This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/checkers/fixtures/doc-drift/clean-repo
Adam Moussa 95e481890a
feat(secrev): wire full Plane-1 roster into checker coordinator + fix fixture SAM (#22)
* feat(secrev): wire full Plane-1 roster into the checker coordinator registry

Register doc-drift, aws-posture, plan-groomer, confluence-doc (weekly cadence)
alongside compliance-drift + dependency-cve (nightly). The coordinator canary
suite now runs all 6 roles' canaries (all PASS) under the one shared budget +
versioned rotation/coverage state; --squeeze-dry-run still proves defer-not-drop
+ COVERAGE alarm. Central integration after the parallel Phase-3/4 PRs landed.

* fix(secrev): valid SAM in doc-drift fixture templates (cfn-lint E0001)

The doc-drift sample-stack fixtures declared AWS::Serverless::Function with no
Properties; cfn-lint's SAM transform errored (HIGH). Added minimal valid
Properties (Handler/Runtime/InlineCode). Pre-existing on main — #19 pushed with
--no-verify (xargs overflow) and CI runs no cfn-lint, so it slipped through.
doc-drift still detects the stack (keys on template presence).
2026-06-18 16:31:03 -04:00
..
api feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
dotgit feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
handlers/ingest feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
openapi feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
README.md feat(secrev): Plane-1 Phase 3 — doc-drift + IAM artifacts (aws-posture gated) (#19) 2026-06-18 16:25:40 -04:00
template.yaml feat(secrev): wire full Plane-1 roster into checker coordinator + fix fixture SAM (#22) 2026-06-18 16:31:03 -04:00

clean-repo

Well-documented service. Architecture:

  • The api/ service exposes the public HTTP surface.
  • A SAM stack (see template.yaml) provisions the IngestFn Lambda.
  • Lambda handler code lives under handlers/ingest.
  • The HTTP contract is published in the openapi/ spec.

Data flow: api -> IngestFn -> downstream.