This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/checkers
Adam Moussa 19a57408d2 feat(secrev): plan-groomer Plane-1 Phase 4 planner (report-only)
Aggregates the OTHER Plane-1 checkers' latest reports (compliance-drift,
dependency-cve, doc-drift, confluence-doc) into one prioritized, deduped
"groomed weekly plan" written into the mode-600 report. REPORT-ONLY per
decision D3: posts NOTHING to Slack; auto-write to Notion/Jira is a later
toggle (inert --notify seam). Reuses lib/sweep_substrate.sh redact().

Offline --canary asserts the groomed-plan item count (5) against a fixture
report set, exercising latest-date selection, dedup, multi-source aggregation,
and no-data discipline (a missing source is noted, never invented as work).
shellcheck-clean (only the shared SC1091 substrate-source info, at parity with
compliance-drift/dependency-cve). PROVISIONING (auto-write toggle, systemd
wiring, coordinator registry) deferred — gated.
2026-06-18 15:51:45 -04:00
..
fixtures feat(secrev): plan-groomer Plane-1 Phase 4 planner (report-only) 2026-06-18 15:51:45 -04:00
compliance-drift.sh feat(secrev): compliance-drift Plane-1 Tier-1 checker (ALARM-only) 2026-06-18 14:06:31 -04:00
dependency-cve.sh feat(secrev): Plane-1 Phase 2 — coordinator + dependency-cve checker (#16) 2026-06-18 15:08:58 -04:00
plan-groomer.sh feat(secrev): plan-groomer Plane-1 Phase 4 planner (report-only) 2026-06-18 15:51:45 -04:00