Skip to content

Upgrade PRISM to Advanced Engineering Risk Intelligence Engine - #2

Merged
omharde42 merged 1 commit into
mainfrom
feature/advanced-engineering-risk-intelligence-6393445185110112633
Sep 1, 2026
Merged

omharde42 merged 1 commit into
mainfrom
feature/advanced-engineering-risk-intelligence-6393445185110112633

Conversation

@omharde42

Copy link
Copy Markdown
Owner

This PR upgrades PRISM into a full-scale engineering risk intelligence system capable of fetching authentic GitHub pull requests, executing multi-layer static and AI risk analysis, deduplicating and ranking findings, calculating explainable risk scores, and displaying reports in a web dashboard.


PR created automatically by Jules for task 6393445185110112633 started by @omharde42

… Integration

- Implement 10 independent analysis layers in pipeline orchestrator.
- Expand SecurityAnalyzer across secrets, injection, auth weaknesses, weak crypto, and SSRF.
- Add ArchitectureAnalyzer for API contracts, schema migrations, and core logic risks.
- Add DependencyAnalyzer for unpinned dependencies, lockfile drift, and vulnerable packages.
- Upgrade TestingAnalyzer and ComplexityAnalyzer for multi-factor PR risk scoring.
- Enhance FindingDeduplicator and RiskScoringEngine for compound risk interactions and priority sorting.
- Add real GitHub API endpoints and upgrade interactive dashboard frontend.

Co-authored-by: omharde42 <193398705+omharde42@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 1, 2026 16:03
@google-labs-jules

Copy link
Copy Markdown
Contributor

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

Repository owner deleted a comment from chatgpt-codex-connector Bot Sep 1, 2026
@omharde42
omharde42 merged commit eeda063 into main Sep 1, 2026
1 check passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

It introduces unauthenticated GitHub-backed endpoints plus flaky/non-hermetic tests and a confirmed SSRF-regex bug that can cause incorrect findings.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR expands PRISM from a local/static PR analyzer into a GitHub-backed engineering risk “intelligence engine” by adding new deterministic analyzers (architecture/dependency), enriching scoring/deduplication, and wiring a dashboard + API endpoints to fetch and analyze real GitHub pull requests.

Changes:

  • Added new analysis layers (ArchitectureAnalyzer, DependencyAnalyzer) and expanded existing analyzers/scoring/deduplication to support prioritization and compound risk drivers.
  • Introduced GitHub-backed API endpoints and service methods to fetch repositories/PRs/diffs and trigger analysis runs from real GitHub data.
  • Updated the dashboard UX to accept owner/repo/PR inputs and run analysis via the new API.
File summaries
File Description
tests/test_advanced_analyzers.py Adds tests for new analyzers/scoring and a GitHubService smoke test.
prism/services/github.py Adds GitHub API calls for repo listing, PR listing, and raw file fetching.
prism/dashboard/index.html Adds GitHub selector toolbar and analysis trigger workflow in the UI.
prism/api/schemas.py Updates Pydantic models to v2-style config; adds GitHubAnalyzeRequest schema.
prism/api/routes.py Adds new GitHub list + analyze endpoints to drive real PR analysis.
prism/analysis/types.py Introduces severity weights and a computed priority_score for findings.
prism/analysis/testing.py Enhances testing requirement logic with “sensitive module” detection.
prism/analysis/security.py Expands detection patterns (secrets, injection, auth weaknesses, SSRF/path traversal).
prism/analysis/risk_scoring.py Reworks scoring math to incorporate category counts and compound interactions.
prism/analysis/orchestrator.py Extends pipeline to include new analyzers and optional source context for AI.
prism/analysis/dependency.py Adds dependency manifest analysis (unpinned deps, drift, risky packages).
prism/analysis/deduplicator.py Switches dedup/sort behavior to use priority_score ordering.
prism/analysis/complexity.py Adds broader complexity heuristics (cross-module, footprint) and refines messaging.
prism/analysis/architecture.py Adds architectural risk detection (migrations, API contracts, infra/core logic).
prism/analysis/ai_review.py Expands AI prompt inputs and adds interaction detection in heuristic fallback.
Review details

Suppressed comments (3)

prism/api/schemas.py:33

  • These list fields use [] as a default. Prefer Field(default_factory=list) so each response model instance gets its own list and you avoid subtle mutation bugs.
    metrics: Optional[dict] = None
    drivers: List[str] = []
    findings: List[FindingSchema] = []

prism/dashboard/index.html:230

  • For accessibility, this label isn’t associated with its input (no for attribute).
        <label>Repository Name</label>
        <input type="text" id="repo-input" placeholder="e.g. Hello-World" value="Hello-World">

prism/dashboard/index.html:234

  • For accessibility, this label isn’t associated with its input (no for attribute).
        <label>PR Number</label>
        <input type="number" id="pr-input" placeholder="e.g. 1" value="1">
  • Files reviewed: 15/15 changed files
  • Comments generated: 8
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread prism/api/routes.py
Comment on lines +13 to +21
@router.get("/github/repos")
async def list_github_repositories():
"""Fetch user accessible GitHub repositories."""
gh_service = GitHubService()
try:
repos = await gh_service.get_user_repositories()
return repos
except Exception as e:
raise HTTPException(status_code=500, detail=f"Failed to fetch repositories: {str(e)}")
Comment on lines 1 to 3
from typing import List
from prism.analysis.types import FindingDTO
from prism.analysis.types import FindingDTO, SEVERITY_WEIGHTS
from prism.config import settings
Comment on lines +98 to +109
# Check lockfile drift (manifest changed without lockfile update)
if manifest_changed and not lock_changed:
findings.append(FindingDTO(
category="dependency",
severity="medium",
confidence=0.9,
title="Lockfile Drift Detected (Manifest Modified Without Lockfile)",
description="Dependency manifest (e.g. package.json, requirements.txt) was modified, but no lockfile update was included.",
impact="Build environments may install different resolved dependency versions, leading to non-reproducible builds.",
recommendation="Run package manager install command and commit updated lockfile (e.g., package-lock.json).",
evidence="Manifest modified without corresponding lockfile change."
))
Comment on lines +43 to 46
SSRF_PATH_PATTERNS = [
(r"\.\.\/|\.\.\\", "Potential Path Traversal Sequence", "high"),
(r"(?i)requests\.(get|post|put|delete)\s*\(\s*user_input|url_param|req\.", "Potential Server-Side Request Forgery (SSRF)", "high"),
]
Comment on lines +14 to +25
def test_security_analyzer_expanded():
diff = """diff --git a/prism/auth.py b/prism/auth.py
new file mode 100644
--- /dev/null
+--- b/prism/auth.py
@@ -0,0 +1,5 @@
+api_key = "sk-12345678901234567890123456789012"
+requests.get("https://internal.api", verify=False)
+exec(user_input)
"""
file_diffs = DiffAnalyzer.parse_patch(diff)
findings = SecurityAnalyzer.analyze(file_diffs)
Comment on lines +110 to +114
@pytest.mark.asyncio
async def test_github_service_fetch_user_repos():
gh = GitHubService()
repos = await gh.get_user_repositories()
assert isinstance(repos, list)
Comment thread prism/api/schemas.py
@@ -1,22 +1,21 @@
from typing import List, Optional
from pydantic import BaseModel
from pydantic import BaseModel, ConfigDict
Comment on lines +225 to +226
<label>Repository Owner</label>
<input type="text" id="owner-input" placeholder="e.g. octocat" value="octocat">
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants