mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-09-30 13:53:16 +00:00
Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced.
69 lines
3 KiB
JSON
69 lines
3 KiB
JSON
{
|
|
"$schema": "http://json-schema.org/draft-07/schema#",
|
|
"title": "Sea Haven security-review finding",
|
|
"description": "Structured finding contract for /sh-security-review. Same shape for interactive (Path A) and automated (Path B) runs, and the input review.sh reads to make the block decision.",
|
|
"type": "object",
|
|
"required": ["findings", "summary"],
|
|
"properties": {
|
|
"findings": {
|
|
"type": "array",
|
|
"items": {
|
|
"type": "object",
|
|
"required": ["id", "title", "severity", "cwe", "file", "category", "data_flow", "proof", "status"],
|
|
"properties": {
|
|
"id": { "type": "string", "description": "stable slug, e.g. sqli-payment-handler-get-payment" },
|
|
"title": { "type": "string" },
|
|
"severity": {
|
|
"type": "string",
|
|
"enum": ["critical", "high", "medium", "low", "info", "unverified"],
|
|
"description": "unverified = a claim with no accepted proof; auto-downgraded from its claimed severity"
|
|
},
|
|
"claimed_severity": {
|
|
"type": "string",
|
|
"enum": ["critical", "high", "medium", "low", "info"],
|
|
"description": "the detector's original severity before the verifier ruled"
|
|
},
|
|
"cwe": { "type": "string", "pattern": "^CWE-[0-9]+$" },
|
|
"file": { "type": "string" },
|
|
"line": { "type": ["integer", "null"] },
|
|
"category": {
|
|
"type": "string",
|
|
"enum": ["injection", "authz", "secrets-crypto", "iac-iam", "web-client", "logic", "other"]
|
|
},
|
|
"data_flow": {
|
|
"type": "string",
|
|
"description": "numbered plain-English trace from untrusted source to dangerous sink"
|
|
},
|
|
"proof": {
|
|
"type": "object",
|
|
"required": ["input", "outcome"],
|
|
"properties": {
|
|
"input": { "type": "string", "description": "concrete malicious input / trigger" },
|
|
"outcome": { "type": "string", "description": "the specific bad result it produces" },
|
|
"test": { "type": ["string", "null"], "description": "optional failing-test sketch" }
|
|
}
|
|
},
|
|
"status": {
|
|
"type": "string",
|
|
"enum": ["confirmed", "unverified", "suppressed"],
|
|
"description": "confirmed = verifier accepted proof; unverified = no accepted proof; suppressed = dismissed with justification"
|
|
},
|
|
"suppression_justification": {
|
|
"type": ["string", "null"],
|
|
"description": "REQUIRED when status=suppressed; logged and surfaced in the report"
|
|
},
|
|
"recommendation": { "type": "string" }
|
|
}
|
|
}
|
|
},
|
|
"summary": {
|
|
"type": "object",
|
|
"required": ["confirmed_critical", "confirmed_high", "block"],
|
|
"properties": {
|
|
"confirmed_critical": { "type": "integer" },
|
|
"confirmed_high": { "type": "integer" },
|
|
"block": { "type": "boolean", "description": "true if any confirmed critical/high is unsuppressed (the gate condition)" }
|
|
}
|
|
}
|
|
}
|
|
}
|