Je termine la série par l'opérationnel, comment lancer le workflow au quotidien. Un plan.md persistant, des hooks pre-commit comme garde-fous, un pipeline CI multi-niveaux, et un audit simple pour reprendre un repo existant.
Audit
I wrap up the series with the operational side: how to launch the workflow daily. A persistent plan.md, pre-commit hooks as guardrails, a multi-level CI pipeline, and a simple audit to adopt an existing repo.
La v1.1.0 de pi-secured-setup passe au OWASP AI Agent Security Cheat Sheet. Audit log chaîné par HMAC, détection d'exfiltration bash, rate limiting, scanner d'injection prompt, et 14 advisories Dependabot fermés.
pi-secured-setup v1.1.0 maps against the OWASP AI Agent Security Cheat Sheet. HMAC-chained audit log, bash exfiltration detection, rate limiting, prompt injection scanner, and 14 Dependabot advisories closed.
A test suite can show good coverage and miss an obvious bug. To measure real quality, I look at four complementary axes, with a simple audit to apply to an existing project.
Une suite de tests peut afficher une bonne couverture et rater un bug évident. Pour mesurer la qualité réelle, je regarde quatre axes complémentaires, avec un audit simple à appliquer sur un projet existant.