working POC
working change handlers:
- Create
- Modify
Remediation actions
- POSIX
- set file to write-only
Ruleset for Semgrep exists in remote registry, currently supports Java/Unix shell
todos:
implement webhook handler implement timestamp/result based shell subprocess termination properly CLI-ify app