← Files NightshiftARCHIVED FILE

skills/nightshift/references/compose/shifts/vulnerability-sweep.md

2.81 KB · Oct 2, 2026 · 00:30 UTC

↓ Download file

# Vulnerability sweep — finite — the advisories filed against what you already ship

Advisories are not lint: no tool in the project reports them, and they arrive on someone else's
schedule. The list is what the audit tool publishes today, so it ends — usually in an hour or two,
unless a major upgrade turns out to be the only route to a fix.

Write receipts from `$NIGHTSHIFT_PLUGIN_ROOT/skills/nightshift/references/receipts/cycle-specialist-evidence.md`.
The model writes the receipt. Unparsed tool output is `unavailable`, never "no findings".
If present, `ns normalize-output` turns a supported tool format into one compact
summary for the receipt and the ledger; otherwise read the raw output directly.

Supported wherever the ecosystem publishes advisories — npm/pnpm/yarn, pip, cargo, go.
Never select this entry in artifact mode. Do not `git init` a notes folder to make findings commitable.

## Supply-chain posture mode

Inventory posture from repository-owned standards and tools only, reading the output of tools the
project already runs into a `mode: supply-chain` receipt from `receipts/cycle-specialist-evidence.md`.
Record observed components and standards; never give legal conclusions from license tooling.

```text
- [ ] **Vulnerability sweep — clear the advisories the audit tool reports.**
  - Never select this entry when work mode is artifact.
  - Discovery: for supply-chain posture mode read repository-owned scanner output first.
    Otherwise use the project's own audit — `pnpm audit` / `npm audit`, `pip-audit`, `cargo audit`,
    `govulncheck`. Enrich each advisory in a `mode: vuln-enrich` receipt from
    `receipts/cycle-specialist-evidence.md`: provenance, affected and fixed versions, transitive path, reachability,
    and runtime versus dev exposure.
    Work critical and high first, so an interrupted night cleared what mattered.
  - Per advisory: read what the vulnerability actually is and whether the project's usage reaches
    it, move to the fixed version, adapt the code that change requires, run the item gate, commit.
  - **Never downgrade to satisfy an advisory.** Where the only offered fix is an older version,
    park it with the advisory link — a silent regression is not a fix.
  - Never add an ignore or suppression entry, and never reach for an audit tool's `--force`.
    Silencing an advisory is not clearing it.
  - An advisory reachable only through a transitive dependency, or with no fixed version published,
    goes to parking-lot.md with its link and severity: overrides and resolutions are owner calls.
  - Record every disposition in snag-log.md so the next sweep does not re-raise a parked advisory.
  - Ends when the audit reports clean, or every advisory still standing is parked with a reason.
  - Verify: the item gate is green at every commit; the audit is re-run after the last fix.
```

SHA-256: 60b8fb7eb7ab7aa79997a5346d78b87686589efc4b1ea20fe9ee89ee18d860c0