Skip to content

Align CloudSec and MailSec CLI contracts and onboarding - #408

Merged
maximelb merged 2 commits into
masterfrom
audit/security-products-cli-20260930
Sep 30, 2026
Merged

maximelb merged 2 commits into
masterfrom
audit/security-products-cli-20260930

Conversation

@maximelb

@maximelb maximelb commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Cloud Security, Code Security and Email Security have expanded beyond several SDK/CLI bindings and their onboarding help. This aligns the client with the current public API and gives new users an explicit path from installation and provider setup to their first results.

  • Add Microsoft 365 certificate generation, image-lineage filters and acknowledged filter receipts, CAASM kind/source/posture selectors, bounded resumable CSV exports, and optional base commits for GitLab/Bitbucket PR checks.
  • Add MailSec onboarding substitutions, coverage time windows, live/backfill selection and revision limits. Reject unsupported similar-message paging instead of silently repeating the same candidate set.
  • Add built-in product guides and cheatsheets, missing CloudSec Hive names, and a security-product SDK guide. Correct permissions, parsed-message evidence, AutoFix lockfiles, provider capabilities and scanner-access help.

Installation uses the standard released limacharlie package for CloudSec, CodeSec and MailSec. The local scanner default is updated to 0.24.0; pulling it still requires registry access, and the CLI explains accessible-image/binary alternatives. This change does not publish the scanner or enable backend capabilities.

Validation: the complete CI-equivalent pytest tests/unit/ tests/microbenchmarks/ --benchmark-disable suite passed: 4662 passed, with five pre-existing platform/docstring skips. Product help examples and SDK example signatures were checked, and git diff --check passed. New regression tests cover query/body serialization, tri-state and empty selectors, opaque cursors, certificate output, provider-specific PR requirements and early refusals. No production changes or customer-provider operations were performed.

Companion customer-facing onboarding/reference update: documentation #460.

Companion MCP workflow/onboarding review: lc-mcp-server #75.

Fill missing certificate onboarding, lineage and asset selectors, resumable exports, provider PR-check options, MailSec setup/time/lane/revision parameters. Reject unsupported similar-message pagination and add product help and SDK guides.
lcbill
lcbill previously approved these changes Sep 30, 2026
@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

@limacharlie-refractionpoint

limacharlie-refractionpoint Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/python-limacharlie e40d088…efed5da — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

@maximelb

Copy link
Copy Markdown
Contributor Author

Adversarial self-review completed against the current gateway and service contracts:

  • New selectors preserve existing request shapes, including repeated values, explicit false/empty values, opaque cursors and organization scoping. Image lineage selectors require the exact applied-filter receipt rather than accepting silently widened results.
  • Microsoft 365 certificate output contains only the returned public certificate. Replacement is explicit and its authentication interruption is documented.
  • Existing positional PR-check calls remain compatible; base commits are optional only for the appropriate providers. Unsupported MailSec similar paging fails before a request.
  • CLI help examples and SDK call signatures were checked. The complete local suite and all remote CI checks pass. No open issues were found in this review.

The /lc-review request received no substantive AI review response within ten minutes. The automatic approval with an empty body preceded that request; the Code Security scan reports no new code findings but is a separate check. Neither is treated as the requested AI review. This PR remains open and unmerged.

@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

@maximelb

Copy link
Copy Markdown
Contributor Author

Release guidance updated per the imminent-release assumption: removed development-only installs, source pins and repeated CLI-version notices. Customer docs and MCP errors now use the standard released limacharlie package.

All three updated PRs are green. Local checks passed: strict MkDocs, 215 documentation tests, Markdown lint, rendered numbering checks and the affected CloudSec MCP tests. Adversarial review found no open issues. The renewed /lc-review requests received no written feedback within ten minutes; empty automatic approvals are not counted as written reviews.

@maximelb
maximelb merged commit e7708e0 into master Sep 30, 2026
7 checks passed
@maximelb
maximelb deleted the audit/security-products-cli-20260930 branch September 30, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants