Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced. |
||
|---|---|---|
| .. | ||
| EXPECTED_GAP_COUNT | ||
| mock-aws-inventory.json | ||
| mock-page-map.json | ||
| README.md | ||
| repos.txt | ||
confluence-doc canary fixtures
Planted doc-gap corpus for checkers/confluence-doc.sh --canary (offline, no network/token).
The checker asserts the total doc-gap count equals EXPECTED_GAP_COUNT (anti-complacency
floor, design §6.4). If a gap check regresses (stops firing) or the fixture changes, the count
drifts and the canary FAILS (exit 3).
--canary implies --dry-run + --no-api, so the LIVE Confluence API checks (page-existence +
staleness, which need the gated confluence-bot token, D6) are SKIPPED and noted — they are
never counted as a gap on missing data (memory feedback_cloudwatch_alarms).
Fixture inputs
| File | Role |
|---|---|
repos.txt |
the repo set to diff against the page-ID map (one repo name per line) |
mock-page-map.json |
a MOCK IT page-ID map (same shape as project_confluence_migration) |
mock-aws-inventory.json |
a MOCK read-only AWS inventory (what the API/collector would return) |
The 3 planted gaps
| Check | Subject | Why it's a gap |
|---|---|---|
| repo-documented | orphan-tool-repo |
no page in the mock map (and not doc-exempt) |
| aws-documented | afi-backup-monitor (Lambda) |
inventory resource with no page in the mock map |
| required-page | IAM & Access Management |
a REQUIRED standing page omitted from the mock map |
Non-gaps proving the checks are precise (must NOT inflate the count):
payments-dashboard,seahaven-slack-botrepos → matched to their pages.engineering-handbookrepo →DOC_EXEMPT_REPOS→ skipped, not a gap.payments-dashboardLambda → matched to the "Payments Dashboard" page.Incident Response Runbooks,Backup & Disaster Recoveryrequired pages → present in the map.- The LIVE API staleness/existence check → SKIPPED (no creds in canary), noted, not a gap.
Total = 3 (EXPECTED_GAP_COUNT).
When you add/remove a check, a fixture input, or a planted gap, update the fixture(s) and
EXPECTED_GAP_COUNT in the same commit (the canary edit is itself caught on the next run —
design §6.4).
Not exercised offline (PROVISIONING — gated)
The LIVE Confluence reads (and the on-demand WRITE path via
~/.claude/scripts/confluence_mermaid.py, including the page-1540098 live dry-run that must list
all 16 weweave Mermaid macros) require the confluence-bot service account + token. That account
creation, its 90-day rotation, and the Mermaid live dry-run are provisioning steps documented in
the checker's PROVISIONING footer — they are NOT performed by the canary.