Read-only org compliance checker on the shared substrate (no re-clone; scans existing mirrors). Checklist grounded in handbook/github-standards: kebab repo name, README, CI/CD, Dependabot config+alerts, tracked-.env secrets, branch protection, merge settings; handbook exceptions (docs-only, compliance-exempt) honored. Mode-600 reports, ALARM-only (clean=silent). Includes planted-drift canary (asserts 6). Review fixes folded in: branch-protection + dependabot are status-code-aware (only a real 404 is drift; transient API failure -> skip, no false alarm); secrets-committed fires only on secret-shaped values (not benign config). NOT scheduled (provisioning gated).
1.1 KiB
1.1 KiB
compliance-drift canary fixtures
Planted-drift corpus for checkers/compliance-drift.sh --canary (offline, no network/token).
The checker asserts the total drift count equals EXPECTED_DRIFT_COUNT (anti-complacency floor,
design §6.4). If a check regresses (stops firing), the count drops and the canary FAILS (exit 3).
Fixtures (each a real git checkout so the tracked-.env / ls-files checks work):
| Fixture | Planted drift | Count |
|---|---|---|
clean-repo |
none — kebab name, README, ci.yaml, dependabot.yml, .env is gitignored (must NOT fire) |
0 |
BadName_repo |
non-kebab name; no README; no ci.yaml; has package.json but no dependabot.yml; tracked .env with values |
5 |
docs-repo |
docs-only (CI skipped via DOCS_ONLY_REPOS), kebab name, no README | 1 |
Total = 6 (EXPECTED_DRIFT_COUNT). The canary pins DOCS_ONLY_REPOS=docs-repo and
COMPLIANCE_EXEMPT="" internally so it is deterministic regardless of the operator's env.
When you add/remove a check or fixture, update both the fixture and EXPECTED_DRIFT_COUNT
in the same commit (the canary edit is itself caught on the next run — design §6.4).