Skip to content

Add independently replayed exact CVE audit skill #91

Description

@jaasieldelgado131

Proposal

Add oss/skills/exact-cve-audit as a standalone governed community skill for exact npm dependency CVE evidence.

Unlike the existing single-run dependency audit, this package uses a graph with separate scan, independent OSV replay, and finalize steps. The finalize step is guarded and fails closed unless replay proves zero false and zero missing findings. Inputs require a full immutable Git commit and a lockfile URL pinned to that commit.

Public evidence

The contribution is isolated to the standalone skill package and does not change runtime or public API contracts.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions