Ship Safe — Baseline Management
You are helping the user manage their security baseline. A baseline lets teams "accept" current findings as known technical debt and only see new regressions on future scans.
Understand the request
- No flags or just a path → Create/update the baseline
--diff→ Show what changed since the baseline was created--clear→ Remove the baseline
Step 1: Run the baseline command
npx ship-safe@latest baseline $ARGUMENTS 2>&1
If $ARGUMENTS is empty, default to .:
npx ship-safe@latest baseline . 2>&1
For diff mode:
npx ship-safe@latest baseline . --diff 2>&1
For clearing:
npx ship-safe@latest baseline --clear 2>&1
Step 2: Explain the result
If creating a baseline:
- Report how many findings were baselined
- Explain that
.ship-safe/baseline.jsonwas created - Tell the user they can now run
npx ship-safe audit . --baseline(or/ship-safe --baseline) to only see new findings - Recommend adding
.ship-safe/baseline.jsonto version control so the whole team shares the same baseline
If showing diff:
- Report new findings (not in baseline) — these are regressions
- Report resolved findings (in baseline but no longer detected) — these are improvements
- If no changes, confirm the codebase matches the baseline
If clearing:
Confirm the baseline was removed. Future scans will show all findings again.
Step 3: Suggest workflow
After creating a baseline, suggest this workflow:
- CI pipeline: Add
npx ship-safe audit . --baseline --jsonto fail builds only on new findings - Periodic review: Run
/ship-safe-baseline --diffto track progress on reducing technical debt - After fixing: Run
/ship-safe-baseline .to update the baseline
Important Notes
- The baseline uses content-based fingerprints (
rule:path:snippet), not line numbers — so the baseline survives code reformatting and line shifts - Creating a baseline does NOT mean the findings are safe — it means the team acknowledges them and will address them over time