Skip to content

Codex task: integrate product-suite DevSecOps intelligence and release posture tracking #7

@mdheller

Description

@mdheller

Mission

Integrate global-devsecops-intelligence into the SocioProphet / SourceOS / Holmes product-suite workstream as the security, CI/CD, release posture, dependency risk, and agent-PR intelligence lane.

This issue is designed for a Codex agent. Keep the change bounded and open a PR.

Active suite surfaces

Track posture for:

  • SocioProphet/prophet-cli
  • SourceOS-Linux/sourceos-model-carry
  • SocioProphet/holmes
  • SocioProphet/functional-model-surfaces
  • SocioProphet/prophet-platform
  • SocioProphet/agentplane
  • SocioProphet/sociosphere
  • SocioProphet/model-governance-ledger
  • SocioProphet/model-router
  • SocioProphet/guardrail-fabric
  • SocioProphet/agent-registry
  • SocioProphet/sherlock-search
  • SocioProphet/prophet-core-query
  • SocioProphet/prophet-workspace
  • SocioProphet/socioprophet

Scope

Add docs/examples/validation for a suite DevSecOps intelligence record that captures:

  • repository id and role
  • active issue/PR refs
  • CI status expectation
  • release chain status: build, test, validate, dist, checksums, SBOM, attestation, Homebrew formula
  • dependency/security scan posture
  • agent lane: Copilot or Codex
  • merge readiness gate
  • evidence/readout links

Suggested files

  • docs/SUITE_DEVSECOPS_INTELLIGENCE.md
  • examples/suite-devsecops-record.example.json
  • examples/agent-pr-risk.example.json
  • tools/validate_examples.py
  • Makefile target validate

Acceptance criteria

  • make validate validates examples.
  • Examples include the first-wave repos: prophet-cli, sourceos-model-carry, holmes, and functional-model-surfaces.
  • Docs define Copilot vs Codex risk/review expectations.
  • Docs define a merge readiness checklist for agent-authored PRs.
  • No external scanning service integration is required yet; this is the first contract/fixture pass.

Do not

  • Do not store secrets or tokens.
  • Do not auto-merge agent PRs.
  • Do not vendor scanner binaries or security datasets.
  • Do not claim scan results unless produced by a deterministic fixture or real local command.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions