Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced. |
||
|---|---|---|
| .. | ||
| BadName_repo | ||
| clean-repo | ||
| docs-repo | ||
| EXPECTED_DRIFT_COUNT | ||
| README.md | ||
compliance-drift canary fixtures
Planted-drift corpus for checkers/compliance-drift.sh --canary (offline, no network/token).
The checker asserts the total drift count equals EXPECTED_DRIFT_COUNT (anti-complacency floor,
design §6.4). If a check regresses (stops firing), the count drops and the canary FAILS (exit 3).
Fixtures (each a real git checkout so the tracked-.env / ls-files checks work):
| Fixture | Planted drift | Count |
|---|---|---|
clean-repo |
none — kebab name, README, ci.yaml, dependabot.yml, .env is gitignored (must NOT fire) |
0 |
BadName_repo |
non-kebab name; no README; no ci.yaml; has package.json but no dependabot.yml; tracked .env with values |
5 |
docs-repo |
docs-only (CI skipped via DOCS_ONLY_REPOS), kebab name, no README | 1 |
Total = 6 (EXPECTED_DRIFT_COUNT). The canary pins DOCS_ONLY_REPOS=docs-repo and
COMPLIANCE_EXEMPT="" internally so it is deterministic regardless of the operator's env.
Secret-fixture naming: BadName_repo's planted tracked-secret env file is committed as
dotenv.fixture, NOT .env. The repo's root .gitignore lists .env, so a literal .env
fixture would silently never be committed — on a fresh clone the secrets-committed drift would
vanish and the count would drop to 5 (this regression was caught by this very canary). The
--canary materialization renames dotenv.fixture → .env in its temp work area; the
dotgit/ index already TRACKS .env, so git ls-files still reports it. This mirrors the
.fixture-suffix convention the dependency-cve fixtures use for their manifests. Keep any new
committed secret fixture under a non-gitignored name and rename it in the canary.
When you add/remove a check or fixture, update both the fixture and EXPECTED_DRIFT_COUNT
in the same commit (the canary edit is itself caught on the next run — design §6.4).