Release audit — POM 2.0.0
Date: 2026-07-12
Automated verification
npm run verify performs:
- Strict TypeScript check against real OMP packages.
- Production-code behavioral tests.
- Temporary-project runtime smoke test.
- Structural package, resource, agent-frontmatter, and theme-schema checks.
npm pack --dry-run.
Covered behaviors include stage ordering, active-run gates, evidence requirements, blocker lifecycle, traversal/symlink defense, destructive-command policy, validator behavior, native Hive translation, Swarm graph generation, ZIP member decompression, CRC validation, and malformed archive rejection.
Security posture
- Canonical paths are resolved with
realpath. - Symbolic-link escapes are rejected.
- Empty canonical artifacts are rejected.
- Manifest hashes and byte counts are remeasured.
- Recursive destructive commands against the project root are blocked by default.
- ZIP member names, methods, decompression, sizes, duplicate names, and CRC values are verified.
The command policy is a guardrail, not an operating-system sandbox. Host approvals and normal filesystem permissions remain authoritative.
Known release boundary
Bun and the omp executable are unavailable in this build environment. Therefore omp plugin doctor and a live interactive TUI smoke session were not run here. They remain mandatory host acceptance checks after installation.
npm audit currently reports moderate issues in the development/host dependency tree. The release archive does not claim a zero-vulnerability dependency graph; operators should evaluate the host’s current dependency advisories.