security-review/checkers/fixtures/confluence-doc/README.md
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

2.5 KiB

confluence-doc canary fixtures

Planted doc-gap corpus for checkers/confluence-doc.sh --canary (offline, no network/token). The checker asserts the total doc-gap count equals EXPECTED_GAP_COUNT (anti-complacency floor, design §6.4). If a gap check regresses (stops firing) or the fixture changes, the count drifts and the canary FAILS (exit 3).

--canary implies --dry-run + --no-api, so the LIVE Confluence API checks (page-existence + staleness, which need the gated confluence-bot token, D6) are SKIPPED and noted — they are never counted as a gap on missing data (memory feedback_cloudwatch_alarms).

Fixture inputs

File Role
repos.txt the repo set to diff against the page-ID map (one repo name per line)
mock-page-map.json a MOCK IT page-ID map (same shape as project_confluence_migration)
mock-aws-inventory.json a MOCK read-only AWS inventory (what the API/collector would return)

The 3 planted gaps

Check Subject Why it's a gap
repo-documented orphan-tool-repo no page in the mock map (and not doc-exempt)
aws-documented afi-backup-monitor (Lambda) inventory resource with no page in the mock map
required-page IAM & Access Management a REQUIRED standing page omitted from the mock map

Non-gaps proving the checks are precise (must NOT inflate the count):

  • payments-dashboard, seahaven-slack-bot repos → matched to their pages.
  • engineering-handbook repo → DOC_EXEMPT_REPOS → skipped, not a gap.
  • payments-dashboard Lambda → matched to the "Payments Dashboard" page.
  • Incident Response Runbooks, Backup & Disaster Recovery required pages → present in the map.
  • The LIVE API staleness/existence check → SKIPPED (no creds in canary), noted, not a gap.

Total = 3 (EXPECTED_GAP_COUNT).

When you add/remove a check, a fixture input, or a planted gap, update the fixture(s) and EXPECTED_GAP_COUNT in the same commit (the canary edit is itself caught on the next run — design §6.4).

Not exercised offline (PROVISIONING — gated)

The LIVE Confluence reads (and the on-demand WRITE path via ~/.claude/scripts/confluence_mermaid.py, including the page-1540098 live dry-run that must list all 16 weweave Mermaid macros) require the confluence-bot service account + token. That account creation, its 90-day rotation, and the Mermaid live dry-run are provisioning steps documented in the checker's PROVISIONING footer — they are NOT performed by the canary.