security-review/checkers/fixtures/compliance-drift/README.md
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

28 lines
1.9 KiB
Markdown

# compliance-drift canary fixtures
Planted-drift corpus for `checkers/compliance-drift.sh --canary` (offline, no network/token).
The checker asserts the total drift count equals `EXPECTED_DRIFT_COUNT` (anti-complacency floor,
design §6.4). If a check regresses (stops firing), the count drops and the canary FAILS (exit 3).
Fixtures (each a real git checkout so the tracked-`.env` / `ls-files` checks work):
| Fixture | Planted drift | Count |
|---|---|---|
| `clean-repo` | none — kebab name, README, ci.yaml, dependabot.yml, `.env` is **gitignored** (must NOT fire) | 0 |
| `BadName_repo` | non-kebab name; no README; no ci.yaml; has `package.json` but no `dependabot.yml`; tracked `.env` with values | 5 |
| `docs-repo` | docs-only (CI skipped via DOCS_ONLY_REPOS), kebab name, no README | 1 |
Total = **6** (`EXPECTED_DRIFT_COUNT`). The canary pins `DOCS_ONLY_REPOS=docs-repo` and
`COMPLIANCE_EXEMPT=""` internally so it is deterministic regardless of the operator's env.
**Secret-fixture naming:** `BadName_repo`'s planted tracked-secret env file is committed as
`dotenv.fixture`, NOT `.env`. The repo's root `.gitignore` lists `.env`, so a literal `.env`
fixture would silently never be committed — on a fresh clone the `secrets-committed` drift would
vanish and the count would drop to 5 (this regression was caught by this very canary). The
`--canary` materialization renames `dotenv.fixture` → `.env` in its temp work area; the
`dotgit/` index already TRACKS `.env`, so `git ls-files` still reports it. This mirrors the
`.fixture`-suffix convention the `dependency-cve` fixtures use for their manifests. Keep any new
committed secret fixture under a non-gitignored name and rename it in the canary.
When you add/remove a check or fixture, update both the fixture and `EXPECTED_DRIFT_COUNT`
in the same commit (the canary edit is itself caught on the next run — design §6.4).