsened || distanceAlertTriggered,
reasons: [
ARGS.alertOnWorsening && worsened
? `composite worst ${baseWorst}${currWorst}` : null,
distanceAlertTriggered
? `structural similarity ${structuralDistance.overall} < threshold ${ARGS.alertOnDistanceBelow}` : null,
].filter(Boolean),
} : null,
generatedAt: new Date().toISOString(),
};
if (ARGS.format === 'json') {
console.log(JSON.stringify(payload, null, 2));
} else {
console.log(`# audit-trend`);
console.log('');
console.log(`Baseline: ${baseline.startedAt}`);
console.log(`Current: ${current.startedAt}`);
console.log('');
console.log(`| Metric | Baseline | Current | Verdict |`);
console.log(`|---|---|---|---|`);
const verdictIcon = worsened ? '⚠ worsened' : (improved ? '✓ improved' : '— unchanged');
console.log(`| composite worst | ${baseWorst} | ${currWorst} | ${verdictIcon} |`);
for (const [label, c] of Object.entries(components)) {
console.log(`| ${label} | — | — | ${c.delta} |`);
}
console.log('');
console.log(`Findings: **+${introduced.length} introduced**, **${cleared.length} cleared**`);
if (introduced.length > 0) {
console.log('');
console.log('## Introduced findings');
console.log('');
console.log('| Severity | Server | Tool | Message |');
console.log('|---|---|---|---|');
for (const f of introduced.slice(0, 20)) {
console.log(`| ${f.severity ?? '-'} | ${f.server ?? '-'} | ${f.tool ?? '-'} | ${(f.message ?? '').slice(0, 80)} |`);
}
}
if (cleared.length > 0) {
console.log('');
console.log('## Cleared findings');
console.log('');
for (const f of cleared.slice(0, 5)) {
console.log(`- ${f.severity ?? '-'} ${f.id ?? '-'} (${f.server ?? '-'}/${f.tool ?? '-'})`);
}
}
console.log('');
// iter 38 — structural distance row
if (structuralDistance.verdict !== 'unavailable') {
console.log(`## Structural distance (ADR-152 §3.1)`);
console.log('');
console.log(`| Metric | Value |`);
console.log(`|---|---:|`);
console.log(`| overall similarity | ${structuralDistance.overall.toFixed(4)} |`);
console.log(`| distance (1 sim) | ${structuralDistance.distance.toFixed(4)} |`);
console.log(`| verdict | **${structuralDistance.verdict}** |`);
console.log('');
} else {
console.log(`Structural distance: _unavailable — ${structuralDistance.reason}_`);
console.log('');
}
if (payload.alert) {
if (payload.alert.triggered) {
console.log(`⚠ **ALERT**: ${payload.alert.reasons.join('; ')}`);
} else {
console.log(`✓ no alert triggered`);
}
}
}
if (payload.alert?.triggered) process.exit(1);
}
main();