feat(security): add issue inventory and evidence-classification foundation - #911
feat(security): add issue inventory and evidence-classification foundation#911seonghobae wants to merge 12 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Merge protected develop into the canonical documentation branch, promote the separately verified webhook prevention and bounded scanner-detection controls, keep PR #911 labelled active, and update executable documentation contracts.
|
Closing this draft and preserving the branch as an evidence source rather than merging or rebasing it wholesale. The PR itself records 0/414 cause-bound issues, 0/417 independently validated direct-detector claims, and 0/414 protected-branch operational proofs; it is also a 20k-line, non-mergeable change based on an obsolete |
Scope
This PR is an inventory and evidence-classification foundation, not completed issue-level detector efficacy.
Current machine-checked measurements:
(classifier_family, claim_id)semantics: 20;developoperational proof: 0/414.A failure collector, issue number, title/body digest, generic family fixture, log regex, caller-provided Boolean/list, or signed opaque upstream outcome does not count as AppGuardrail directly detecting the underlying condition.
What this PR adds
docs/issue-detection-traceability.jsonplus a deliberately bounded topology/count/status validator;Independent documentation re-audit
Protected
develop@0d07baae44a40edfcaec5e42c7fb9351510ca9f0wasPARTIAL/MISSINGfor the canonical issue-detection documentation graph. The active PR now provides an honest, status-bearing reconstruction, including:ACTIVE_PR,PARTIAL, andMISSINGstates in Architecture, threat model, operability, and incident response;The implementation remains incomplete:
DetectionResultand familyFamilyAssessmenttaxonomies are not unified;Verification at exact head
Local verification on the exact tree published as
a71a51daca45dfc47a362a26e09a60a035c92a91:appguardrail_core/issue_detection.py: 1,363/1,363 statements (100%);appguardrail_core/issue_detection_docs.py: 389/389 statements (100%);git diff --checkvalidation passed.The seven published remote blobs exactly match the locally tested Git object IDs and there are 0 unresolved review threads. Exact-head hosted checks for the new head are pending and must not be inferred as passing. Even successful checks validate the foundation only; they cannot satisfy the direct-efficacy blockers below.
Merge blockers / next queue
probe_ref/acquirer_ref, independently acquired source identity, atomic cause, obligation binding, and typed assessments.developcommit.The PR must remain Draft until these boundaries are implemented and exact-head gates permit promotion.