This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/checkers/fixtures/confluence-doc/EXPECTED_GAP_COUNT

2 lines
2 B
Text
Raw Normal View History

feat(secrev): Plane-1 Phase 4 — plan-groomer + confluence-doc (recommend-only) (#20) * feat(secrev): plan-groomer Plane-1 Phase 4 planner (report-only) Aggregates the OTHER Plane-1 checkers' latest reports (compliance-drift, dependency-cve, doc-drift, confluence-doc) into one prioritized, deduped "groomed weekly plan" written into the mode-600 report. REPORT-ONLY per decision D3: posts NOTHING to Slack; auto-write to Notion/Jira is a later toggle (inert --notify seam). Reuses lib/sweep_substrate.sh redact(). Offline --canary asserts the groomed-plan item count (5) against a fixture report set, exercising latest-date selection, dedup, multi-source aggregation, and no-data discipline (a missing source is noted, never invented as work). shellcheck-clean (only the shared SC1091 substrate-source info, at parity with compliance-drift/dependency-cve). PROVISIONING (auto-write toggle, systemd wiring, coordinator registry) deferred — gated. * feat(secrev): confluence-doc Plane-1 Phase 4 doc-gap detector (recommend-only) Scheduled, read-only documentation gap detector. Diffs the org repo set + an optional read-only AWS inventory + the IT page-ID map (project_confluence_ migration) against Confluence and REPORTS doc gaps / stale pages / missing runbooks into the mode-600 report. RECOMMEND-ONLY per D3/D7: NEVER auto-writes Confluence; the on-demand SSH-invoked write path (incl. Mermaid edits via ~/.claude/scripts/confluence_mermaid.py) is a separate, gated provisioning path. LIVE Confluence API reads need the gated confluence-bot service-account token (D6); when creds are absent OR --no-api/--canary, the API checks are SKIPPED and noted, NEVER reported as a gap on missing data (mirrors compliance-drift's status-code-aware API-skip pattern: 200 parse, 404 real gap, else skip). Offline --canary asserts the doc-gap count (3) against a fixture (repo list + mock page-map + mock AWS inventory): a repo with no IT page, an AWS resource not in the map, and a missing required runbook page; precision non-gaps (matched repos/resources, doc-exempt repo, present required pages, skipped API) must not inflate the count. shellcheck-clean (only the shared SC1091 substrate-source info). PROVISIONING (confluence-bot account + 90-day rotation, page-1540098 live dry-run expecting 16 weweave macros, systemd wiring, coordinator registry) documented in the footer, deferred — gated. * fix(secrev): commit compliance-drift secret fixture as dotenv.fixture (canary broke on fresh clone) The compliance-drift canary's planted tracked-secret fixture was BadName_repo/.env, but the repo root .gitignore lists '.env' — so it was never committed. On a fresh clone of main the file is absent, the secrets-committed check stops firing, and the canary FAILS (expected 6, got 5). It only passed where a gitignored, untracked '.env' happened to exist locally. Verified the failure reproduces in a clean clone of origin/main (3d97139) and in a fresh worktree. Fix (in-convention, mirrors the dependency-cve .fixture-suffix trick): ship the secret as BadName_repo/dotenv.fixture (committable, not gitignored); the --canary materialization renames dotenv.fixture -> .env in its temp work area. The dotgit/ index already TRACKS .env, so git ls-files still reports it and the drift fires. Restores the documented 6/6 canary on any fresh checkout. shellcheck stays clean.
2026-06-18 16:03:37 -04:00
3