This website requires JavaScript.
Explore
Help
Sign in
adam
/
orchestrator
Archived
Watch
1
Star
0
Fork
You've already forked orchestrator
0
Code
Issues
Pull requests
Projects
Releases
Packages
Wiki
Activity
Actions
This repository has been archived on
2026-08-04
. You can view files and clone it, but cannot push or open issues or pull requests.
891df447bb
orchestrator
/
security-review
/
checkers
/
fixtures
/
doc-drift
/
EXPECTED_DRIFT_COUNT
2 lines
2 B
Text
Raw
Normal View
History
Unescape
Escape
feat(secrev): doc-drift Plane-1 Tier-1 checker (UNGATED) Third Plane-1 checker on the Phase-0 shared substrate, mirroring compliance-drift.sh / dependency-cve.sh conventions verbatim (set -euo pipefail, sourced substrate, --canary/--dry-run/--no-api/--refresh/--targets, mode-600 reports under $REPORT_ROOT/doc-drift/<UTC-date>/, ALARM-only, finding.schema spirit JSON, exit 0/2/3, dotgit->.git fixture trick). Detects documentation drift deterministically (design §4 doc-drift row): - readme-omits-component: README omits an existing major component in the tree (top-level service dir, SAM/CDK stack, Lambda handler dir, openapi/docs spec) - readme-stale-vs-code: README last-touch far older than newest code commit (two-factor: >=DOC_DRIFT_STALE_DAYS AND >=DOC_DRIFT_STALE_COMMITS) A repo with NO README is SKIPPED (compliance-drift owns readme-present; no double-flag). Future Gemini large-context judge (§4) is an inert stub (maybe_judge), off in canary/dry-run/offline. Planted-drift fixture corpus + EXPECTED_DRIFT_COUNT=4, canary-asserted (exit 3 on miss). shellcheck -x clean (only accepted SC1091 source-line info). Does NOT touch checker_coordinator.sh, requirements.txt, or aws-posture. Wiring/systemd is gated (PROVISIONING footer). Design refs §4, §7 Phase 3.
2026-06-18 15:55:18 -04:00
4
Reference in a new issue
Copy permalink