mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-10-03 19:03:21 +00:00
40 lines
2.2 KiB
Markdown
40 lines
2.2 KiB
Markdown
|
|
# plan-groomer canary fixtures
|
||
|
|
|
||
|
|
Sample sibling-checker reports for `checkers/plan-groomer.sh --canary` (offline, no network/
|
||
|
|
token). The planner asserts the groomed-plan **item count** equals `EXPECTED_PLAN_ITEMS`
|
||
|
|
(anti-complacency floor, design §6.4). If aggregation or dedup regresses, the count drifts
|
||
|
|
and the canary FAILS (exit 3).
|
||
|
|
|
||
|
|
## How the canary works
|
||
|
|
|
||
|
|
`--canary` points `$REPORT_ROOT_BASE` at `sample-reports/` and writes the groomed plan into a
|
||
|
|
mode-700 temp dir (so the canary writes nothing under `$HOME`). It reads each source checker's
|
||
|
|
**latest** `<date>/<checker>.json`, normalizes every `.findings[]` into a plan item
|
||
|
|
`{repo, severity, source, title, action}`, **dedupes** on `repo|source|title`, prioritizes by
|
||
|
|
severity, and writes the plan into the mode-600 report.
|
||
|
|
|
||
|
|
These are plain report JSON files (no `dotgit/` trick needed — plan-groomer reads sibling
|
||
|
|
reports, it does not scan git checkouts).
|
||
|
|
|
||
|
|
## Fixture report set
|
||
|
|
|
||
|
|
| Source checker | Date dir | Findings | Contributes to plan |
|
||
|
|
|---|---|---|---|
|
||
|
|
| `compliance-drift` | `2026-06-10` (OLD) | 1 | **0** — sentinel: older date MUST be skipped (latest-date selection) |
|
||
|
|
| `compliance-drift` | `2026-06-17` (latest) | 3 | **2** — two of the three are an exact duplicate (`payments-dashboard` / README) that must dedup to one |
|
||
|
|
| `dependency-cve` | `2026-06-17` | 2 | **2** — `jinja2` (high) + `lodash` (critical) |
|
||
|
|
| `doc-drift` | `2026-06-17` | 1 | **1** — stale README arch section |
|
||
|
|
| `confluence-doc` | (none) | — | **0** — no report present; noted in `missing_sources`, NEVER invented as work |
|
||
|
|
|
||
|
|
Total groomed plan items = **5** (`EXPECTED_PLAN_ITEMS`).
|
||
|
|
|
||
|
|
This exercises four invariants in one run:
|
||
|
|
1. **latest-date selection** — the `2026-06-10` sentinel must not leak into the plan.
|
||
|
|
2. **dedup** — the duplicate README finding collapses to one item.
|
||
|
|
3. **multi-source aggregation** — three different checkers feed one prioritized plan.
|
||
|
|
4. **no-data discipline** — a missing source (`confluence-doc`) is noted, never fabricated.
|
||
|
|
|
||
|
|
When you add/remove a source checker, a fixture report, or a finding, update the fixture(s)
|
||
|
|
and `EXPECTED_PLAN_ITEMS` in the same commit (the canary edit is itself caught on the next run
|
||
|
|
— design §6.4).
|