Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced. |
||
|---|---|---|
| .. | ||
| sample-reports | ||
| EXPECTED_PLAN_ITEMS | ||
| README.md | ||
plan-groomer canary fixtures
Sample sibling-checker reports for checkers/plan-groomer.sh --canary (offline, no network/
token). The planner asserts the groomed-plan item count equals EXPECTED_PLAN_ITEMS
(anti-complacency floor, design §6.4). If aggregation or dedup regresses, the count drifts
and the canary FAILS (exit 3).
How the canary works
--canary points $REPORT_ROOT_BASE at sample-reports/ and writes the groomed plan into a
mode-700 temp dir (so the canary writes nothing under $HOME). It reads each source checker's
latest <date>/<checker>.json, normalizes every .findings[] into a plan item
{repo, severity, source, title, action}, dedupes on repo|source|title, prioritizes by
severity, and writes the plan into the mode-600 report.
These are plain report JSON files (no dotgit/ trick needed — plan-groomer reads sibling
reports, it does not scan git checkouts).
Fixture report set
| Source checker | Date dir | Findings | Contributes to plan |
|---|---|---|---|
compliance-drift |
2026-06-10 (OLD) |
1 | 0 — sentinel: older date MUST be skipped (latest-date selection) |
compliance-drift |
2026-06-17 (latest) |
3 | 2 — two of the three are an exact duplicate (payments-dashboard / README) that must dedup to one |
dependency-cve |
2026-06-17 |
2 | 2 — jinja2 (high) + lodash (critical) |
doc-drift |
2026-06-17 |
1 | 1 — stale README arch section |
confluence-doc |
(none) | — | 0 — no report present; noted in missing_sources, NEVER invented as work |
Total groomed plan items = 5 (EXPECTED_PLAN_ITEMS).
This exercises four invariants in one run:
- latest-date selection — the
2026-06-10sentinel must not leak into the plan. - dedup — the duplicate README finding collapses to one item.
- multi-source aggregation — three different checkers feed one prioritized plan.
- no-data discipline — a missing source (
confluence-doc) is noted, never fabricated.
When you add/remove a source checker, a fixture report, or a finding, update the fixture(s)
and EXPECTED_PLAN_ITEMS in the same commit (the canary edit is itself caught on the next run
— design §6.4).