Repository navigation
build(deps): refresh bundled scanner and harness tools - #65
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 7, 2026, 6:45 AM ET / 10:45 UTC. ClawSweeper reviewWhat this changesUpdates five scanner and judge tools bundled in ClawScan’s Docker image and records the refresh in the changelog. Merge readiness✅ Ready for maintainer review The refresh remains useful: current main retains the older pins. No actionable defect was found in the introduced changes, and the supplied runtime validation supports this bounded dependency update. Priority: P2 Review scores
Verification
How this fits togetherClawScan runs command-backed scanners and external judge commands in a bundled Docker image by default. The image supplies their executable dependencies; scanner results return to ClawScan as raw JSON evidence. flowchart TD
A[Skill files] --> B[ClawScan CLI]
B --> C[Docker sandbox]
D[Pinned tool packages] --> C
C --> E[Scanner or judge command]
E --> F[JSON evidence and verdict artifacts]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep the established Docker packaging and raw-evidence adapters while refreshing the pinned tools with the documented smoke coverage. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR refreshes existing dependencies rather than reporting a bug; the supplied comparison exercises the Cisco production scan path. Is this the best way to solve the issue? Yes: updating the existing image pins is the narrow packaging change, and no competing implementation or concrete compatibility defect was found. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against ff17e1d76e98. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
|
Merged as 128e696. The candidate runtime image built successfully, and all eight bundled CLI entrypoints passed their help checks. The baseline and candidate each completed 10/10 Cisco SkillTrustBench scans without failures or skips, retaining the same safety flags and maximum severities. Three lower-severity finding changes were checked against the published scanner sources and are explained in the PR body. This was a scanner smoke comparison without model-backed judging or credentialed API validation. Independent Codex autoreview was clean through P3. Exact-head CI and the two-architecture PR image build passed. After merge, main CI, CodeQL, and the automatic runtime image job all passed. |
Refresh five bundled runtime tools to releases that satisfy the two-day dependency cooldown, retaining Node 24 and Python 3.12.
Newer releases inside the cooldown are held. Go modules, pinned GitHub Actions, A.I.G, and AgentVerus are already current. The latest SkillSpector source revision is also held for cooldown.
Validation on a disposable Linux host:
docker build -t clawscan-runtime:candidate docker/clawscan-runtimepassed.--help: Codex, Claude, A.I.G, SkillSpector, Snyk, Socket, AgentVerus, and Cisco.clawscan benchmark SkillTrustBench --limit 10 --scanner cisco --sandbox-image <image> --output <artifact>against the current published image and the candidate. Both completed 10/10 scans with zero failures or skips. The sample contains 2 clean, 4 suspicious, and 4 malicious ground-truth cases.is_safeand maximum severity. Seven cases retained identical finding identities; three changed lower-severity findings, matching the changes in the checksum-verified published Cisco sources:case_03510: dropped a medium pipeline finding because a Python script consumes stdin as data rather than executing it as code.case_03004: dropped a medium brand finding because the updated rule requires an affiliation claim rather than a vendor mention.case_02130: added a low undeclared-network-destination finding for an undocumented API host.