Repository navigation
Upgrade PRISM to Advanced Engineering Risk Intelligence Engine - #2
Conversation
… Integration - Implement 10 independent analysis layers in pipeline orchestrator. - Expand SecurityAnalyzer across secrets, injection, auth weaknesses, weak crypto, and SSRF. - Add ArchitectureAnalyzer for API contracts, schema migrations, and core logic risks. - Add DependencyAnalyzer for unpinned dependencies, lockfile drift, and vulnerable packages. - Upgrade TestingAnalyzer and ComplexityAnalyzer for multi-factor PR risk scoring. - Enhance FindingDeduplicator and RiskScoringEngine for compound risk interactions and priority sorting. - Add real GitHub API endpoints and upgrade interactive dashboard frontend. Co-authored-by: omharde42 <193398705+omharde42@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
There was a problem hiding this comment.
🟡 Changes recommended
It introduces unauthenticated GitHub-backed endpoints plus flaky/non-hermetic tests and a confirmed SSRF-regex bug that can cause incorrect findings.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR expands PRISM from a local/static PR analyzer into a GitHub-backed engineering risk “intelligence engine” by adding new deterministic analyzers (architecture/dependency), enriching scoring/deduplication, and wiring a dashboard + API endpoints to fetch and analyze real GitHub pull requests.
Changes:
- Added new analysis layers (ArchitectureAnalyzer, DependencyAnalyzer) and expanded existing analyzers/scoring/deduplication to support prioritization and compound risk drivers.
- Introduced GitHub-backed API endpoints and service methods to fetch repositories/PRs/diffs and trigger analysis runs from real GitHub data.
- Updated the dashboard UX to accept owner/repo/PR inputs and run analysis via the new API.
File summaries
| File | Description |
|---|---|
| tests/test_advanced_analyzers.py | Adds tests for new analyzers/scoring and a GitHubService smoke test. |
| prism/services/github.py | Adds GitHub API calls for repo listing, PR listing, and raw file fetching. |
| prism/dashboard/index.html | Adds GitHub selector toolbar and analysis trigger workflow in the UI. |
| prism/api/schemas.py | Updates Pydantic models to v2-style config; adds GitHubAnalyzeRequest schema. |
| prism/api/routes.py | Adds new GitHub list + analyze endpoints to drive real PR analysis. |
| prism/analysis/types.py | Introduces severity weights and a computed priority_score for findings. |
| prism/analysis/testing.py | Enhances testing requirement logic with “sensitive module” detection. |
| prism/analysis/security.py | Expands detection patterns (secrets, injection, auth weaknesses, SSRF/path traversal). |
| prism/analysis/risk_scoring.py | Reworks scoring math to incorporate category counts and compound interactions. |
| prism/analysis/orchestrator.py | Extends pipeline to include new analyzers and optional source context for AI. |
| prism/analysis/dependency.py | Adds dependency manifest analysis (unpinned deps, drift, risky packages). |
| prism/analysis/deduplicator.py | Switches dedup/sort behavior to use priority_score ordering. |
| prism/analysis/complexity.py | Adds broader complexity heuristics (cross-module, footprint) and refines messaging. |
| prism/analysis/architecture.py | Adds architectural risk detection (migrations, API contracts, infra/core logic). |
| prism/analysis/ai_review.py | Expands AI prompt inputs and adds interaction detection in heuristic fallback. |
Review details
Suppressed comments (3)
prism/api/schemas.py:33
- These list fields use
[]as a default. PreferField(default_factory=list)so each response model instance gets its own list and you avoid subtle mutation bugs.
metrics: Optional[dict] = None
drivers: List[str] = []
findings: List[FindingSchema] = []
prism/dashboard/index.html:230
- For accessibility, this label isn’t associated with its input (no
forattribute).
<label>Repository Name</label>
<input type="text" id="repo-input" placeholder="e.g. Hello-World" value="Hello-World">
prism/dashboard/index.html:234
- For accessibility, this label isn’t associated with its input (no
forattribute).
<label>PR Number</label>
<input type="number" id="pr-input" placeholder="e.g. 1" value="1">
- Files reviewed: 15/15 changed files
- Comments generated: 8
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @router.get("/github/repos") | ||
| async def list_github_repositories(): | ||
| """Fetch user accessible GitHub repositories.""" | ||
| gh_service = GitHubService() | ||
| try: | ||
| repos = await gh_service.get_user_repositories() | ||
| return repos | ||
| except Exception as e: | ||
| raise HTTPException(status_code=500, detail=f"Failed to fetch repositories: {str(e)}") |
| from typing import List | ||
| from prism.analysis.types import FindingDTO | ||
| from prism.analysis.types import FindingDTO, SEVERITY_WEIGHTS | ||
| from prism.config import settings |
| # Check lockfile drift (manifest changed without lockfile update) | ||
| if manifest_changed and not lock_changed: | ||
| findings.append(FindingDTO( | ||
| category="dependency", | ||
| severity="medium", | ||
| confidence=0.9, | ||
| title="Lockfile Drift Detected (Manifest Modified Without Lockfile)", | ||
| description="Dependency manifest (e.g. package.json, requirements.txt) was modified, but no lockfile update was included.", | ||
| impact="Build environments may install different resolved dependency versions, leading to non-reproducible builds.", | ||
| recommendation="Run package manager install command and commit updated lockfile (e.g., package-lock.json).", | ||
| evidence="Manifest modified without corresponding lockfile change." | ||
| )) |
| SSRF_PATH_PATTERNS = [ | ||
| (r"\.\.\/|\.\.\\", "Potential Path Traversal Sequence", "high"), | ||
| (r"(?i)requests\.(get|post|put|delete)\s*\(\s*user_input|url_param|req\.", "Potential Server-Side Request Forgery (SSRF)", "high"), | ||
| ] |
| def test_security_analyzer_expanded(): | ||
| diff = """diff --git a/prism/auth.py b/prism/auth.py | ||
| new file mode 100644 | ||
| --- /dev/null | ||
| +--- b/prism/auth.py | ||
| @@ -0,0 +1,5 @@ | ||
| +api_key = "sk-12345678901234567890123456789012" | ||
| +requests.get("https://internal.api", verify=False) | ||
| +exec(user_input) | ||
| """ | ||
| file_diffs = DiffAnalyzer.parse_patch(diff) | ||
| findings = SecurityAnalyzer.analyze(file_diffs) |
| @pytest.mark.asyncio | ||
| async def test_github_service_fetch_user_repos(): | ||
| gh = GitHubService() | ||
| repos = await gh.get_user_repositories() | ||
| assert isinstance(repos, list) |
| @@ -1,22 +1,21 @@ | |||
| from typing import List, Optional | |||
| from pydantic import BaseModel | |||
| from pydantic import BaseModel, ConfigDict | |||
| <label>Repository Owner</label> | ||
| <input type="text" id="owner-input" placeholder="e.g. octocat" value="octocat"> |
This PR upgrades PRISM into a full-scale engineering risk intelligence system capable of fetching authentic GitHub pull requests, executing multi-layer static and AI risk analysis, deduplicating and ranking findings, calculating explainable risk scores, and displaying reports in a web dashboard.
PR created automatically by Jules for task 6393445185110112633 started by @omharde42