Publish Validated PowerShell Detection Lifecycle v1 - #19
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 09b19d8021
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| - name: Validated PowerShell lifecycle pack | ||
| run: | | ||
| python3 automation/build_powershell_lifecycle_pack.py --check |
There was a problem hiding this comment.
Check staleness before regenerating artifacts
In the inspected detection-validation workflow, an artifact-only change can pass this check because the earlier Sigma conversion step rewrites every generated SPL/EQL file before --check hashes them. With no subsequent git diff --exit-code, CI compares the regenerated canonical files to the old manifest and succeeds, while the changed file remains in the commit and becomes stale after merge. Run the lifecycle check before conversion or verify that conversion leaves the worktree unchanged.
Useful? React with 👍 / 👎.
Summary
Validation
Evidence boundary
This organizes the existing 2026-07-18 live validation. It does not claim a new execution or newly measured latency.