From 95e481890aa7e2e4f7521c0a3440e0057cbeae9f Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 18 Jun 2026 16:31:03 -0400 Subject: [PATCH] feat(secrev): wire full Plane-1 roster into checker coordinator + fix fixture SAM (#22) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * feat(secrev): wire full Plane-1 roster into the checker coordinator registry Register doc-drift, aws-posture, plan-groomer, confluence-doc (weekly cadence) alongside compliance-drift + dependency-cve (nightly). The coordinator canary suite now runs all 6 roles' canaries (all PASS) under the one shared budget + versioned rotation/coverage state; --squeeze-dry-run still proves defer-not-drop + COVERAGE alarm. Central integration after the parallel Phase-3/4 PRs landed. * fix(secrev): valid SAM in doc-drift fixture templates (cfn-lint E0001) The doc-drift sample-stack fixtures declared AWS::Serverless::Function with no Properties; cfn-lint's SAM transform errored (HIGH). Added minimal valid Properties (Handler/Runtime/InlineCode). Pre-existing on main — #19 pushed with --no-verify (xargs overflow) and CI runs no cfn-lint, so it slipped through. doc-drift still detects the stack (keys on template presence). --- security-review/checker_coordinator.sh | 7 ++++++- .../checkers/fixtures/doc-drift/clean-repo/template.yaml | 6 ++++++ .../fixtures/doc-drift/drift-omits-repo/template.yaml | 6 ++++++ 3 files changed, 18 insertions(+), 1 deletion(-) diff --git a/security-review/checker_coordinator.sh b/security-review/checker_coordinator.sh index 0d5fcb5..36acb68 100755 --- a/security-review/checker_coordinator.sh +++ b/security-review/checker_coordinator.sh @@ -8,7 +8,8 @@ # budget-squeeze dry-run to prove deferral-not-drop + COVERAGE ALARM"). # # WHAT IT DOES: -# Orchestrates the Plane-1 Tier-1 checkers (compliance-drift, dependency-cve) under ONE shared +# Orchestrates the Plane-1 checkers (compliance-drift, dependency-cve, doc-drift, aws-posture, +# plan-groomer, confluence-doc) under ONE shared # budget + versioned rotation/coverage state. Nightly it (mirrors nightly_sweep + §5): # 1) loads the shared budget ledger + the versioned rotation/coverage state (integrity-checked) # 2) runs the CANARY SUITE FIRST — each role's checker with --canary; a miss is a COMPLACENCY @@ -128,6 +129,10 @@ fi declare -a ROLES=( "compliance-drift|$CHECKERS_DIR/compliance-drift.sh|0.00|1" "dependency-cve|$CHECKERS_DIR/dependency-cve.sh|0.00|1" + "doc-drift|$CHECKERS_DIR/doc-drift.sh|0.00|7" + "aws-posture|$CHECKERS_DIR/aws-posture.sh|0.00|7" + "plan-groomer|$CHECKERS_DIR/plan-groomer.sh|0.00|7" + "confluence-doc|$CHECKERS_DIR/confluence-doc.sh|0.00|7" ) role_field() { echo "$1" | cut -d'|' -f"$2"; } diff --git a/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml b/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml index 513273c..549a326 100644 --- a/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml +++ b/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml @@ -3,3 +3,9 @@ Transform: AWS::Serverless-2016-10-31 Resources: IngestFn: Type: AWS::Serverless::Function + Properties: + Handler: app.handler + Runtime: python3.12 + InlineCode: | + def handler(event, context): + return {"statusCode": 200} diff --git a/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml b/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml index 9a24dce..3f49180 100644 --- a/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml +++ b/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml @@ -3,3 +3,9 @@ Transform: AWS::Serverless-2016-10-31 Resources: ChargeFn: Type: AWS::Serverless::Function + Properties: + Handler: app.handler + Runtime: python3.12 + InlineCode: | + def handler(event, context): + return {"statusCode": 200}