DEMO Beat 1: drop secure-baseline pin (expect required-packages fail)#10
DEMO Beat 1: drop secure-baseline pin (expect required-packages fail)#10danielmeppiel wants to merge 4 commits into
Conversation
7ab686a to
6a5b04d
Compare
Required by org policy (apm-policy.yml dependencies.require). Expected: apm audit --ci fails on required-packages check. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
6a5b04d to
53fb1f1
Compare
|
Closing as DO-NOT-MERGE demo artifact. PR is wired for D2 governance demo (PLATFORM.md §D2) — kept open as a reference; closing to avoid accidental merge. Re-open from the same branch for the live demo. |
Frontmatter of pr-review-panel.md and triage-panel.md changed but the .lock.yml files were not recompiled, causing 'Check workflow lock file' to fail with ERR_CONFIG on PR #10. Run gh aw compile (v0.71.5) to bring locks back in sync. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
🏛️ Architect reviewWhat I seeThis PR removes the explicit Concerns
Looks good
🛡️ Security reviewWhat I seeThis diff removes the Findings
Checklist
⚖️ Panel verdict: REJECT2 blockers (security) · 1 design flaw (architect). This PR intentionally drops the
|
Demo PR — D2 Governance. Removes the explicit
secure-baselinepin fromapm.yml. Expected:apm auditfiresrequired-packagesviolation, ruleset blocks merge.Org policy:
dependencies.require: [DevExpGbb/zava-agent-config/plugins/secure-baseline]