mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-10-01 14:23:15 +00:00
Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced.
47 lines
2.5 KiB
Markdown
47 lines
2.5 KiB
Markdown
# confluence-doc canary fixtures
|
|
|
|
Planted doc-gap corpus for `checkers/confluence-doc.sh --canary` (offline, no network/token).
|
|
The checker asserts the total doc-gap count equals `EXPECTED_GAP_COUNT` (anti-complacency
|
|
floor, design §6.4). If a gap check regresses (stops firing) or the fixture changes, the count
|
|
drifts and the canary FAILS (exit 3).
|
|
|
|
`--canary` implies `--dry-run + --no-api`, so the LIVE Confluence API checks (page-existence +
|
|
staleness, which need the gated `confluence-bot` token, D6) are SKIPPED and noted — they are
|
|
never counted as a gap on missing data (memory `feedback_cloudwatch_alarms`).
|
|
|
|
## Fixture inputs
|
|
|
|
| File | Role |
|
|
|---|---|
|
|
| `repos.txt` | the repo set to diff against the page-ID map (one repo name per line) |
|
|
| `mock-page-map.json` | a MOCK IT page-ID map (same shape as `project_confluence_migration`) |
|
|
| `mock-aws-inventory.json` | a MOCK read-only AWS inventory (what the API/collector would return) |
|
|
|
|
## The 3 planted gaps
|
|
|
|
| Check | Subject | Why it's a gap |
|
|
|---|---|---|
|
|
| repo-documented | `orphan-tool-repo` | no page in the mock map (and not doc-exempt) |
|
|
| aws-documented | `afi-backup-monitor` (Lambda) | inventory resource with no page in the mock map |
|
|
| required-page | `IAM & Access Management` | a REQUIRED standing page omitted from the mock map |
|
|
|
|
Non-gaps proving the checks are precise (must NOT inflate the count):
|
|
- `payments-dashboard`, `seahaven-slack-bot` repos → matched to their pages.
|
|
- `engineering-handbook` repo → `DOC_EXEMPT_REPOS` → skipped, not a gap.
|
|
- `payments-dashboard` Lambda → matched to the "Payments Dashboard" page.
|
|
- `Incident Response Runbooks`, `Backup & Disaster Recovery` required pages → present in the map.
|
|
- The LIVE API staleness/existence check → SKIPPED (no creds in canary), noted, not a gap.
|
|
|
|
Total = **3** (`EXPECTED_GAP_COUNT`).
|
|
|
|
When you add/remove a check, a fixture input, or a planted gap, update the fixture(s) and
|
|
`EXPECTED_GAP_COUNT` in the same commit (the canary edit is itself caught on the next run —
|
|
design §6.4).
|
|
|
|
## Not exercised offline (PROVISIONING — gated)
|
|
|
|
The LIVE Confluence reads (and the on-demand WRITE path via
|
|
`~/.claude/scripts/confluence_mermaid.py`, including the page-1540098 live dry-run that must list
|
|
all 16 weweave Mermaid macros) require the `confluence-bot` service account + token. That account
|
|
creation, its 90-day rotation, and the Mermaid live dry-run are provisioning steps documented in
|
|
the checker's PROVISIONING footer — they are NOT performed by the canary.
|