checkov scanned cdk.out/<stack>.template.json, which is gitignored generated
synth output. A dev with a stale cdk.out lying around would false-block unrelated
pushes on CKV_AWS_111 raised against CDK-generated roles (LogRetention, asset
publishing) that are not authored source. Broaden the checkov --skip-path from
cdk.out/asset. to the whole cdk.out/ tree so it treats synth output the same as
semgrep (--exclude cdk.out) and cfn-lint (cdk.out prune) already do.
Authored IaC checkov parses (SAM/CFN template.yaml, Terraform) is tracked source
and is still fully scanned; verified a planted wildcard IAM policy in tracked
source still trips CKV_AWS_111 and blocks.
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.
Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.