secrev/Plane-1: Phase 0 shared substrate + compliance-drift checker #14

Merged
amoussa1229 merged 2 commits from feature/agent-team-plane1-phase0 into main 2026-06-18 18:09:35 +00:00
amoussa1229 commented 2026-06-18 18:07:30 +00:00 (Migrated from github.com)

What

Plane-1 foundation, built by a canary-gated workflow (extract → prove secrev unchanged → checker → review).

Phase 0 — shared sweep substrate (the foundation both planes' scheduled side reuses)

  • security-review/lib/sweep_substrate.sh (new): discovery / mirror / budget-ledger / rotation / Slack-ALARM+redaction / canary as sourceable bash functions.
  • nightly_sweep.sh (415→362): now sources the substrate instead of inline copies.
  • Zero behavior change proven: shellcheck -x clean, offline two-tier dry-run byte-identical before/after (two scenarios), token discipline preserved (read-only PAT, REST-only, no gh CLI, origin scrubbed), review.sh untouched. Revert point: 73e35f3.

Phase 1 — compliance-drift checker (Tier-1, read-only, ALARM-only)

  • security-review/checkers/compliance-drift.sh + planted-drift fixtures.
  • Reuses the substrate (scans existing mirrors, no re-clone). Checklist grounded in the handbook/github-standards: kebab repo name, README, CI/CD, Dependabot config + alerts, tracked-.env secrets, branch protection, merge settings. Handbook exceptions (docs-only, compliance-exempt) honored. Mode-600 reports, ALARM-only (clean = silent). Canary asserts the 6 planted drifts.

Review (workflow)

2 dimensions (secrev-intact + checker-quality) → proof-or-kill verifier. No BLOCK. The secrev-intact pass was clean. 2 checker findings, both fixed (false-alarm hygiene, per feedback_cloudwatch_alarms):

  • branch-protection + dependabot are now status-code-aware — only a real 404 is drift; a transient/forbidden API failure is skipped with no alarm (the -f+-w idiom was misreading real 404s as skips).
  • secrets-committed fires only on secret-shaped values (secret-ish key name or ≥20-char value), not benign config like PORT=3000.

Not in this PR (gated / later)

  • Provisioning: rsync the lib/+checkers/ to the R720, a live org-discovery dry-run (needs GH_TOKEN), and wiring compliance-drift into the systemd schedule — all deploy-gated.
  • Coordinator (shared budget/dedup) + the next checkers (dependency-cve, doc-drift) — Plane-1 Phases 2+.

Note

The checkers/fixtures/ intentionally contain fake secret-shaped strings (planted test data) so the checker can be smoke-tested offline; they are not real credentials.

## What Plane-1 foundation, built by a canary-gated workflow (extract → prove secrev unchanged → checker → review). ### Phase 0 — shared sweep substrate (the foundation both planes' scheduled side reuses) - `security-review/lib/sweep_substrate.sh` (new): discovery / mirror / budget-ledger / rotation / Slack-ALARM+redaction / canary as sourceable bash functions. - `nightly_sweep.sh` (415→362): now sources the substrate instead of inline copies. - **Zero behavior change proven:** shellcheck `-x` clean, offline two-tier dry-run **byte-identical** before/after (two scenarios), token discipline preserved (read-only PAT, REST-only, no `gh` CLI, origin scrubbed), `review.sh` untouched. Revert point: `73e35f3`. ### Phase 1 — compliance-drift checker (Tier-1, read-only, ALARM-only) - `security-review/checkers/compliance-drift.sh` + planted-drift fixtures. - Reuses the substrate (scans **existing** mirrors, no re-clone). Checklist grounded in the handbook/github-standards: kebab repo name, README, CI/CD, Dependabot config + alerts, tracked-`.env` secrets, branch protection, merge settings. Handbook exceptions (docs-only, compliance-exempt) honored. Mode-600 reports, ALARM-only (clean = silent). Canary asserts the 6 planted drifts. ## Review (workflow) 2 dimensions (secrev-intact + checker-quality) → proof-or-kill verifier. **No BLOCK.** The secrev-intact pass was clean. 2 checker findings, **both fixed** (false-alarm hygiene, per `feedback_cloudwatch_alarms`): - branch-protection + dependabot are now **status-code-aware** — only a real `404` is drift; a transient/forbidden API failure is skipped with no alarm (the `-f`+`-w` idiom was misreading real 404s as skips). - `secrets-committed` fires only on **secret-shaped** values (secret-ish key name or ≥20-char value), not benign config like `PORT=3000`. ## Not in this PR (gated / later) - **Provisioning**: rsync the `lib/`+`checkers/` to the R720, a live org-discovery dry-run (needs `GH_TOKEN`), and wiring `compliance-drift` into the systemd schedule — all deploy-gated. - Coordinator (shared budget/dedup) + the next checkers (dependency-cve, doc-drift) — Plane-1 Phases 2+. ## Note The `checkers/fixtures/` intentionally contain fake secret-shaped strings (planted test data) so the checker can be smoke-tested offline; they are not real credentials.
This repo is archived. You cannot comment on pull requests.
No description provided.