security-review/checkers/fixtures/plan-groomer/README.md
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

39 lines
2.2 KiB
Markdown

# plan-groomer canary fixtures
Sample sibling-checker reports for `checkers/plan-groomer.sh --canary` (offline, no network/
token). The planner asserts the groomed-plan **item count** equals `EXPECTED_PLAN_ITEMS`
(anti-complacency floor, design §6.4). If aggregation or dedup regresses, the count drifts
and the canary FAILS (exit 3).
## How the canary works
`--canary` points `$REPORT_ROOT_BASE` at `sample-reports/` and writes the groomed plan into a
mode-700 temp dir (so the canary writes nothing under `$HOME`). It reads each source checker's
**latest** `<date>/<checker>.json`, normalizes every `.findings[]` into a plan item
`{repo, severity, source, title, action}`, **dedupes** on `repo|source|title`, prioritizes by
severity, and writes the plan into the mode-600 report.
These are plain report JSON files (no `dotgit/` trick needed — plan-groomer reads sibling
reports, it does not scan git checkouts).
## Fixture report set
| Source checker | Date dir | Findings | Contributes to plan |
|---|---|---|---|
| `compliance-drift` | `2026-06-10` (OLD) | 1 | **0** — sentinel: older date MUST be skipped (latest-date selection) |
| `compliance-drift` | `2026-06-17` (latest) | 3 | **2** — two of the three are an exact duplicate (`payments-dashboard` / README) that must dedup to one |
| `dependency-cve` | `2026-06-17` | 2 | **2** — `jinja2` (high) + `lodash` (critical) |
| `doc-drift` | `2026-06-17` | 1 | **1** — stale README arch section |
| `confluence-doc` | (none) | — | **0** — no report present; noted in `missing_sources`, NEVER invented as work |
Total groomed plan items = **5** (`EXPECTED_PLAN_ITEMS`).
This exercises four invariants in one run:
1. **latest-date selection** — the `2026-06-10` sentinel must not leak into the plan.
2. **dedup** — the duplicate README finding collapses to one item.
3. **multi-source aggregation** — three different checkers feed one prioritized plan.
4. **no-data discipline** — a missing source (`confluence-doc`) is noted, never fabricated.
When you add/remove a source checker, a fixture report, or a finding, update the fixture(s)
and `EXPECTED_PLAN_ITEMS` in the same commit (the canary edit is itself caught on the next run
— design §6.4).