Skip to content

Add dependency advisory graph skill - #119

Closed
RYDE-PLAY wants to merge 65 commits into
runxhq:mainfrom
RYDE-PLAY:ryde-play/dependency-advisory-graph
Closed

Add dependency advisory graph skill#119
RYDE-PLAY wants to merge 65 commits into
runxhq:mainfrom
RYDE-PLAY:ryde-play/dependency-advisory-graph

Conversation

@RYDE-PLAY

@RYDE-PLAY RYDE-PLAY commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

Adds the dependency-advisory-graph runx skill.

This skill scans a committed npm package-lock.json, queries OSV with exact package/version tuples only, and emits a typed advisory graph packet. It is read-only: it does not install target packages, execute target code, mutate repositories, or report package-name-only advisory matches.

Validation included in this PR:

  • X.yaml defines three harness cases: an advisory-positive OWASP NodeGoat lockfile pinned to commit c5cb68a7084e4ae7dcc60e6a98768720a81841e8, a clean lockfile fixture with no findings, and an intentional missing-lockfile stop case.
  • run.mjs emits dependency.advisory.graph.result.v1, typed_findings, and an advisory_graph with affected_by_exact_version edges.
  • The runner uses Node's built-in https module instead of fetch, so hosted runtimes without global fetch still execute the network cases.
  • harness/local-case-runs.json records local direct case evidence using runx-cli 0.6.13.
  • The NodeGoat fixture found 13 exact-version OSV findings across 6 direct production packages.
  • The clean fixture returned zero findings, zero typed findings, and zero graph edges.
  • The missing-lockfile stop case fails closed instead of fabricating an advisory graph.
  • The generated report includes a graph receipt note; this skill builds the graph directly rather than composing another graph skill.

auscaster and others added 30 commits June 19, 2026 19:55
default to the /internal/thread-outbox pending cursor (drops the fragile client cursor-cache that re-walked history on a fresh runner) and listen for a board-sync repository_dispatch so the venue can trigger the drain low-latency.
a no-ua, no-browser-headers, http1.1 client is an obvious bot signature. the fetch tool now presents a current chrome ua + the browser header set and negotiates http2 with gzip/brotli, applied as overridable defaults. configurable via RUNX_HTTP_USER_AGENT and RUNX_HTTP_BROWSER=0; the anthropic and registry transports stay plain; all transport guards unchanged. tls (ja3/ja4) and http2 fingerprint matching are out of scope.
Conventional follow-up for the pushed lockfile refresh.
Adds the dependency-cve-audit runx skill and registers it in the official catalog.

Verified:
- CI green on PR runxhq#82
- node --check skills/dependency-cve-audit/run.mjs
- runx doctor skills/dependency-cve-audit --json
- runx harness skills/dependency-cve-audit --receipt-dir <tmp> --json
- packages/cli/src/skill-refs.test.ts
Adds the structured-extraction runx skill and completes the paid follow-up integration work.

Maintainer cleanup added:
- deterministic tool fixture for structured.extract
- SKILL.md frontmatter for official catalog generation
- official skill lock/Rust table/catalog allowlist entries

Verified:
- CI green on PR runxhq#80
- local merge simulation after runxhq#82
- node --check skills/structured-extraction/tools/structured/extract/run.mjs
- runx doctor skills/structured-extraction --json
- runx harness skills/structured-extraction --receipt-dir <tmp> --json
- runx dev tools/structured/extract --json with RUNX_PROJECT_DIR set to the skill root
- packages/cli/src/skill-refs.test.ts
auscaster added 21 commits June 21, 2026 03:45
Remove the user-facing installation-id flag from add/registry flows, keep native command help aligned, and update registry fixtures/docs to use versioned runx add plus runx skill execution commands.
Rename the bundled runx operator skill to ops-desk, remove product-specific fixture names, keep newer maturing skills internal until they meet the public catalog bar, and make graph skills fail closed when required graph inputs are missing.
Update the native CLI skill execution/export surfaces, add governed data-plane contracts and fixtures, refresh official skill catalog coverage, and remove local .ai state from Git tracking.

Validation: pnpm bindings:check; pnpm exec tsc --noEmit --allowJs --checkJs --module NodeNext --moduleResolution NodeNext --target ES2022 --skipLibCheck scripts/check-upstream-skill-bindings.mjs; git diff --check
@RYDE-PLAY
RYDE-PLAY force-pushed the ryde-play/dependency-advisory-graph branch 4 times, most recently from d2901f8 to 2b4310b Compare June 23, 2026 00:01
@RYDE-PLAY
RYDE-PLAY force-pushed the ryde-play/dependency-advisory-graph branch from 2b4310b to 789b841 Compare June 23, 2026 00:17
@auscaster

Copy link
Copy Markdown
Collaborator

Closing to consolidate: we're reviewing one PR per contributor and yours is #277 (rollback-judge). Most of these predate the July skill-tree rename, which was our break, not yours, so they can't rebase cleanly anyway.

@auscaster auscaster closed this Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants