# supply_chain - Agent Ruleset

> **Skills**: on-demand rulesets live in [`../../skills/`](../../skills/); the full
> list is the SKILLS CATALOGUE in the [root AGENTS.md](../../AGENTS.md). The table
> below is generated by `sync.sh` - never hand-edit it.
>
> Scope covers `scanners/supply_chain_scan/`, `scanners/supply_chain_common/`
> (shared logic), and `scanners/supply_chain_analyzer/`.

### Auto-invoke Skills

When performing these actions, ALWAYS invoke the corresponding skill FIRST:

| Action | Skill |
| ------ | ----- |
| Editing the supply-chain scanner or its offline OSV database handling | `supply-chain-scan` |

---

## CRITICAL RULES - NON-NEGOTIABLE

<!-- Add a rule only if an agent breaks it while working elsewhere AND cannot
     discover it from the file being edited. See the root AGENTS.md for repo-wide rules. -->

- **NEVER** rely on `supply_chain_common` being importable in a spawned scan
  container by default. It is **not baked** into the analyzer image (only the
  entrypoint is COPYed); every caller must **bind-mount** it at spawn, or the run
  dies with `ModuleNotFoundError: No module named 'supply_chain_common'` (see
  [redamon.sh:2349](../../redamon.sh#L2349)).

---

## TECH STACK

Python 3.11 · offline OSV + GuardDog + retire.js + trufflehog, a 3-layer
malicious/vulnerable package detector. `scanners/supply_chain_common/` is the
shared library (bind-mounted, not baked); `scanners/supply_chain_analyzer/`
dispatches; the scan
runs under the `root-agent` test section (image `redamon-agent`).

## PROJECT STRUCTURE

```
../supply_chain_common/    shared: osv_db_sync.py (offline DB), osv_runner.py, guarddog_runner.py,
                           deep_recovery.py (soft-error markers), analyzer_dispatch.py
../supply_chain_analyzer/  entrypoint dispatch (image bakes only the entrypoint)
main.py  supply_chain_runner.py  deep_analysis.py  repo_clone.py   scan entry + orchestration (this dir)
```

## COMMANDS

```bash
./redamon.sh test unit                    # supply_chain_* run under the root-agent section
./redamon.sh supply-chain-sync <ecos>     # bootstrap the offline OSV DB volume (separate from any scan)
```

## QA CHECKLIST

- [ ] `./redamon.sh test unit` green (root-agent section).
- [ ] New or changed behaviour is covered by a test (see the `redamon-testing` skill for where + how).
- [ ] Any new spawn bind-mounts `supply_chain_common` (it is not baked into the image).
- [ ] Invalid analyzer/GuardDog output does not erase existing soft-error markers.
