This website requires JavaScript.
Explore
Help
Sign in
adam
/
orchestrator
Archived
Watch
1
Star
0
Fork
You've already forked orchestrator
0
Code
Issues
Pull requests
Projects
Releases
Packages
Wiki
Activity
Actions
This repository has been archived on
2026-08-04
. You can view files and clone it, but cannot push or open issues or pull requests.
332652257b
orchestrator
/
security-review
/
checkers
/
fixtures
/
compliance-drift
/
EXPECTED_DRIFT_COUNT
2 lines
2 B
Text
Raw
Normal View
History
Unescape
Escape
feat(secrev): compliance-drift Plane-1 Tier-1 checker (ALARM-only) Read-only org compliance checker on the shared substrate (no re-clone; scans existing mirrors). Checklist grounded in handbook/github-standards: kebab repo name, README, CI/CD, Dependabot config+alerts, tracked-.env secrets, branch protection, merge settings; handbook exceptions (docs-only, compliance-exempt) honored. Mode-600 reports, ALARM-only (clean=silent). Includes planted-drift canary (asserts 6). Review fixes folded in: branch-protection + dependabot are status-code-aware (only a real 404 is drift; transient API failure -> skip, no false alarm); secrets-committed fires only on secret-shaped values (not benign config). NOT scheduled (provisioning gated).
2026-06-18 14:06:31 -04:00
6
Reference in a new issue
Copy permalink