23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
229 lines
9.8 KiB
JavaScript
Executable File
229 lines
9.8 KiB
JavaScript
Executable File
#!/usr/bin/env node
|
||
// oia-audit.mjs — composite Phase-2 worker (ADR-150).
|
||
//
|
||
// Bundles three MetaHarness static-analysis surfaces into one timestamped
|
||
// audit record:
|
||
// - harness oia-manifest (Open Infrastructure Architecture L1-L9 alignment)
|
||
// - harness threat-model (categorized MCP-surface threat report)
|
||
// - harness mcp-scan (per-server/tool policy + permissions + deps)
|
||
//
|
||
// The combined record is stored in the `metaharness-audit` memory
|
||
// namespace, keyed by ISO timestamp. Designed to be invoked on a cron
|
||
// schedule (e.g. weekly) so audit drift is visible over time.
|
||
//
|
||
// USAGE
|
||
// node scripts/oia-audit.mjs # run + store
|
||
// node scripts/oia-audit.mjs --path <dir> # audit specific dir
|
||
// node scripts/oia-audit.mjs --dry-run # don't write to memory
|
||
// node scripts/oia-audit.mjs --alert-on-worst high
|
||
// # exit 1 if threat-model worst >= high
|
||
// node scripts/oia-audit.mjs --format json
|
||
//
|
||
// EXIT CODES
|
||
// 0 audit OK (or degraded)
|
||
// 1 --alert-on-worst threshold exceeded
|
||
// 2 config error or audit failure
|
||
|
||
import { spawnSync } from 'node:child_process';
|
||
// iter 63 — SEVERITY_RANK + rankSeverity consolidated to _harness.mjs
|
||
// (was local in iter 62; now shared with audit-trend + mcp-scan).
|
||
import { runHarness, runMetaharness, runHarnessAsync, runMetaharnessAsync, emitDegradedJsonAndExit, parseMcpScanText, SEVERITY_RANK, rankSeverity } from './_harness.mjs';
|
||
|
||
// iter 63 — SEVERITY_RANK + rankSeverity moved to _harness.mjs (single
|
||
// source of truth). The local copy from iter 62 is gone; the imports
|
||
// at the top of this file provide the same names.
|
||
const NS = process.env.OIA_AUDIT_NAMESPACE || 'metaharness-audit';
|
||
const CLI_PKG = process.env.CLI_CORE === '1'
|
||
? '@claude-flow/cli-core@alpha'
|
||
: '@claude-flow/cli@latest';
|
||
|
||
const ARGS = (() => {
|
||
const a = { path: '.', format: 'json', dryRun: false, alertWorst: null };
|
||
for (let i = 2; i < process.argv.length; i++) {
|
||
const v = process.argv[i];
|
||
if (v === '--path') a.path = process.argv[++i];
|
||
else if (v === '--dry-run') a.dryRun = true;
|
||
else if (v === '--alert-on-worst') a.alertWorst = String(process.argv[++i] || '').toLowerCase();
|
||
else if (v === '--format') a.format = process.argv[++i];
|
||
}
|
||
return a;
|
||
})();
|
||
|
||
// iter 47 — the `harness` and `metaharness` CLIs both have `score` /
|
||
// `genome` subcommands but with DIFFERENT output schemas. For the
|
||
// fingerprint to be consumable by _similarity.mjs (which expects the
|
||
// metaharness CLI shape: harnessFit/compileConfidence/agent_topology),
|
||
// we need to dispatch to runMetaharness for score+genome, not runHarness.
|
||
// iter 56 — annotated runOne result is identical for sync/async paths.
|
||
function annotateOne(r, label) {
|
||
let json = r.json;
|
||
if (label === 'mcp-scan' && !json && !r.degraded && r.stdout) {
|
||
const parsed = parseMcpScanText(r.stdout);
|
||
json = { findings: parsed.findings, summary: parsed.summary, rawStdout: r.stdout.slice(0, 400) };
|
||
}
|
||
return {
|
||
label,
|
||
exitCode: r.exitCode,
|
||
degraded: r.degraded,
|
||
reason: r.degraded ? r.reason : null,
|
||
json,
|
||
durationMs: r.durationMs,
|
||
stderrTail: r.degraded ? (r.stderr || '').slice(-200) : null,
|
||
};
|
||
}
|
||
|
||
function runOne(args, label, engine = 'harness') {
|
||
const r = engine === 'metaharness' ? runMetaharness(args) : runHarness(args);
|
||
return annotateOne(r, label);
|
||
}
|
||
|
||
// iter 56 — parallel variant. The composite audit's 5 subprocess calls
|
||
// are mutually independent (each scans the same path read-only), so
|
||
// they can run concurrently. Worst-case wall-clock drops from
|
||
// 5×DEFAULT_TIMEOUT_MS (sequential) to 1×DEFAULT_TIMEOUT_MS (parallel)
|
||
// — the iter-55-flagged gap (oia-audit timeout under unreachable
|
||
// registry) is closed by this.
|
||
async function runAllParallel(path) {
|
||
const tasks = [
|
||
runHarnessAsync(['oia-manifest', path]).then((r) => ['oiaManifest', annotateOne(r, 'oia-manifest')]),
|
||
runHarnessAsync(['threat-model', path]).then((r) => ['threatModel', annotateOne(r, 'threat-model')]),
|
||
runHarnessAsync(['mcp-scan', path]).then((r) => ['mcpScan', annotateOne(r, 'mcp-scan')]),
|
||
runMetaharnessAsync(['score', path]).then((r) => ['score', annotateOne(r, 'score')]),
|
||
runMetaharnessAsync(['genome', path]).then((r) => ['genome', annotateOne(r, 'genome')]),
|
||
];
|
||
const results = await Promise.all(tasks);
|
||
return Object.fromEntries(results);
|
||
}
|
||
|
||
function persist(payload) {
|
||
const key = `audit-${new Date().toISOString().replace(/[:.]/g, '-')}`;
|
||
const r = spawnSync('npx', [
|
||
CLI_PKG, 'memory', 'store',
|
||
'--namespace', NS,
|
||
'--key', key,
|
||
'--value', JSON.stringify(payload),
|
||
], { stdio: ['ignore', 'pipe', 'pipe'], encoding: 'utf-8', shell: process.platform === 'win32' });
|
||
return {
|
||
ok: r.status === 0,
|
||
namespace: NS,
|
||
key,
|
||
error: r.status === 0 ? null : (r.stderr || '').slice(0, 200),
|
||
};
|
||
}
|
||
|
||
async function main() {
|
||
if (ARGS.alertWorst !== null && !SEVERITY_RANK.hasOwnProperty(ARGS.alertWorst)) {
|
||
console.error(`oia-audit: --alert-on-worst must be one of clean|low|medium|high; got ${ARGS.alertWorst}`);
|
||
process.exit(2);
|
||
}
|
||
|
||
const startedAt = new Date().toISOString();
|
||
const wallStart = Date.now();
|
||
// iter 56 — run the 5 sub-audits in parallel (was sequential pre-iter-56).
|
||
// Worst-case wall-clock improves from 5×TIMEOUT to 1×TIMEOUT in the
|
||
// unreachable-registry case; the happy path improves from sum-of-durations
|
||
// to max-of-durations (typically ~2-4× faster).
|
||
const all = await runAllParallel(ARGS.path);
|
||
const wallMs = Date.now() - wallStart;
|
||
const { oiaManifest: oia, threatModel: tm, mcpScan: mcp, score, genome } = all;
|
||
|
||
// If all FIVE say "metaharness not available", surface the degraded
|
||
// payload exactly once and exit 0 (architectural constraint #3).
|
||
if (oia.degraded && tm.degraded && mcp.degraded && score.degraded && genome.degraded) {
|
||
emitDegradedJsonAndExit('metaharness-not-available');
|
||
return;
|
||
}
|
||
|
||
// Aggregate the worst-severity signal across mcp-scan + threat-model.
|
||
// iter 62 — safe lookup using `?? 0` so unknown severities don't
|
||
// silently bump composite via NaN-comparison (was: `acc | undefined`
|
||
// → reduce never updated). Now any [WARN]/[CRITICAL]/[ERROR] finding
|
||
// correctly elevates composite worst.
|
||
const tmWorst = String(tm.json?.worst || 'clean').toLowerCase();
|
||
const mcpFindings = Array.isArray(mcp.json?.findings) ? mcp.json.findings : [];
|
||
// iter 63 — rankSeverity() from _harness.mjs handles unknown-severity
|
||
// safely (returns 0 instead of undefined) so the reduce never sees NaN.
|
||
const mcpWorst = mcpFindings.reduce((acc, f) => {
|
||
const s = String(f.severity || 'low').toLowerCase();
|
||
return rankSeverity(s) > rankSeverity(acc) ? s : acc;
|
||
}, 'clean');
|
||
const compositeWorst = rankSeverity(tmWorst) > rankSeverity(mcpWorst) ? tmWorst : mcpWorst;
|
||
|
||
let alertTriggered = false;
|
||
let alertReason = null;
|
||
if (ARGS.alertWorst !== null) {
|
||
const threshold = rankSeverity(ARGS.alertWorst);
|
||
const compositeRank = rankSeverity(compositeWorst);
|
||
if (compositeRank >= threshold && threshold > 0) {
|
||
alertTriggered = true;
|
||
alertReason = `composite worst=${compositeWorst} ≥ ${ARGS.alertWorst}`;
|
||
}
|
||
}
|
||
|
||
// iter 59 — surface parallelization metrics. wallMs is the actual
|
||
// time the 5 subprocess race took (max of components); the sum of
|
||
// component.durationMs is what a SERIAL implementation would have
|
||
// taken. A future smoke gate compares them to catch silent
|
||
// serialization regression.
|
||
const sumComponentMs = Object.values(all).reduce(
|
||
(a, c) => a + (c?.durationMs ?? 0), 0);
|
||
const payload = {
|
||
path: ARGS.path,
|
||
startedAt,
|
||
finishedAt: new Date().toISOString(),
|
||
timing: {
|
||
wallMs,
|
||
sumComponentMs,
|
||
parallelSpeedup: sumComponentMs > 0
|
||
? Math.round((sumComponentMs / Math.max(wallMs, 1)) * 100) / 100 : 0,
|
||
},
|
||
composite: { worst: compositeWorst, threatModelWorst: tmWorst, mcpScanWorst: mcpWorst },
|
||
components: { oiaManifest: oia, threatModel: tm, mcpScan: mcp, score, genome },
|
||
// iter 38 — denormalized harness fingerprint for cheap similarity().
|
||
// Mirrors the shape `_similarity.mjs::similarity()` expects so
|
||
// audit-trend can call it without reshuffling components.
|
||
fingerprint: {
|
||
score: score?.json && !score.degraded ? score.json : null,
|
||
genome: genome?.json && !genome.degraded ? genome.json : null,
|
||
},
|
||
alert: ARGS.alertWorst !== null ? {
|
||
threshold: ARGS.alertWorst,
|
||
triggered: alertTriggered,
|
||
reason: alertReason || `composite worst=${compositeWorst} < ${ARGS.alertWorst} — OK`,
|
||
} : null,
|
||
persisted: null,
|
||
};
|
||
|
||
if (!ARGS.dryRun) {
|
||
payload.persisted = persist(payload);
|
||
}
|
||
|
||
if (ARGS.format === 'json') {
|
||
console.log(JSON.stringify(payload, null, 2));
|
||
} else {
|
||
console.log(`# oia-audit — ${ARGS.path}`);
|
||
console.log('');
|
||
console.log(`| Component | Exit | Degraded | Duration |`);
|
||
console.log(`|---|---:|:---:|---:|`);
|
||
console.log(`| oia-manifest | ${oia.exitCode} | ${oia.degraded ? '⚠' : '✓'} | ${oia.durationMs}ms |`);
|
||
console.log(`| threat-model | ${tm.exitCode} | ${tm.degraded ? '⚠' : '✓'} | ${tm.durationMs}ms |`);
|
||
console.log(`| mcp-scan | ${mcp.exitCode} | ${mcp.degraded ? '⚠' : '✓'} | ${mcp.durationMs}ms |`);
|
||
console.log('');
|
||
console.log(`Composite worst severity: **${compositeWorst}** (tm=${tmWorst}, mcp=${mcpWorst})`);
|
||
if (payload.persisted) {
|
||
console.log(`Persisted: ${payload.persisted.ok ? `${payload.persisted.namespace}:${payload.persisted.key}` : `FAILED: ${payload.persisted.error}`}`);
|
||
}
|
||
if (payload.alert) {
|
||
console.log('');
|
||
console.log(payload.alert.triggered ? `⚠ **ALERT**: ${payload.alert.reason}` : `✓ ${payload.alert.reason}`);
|
||
}
|
||
}
|
||
|
||
if (alertTriggered) process.exit(1);
|
||
}
|
||
|
||
main().catch((e) => {
|
||
console.error('oia-audit crashed:', e?.message ?? e);
|
||
process.exit(2);
|
||
});
|