← Files NightshiftARCHIVED FILE
skills/nightshift/references/compose/shifts/vulnerability-sweep.md
2.81 KB · Oct 3, 2026 · 06:31 UTC
# Vulnerability sweep — finite — the advisories filed against what you already ship
Advisories are not lint: no tool in the project reports them, and they arrive on someone else's
schedule. The list is what the audit tool publishes today, so it ends — usually in an hour or two,
unless a major upgrade turns out to be the only route to a fix.
Write receipts from `$NIGHTSHIFT_PLUGIN_ROOT/skills/nightshift/references/receipts/cycle-specialist-evidence.md`.
The model writes the receipt. Unparsed tool output is `unavailable`, never "no findings".
If present, `ns normalize-output` turns a supported tool format into one compact
summary for the receipt and the ledger; otherwise read the raw output directly.
Supported wherever the ecosystem publishes advisories — npm/pnpm/yarn, pip, cargo, go.
Never select this entry in artifact mode. Do not `git init` a notes folder to make findings commitable.
## Supply-chain posture mode
Inventory posture from repository-owned standards and tools only, reading the output of tools the
project already runs into a `mode: supply-chain` receipt from `receipts/cycle-specialist-evidence.md`.
Record observed components and standards; never give legal conclusions from license tooling.
```text
- [ ] **Vulnerability sweep — clear the advisories the audit tool reports.**
- Never select this entry when work mode is artifact.
- Discovery: for supply-chain posture mode read repository-owned scanner output first.
Otherwise use the project's own audit — `pnpm audit` / `npm audit`, `pip-audit`, `cargo audit`,
`govulncheck`. Enrich each advisory in a `mode: vuln-enrich` receipt from
`receipts/cycle-specialist-evidence.md`: provenance, affected and fixed versions, transitive path, reachability,
and runtime versus dev exposure.
Work critical and high first, so an interrupted night cleared what mattered.
- Per advisory: read what the vulnerability actually is and whether the project's usage reaches
it, move to the fixed version, adapt the code that change requires, run the item gate, commit.
- **Never downgrade to satisfy an advisory.** Where the only offered fix is an older version,
park it with the advisory link — a silent regression is not a fix.
- Never add an ignore or suppression entry, and never reach for an audit tool's `--force`.
Silencing an advisory is not clearing it.
- An advisory reachable only through a transitive dependency, or with no fixed version published,
goes to parking-lot.md with its link and severity: overrides and resolutions are owner calls.
- Record every disposition in snag-log.md so the next sweep does not re-raise a parked advisory.
- Ends when the audit reports clean, or every advisory still standing is parked with a reason.
- Verify: the item gate is green at every commit; the audit is re-run after the last fix.
```
SHA-256: 60b8fb7eb7ab7aa79997a5346d78b87686589efc4b1ea20fe9ee89ee18d860c0