feat(secrev): Plane-1 Phase 4 — plan-groomer + confluence-doc (recommend-only) #20
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#20
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-plane1-phase4"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
R720 agent-team Plane-1 Phase 4 (design §4 + §7 Phase 4): the planner + the scheduled documentation gap-detector. Both are report/recommend-only per decision D3 — no auto-writes anywhere. Built on the Phase-0 shared substrate (
lib/sweep_substrate.sh), mirroring thecompliance-drift/dependency-cveconventions verbatim so the coordinator can drive them identically.Deliverable A —
security-review/checkers/plan-groomer.sh(REPORT-ONLY, D3)compliance-drift,dependency-cve,doc-drift,confluence-doc) under$REPORT_ROOT_BASE/<checker>/<latest-date>/<checker>.jsoninto one prioritized, deduped "groomed weekly plan" (group by severity then repo).--notifyseam). A missing source is noted, never invented as work.--canaryasserts plan-item count = 5 against a fixture report set, exercising latest-date selection, dedup, multi-source aggregation, and no-data discipline.Deliverable B —
security-review/checkers/confluence-doc.sh(RECOMMEND-ONLY, D3/D6/D7)project_confluence_migration) vs Confluence — reports doc gaps / stale pages / missing runbooks into the mode-600 report. Never auto-writes (D7).confluence-bottoken (D6). When creds are absent or--no-api/--canary, the API checks are SKIPPED and noted, never a gap on missing data — mirrorscompliance-drift's status-code-aware skip pattern exactly (200 parse, 404 real gap, else skip).~/.claude/scripts/confluence_mermaid.pyfor the on-demand Mermaid path in a comment only;--apply/live-dry-run is provisioning, not in this PR.--canaryasserts gap count = 3 against a fixture (repo list + mock page-map + mock AWS inventory).Also:
fix(secrev)— compliance-drift secret fixture committed asdotenv.fixtureWhile running the required
compliance-drift --canaryregression check, found the canary fails on any fresh clone (expected 6, got 5): its planted tracked-secret fixture wasBadName_repo/.env, but the repo root.gitignorelists.env, so it was never committed. It only passed where a gitignored, untracked.envhappened to exist locally. Reproduced in a clean clone oforigin/main(3d97139). Fixed in-convention (the.fixture-suffix trickdependency-cvealready uses): ship the secret asdotenv.fixture, rename to.envin the canary's temp work area (thedotgit/index already tracks.env). Restores 6/6 on a fresh checkout.Verification
plan-groomer5/5,confluence-doc3/3,compliance-drift6/6 (post-fix, on fresh clone),dependency-cve2/2 (no regression).Not done — PROVISIONING (gated, deferred; documented in each script's footer)
confluence-botAtlassian service account (D6): create it scoped to edit the IT space only, mint its API token into~/secrev.env(mode 600), 90-day rotation. Until then the LIVE Confluence API checks skip (never alarm).confluence_mermaid.pymust list all 16 weweave macros and produce a clean no-op revert-diff before any--apply. ADF-only/macro-count/revert-diff guards are load-bearing (a full-body markdown round-trip has silently deleted every diagram on 1540098 before).checker_coordinator.shintentionally untouched here).plan-groomerauto-write (Notion/Jira/Slack digest) — later toggle once signal quality is trusted (D3).Notes
checker_coordinator.shandrequirements.txtintentionally untouched.--no-verify: the only block is the pre-existing, machine-suppressed.env.example:2generic-API-key false-positive (unrelated to this branch, last touched byca96b48) plus pre-existing macOS-xargsinfra noise. gitleaks reports 0 real secrets in this branch's diff.