security-review/checkers/fixtures/plan-groomer
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00
..
sample-reports chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
EXPECTED_PLAN_ITEMS chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
README.md chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00

plan-groomer canary fixtures

Sample sibling-checker reports for checkers/plan-groomer.sh --canary (offline, no network/ token). The planner asserts the groomed-plan item count equals EXPECTED_PLAN_ITEMS (anti-complacency floor, design §6.4). If aggregation or dedup regresses, the count drifts and the canary FAILS (exit 3).

How the canary works

--canary points $REPORT_ROOT_BASE at sample-reports/ and writes the groomed plan into a mode-700 temp dir (so the canary writes nothing under $HOME). It reads each source checker's latest <date>/<checker>.json, normalizes every .findings[] into a plan item {repo, severity, source, title, action}, dedupes on repo|source|title, prioritizes by severity, and writes the plan into the mode-600 report.

These are plain report JSON files (no dotgit/ trick needed — plan-groomer reads sibling reports, it does not scan git checkouts).

Fixture report set

Source checker Date dir Findings Contributes to plan
compliance-drift 2026-06-10 (OLD) 1 0 — sentinel: older date MUST be skipped (latest-date selection)
compliance-drift 2026-06-17 (latest) 3 2 — two of the three are an exact duplicate (payments-dashboard / README) that must dedup to one
dependency-cve 2026-06-17 2 2 — jinja2 (high) + lodash (critical)
doc-drift 2026-06-17 1 1 — stale README arch section
confluence-doc (none) — 0 — no report present; noted in missing_sources, NEVER invented as work

Total groomed plan items = 5 (EXPECTED_PLAN_ITEMS).

This exercises four invariants in one run:

  1. latest-date selection — the 2026-06-10 sentinel must not leak into the plan.
  2. dedup — the duplicate README finding collapses to one item.
  3. multi-source aggregation — three different checkers feed one prioritized plan.
  4. no-data discipline — a missing source (confluence-doc) is noted, never fabricated.

When you add/remove a source checker, a fixture report, or a finding, update the fixture(s) and EXPECTED_PLAN_ITEMS in the same commit (the canary edit is itself caught on the next run — design §6.4).