security-review/checkers/fixtures/compliance-drift
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00
..
BadName_repo chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
clean-repo chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
docs-repo chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
EXPECTED_DRIFT_COUNT chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
README.md chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00

compliance-drift canary fixtures

Planted-drift corpus for checkers/compliance-drift.sh --canary (offline, no network/token). The checker asserts the total drift count equals EXPECTED_DRIFT_COUNT (anti-complacency floor, design §6.4). If a check regresses (stops firing), the count drops and the canary FAILS (exit 3).

Fixtures (each a real git checkout so the tracked-.env / ls-files checks work):

Fixture Planted drift Count
clean-repo none — kebab name, README, ci.yaml, dependabot.yml, .env is gitignored (must NOT fire) 0
BadName_repo non-kebab name; no README; no ci.yaml; has package.json but no dependabot.yml; tracked .env with values 5
docs-repo docs-only (CI skipped via DOCS_ONLY_REPOS), kebab name, no README 1

Total = 6 (EXPECTED_DRIFT_COUNT). The canary pins DOCS_ONLY_REPOS=docs-repo and COMPLIANCE_EXEMPT="" internally so it is deterministic regardless of the operator's env.

Secret-fixture naming: BadName_repo's planted tracked-secret env file is committed as dotenv.fixture, NOT .env. The repo's root .gitignore lists .env, so a literal .env fixture would silently never be committed — on a fresh clone the secrets-committed drift would vanish and the count would drop to 5 (this regression was caught by this very canary). The --canary materialization renames dotenv.fixture → .env in its temp work area; the dotgit/ index already TRACKS .env, so git ls-files still reports it. This mirrors the .fixture-suffix convention the dependency-cve fixtures use for their manifests. Keep any new committed secret fixture under a non-gitignored name and rename it in the canary.

When you add/remove a check or fixture, update both the fixture and EXPECTED_DRIFT_COUNT in the same commit (the canary edit is itself caught on the next run — design §6.4).