-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathmechanisms.json
More file actions
534 lines (534 loc) · 15.2 KB
/
Copy pathmechanisms.json
File metadata and controls
534 lines (534 loc) · 15.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
{
"_comment": [
"Where each blocking row in ENFORCEMENT.md is actually implemented.",
"",
"ENFORCEMENT.md opens by saying every rule appears with the thing that",
"checks it. A mechanism audit found that claim false in six places, and the",
"shape of five of them was the same: a control that existed where it was",
"learned, and a table that generalized it to an artifact it had never",
"reached. The worst case ran for months under a step name it did not earn.",
"scripts/check_mechanisms.py reads this file and refuses that class (D-033).",
"",
"Each entry names one row by its exact text, so renaming a row without",
"revisiting its mechanism fails. Each artifact names the file that holds the",
"mechanism and a pattern that must appear in it.",
"",
"holder is where the file lives. 'this' and 'template' are in this",
"repository and are verified. 'application' is a repository built to this",
"doctrine, which this repository cannot read, so those entries are reported",
"as declared rather than verified: the check belongs to that project's own",
"pipeline. Saying so is the point, because an unverified claim and a",
"verified one must not look alike."
],
"mechanisms": [
{
"rule": "No secrets in a commit",
"table": "Blocked at commit",
"artifacts": [
{
"holder": "this",
"path": ".pre-commit-config.yaml",
"pattern": "id: gitleaks"
},
{
"holder": "template",
"path": ".pre-commit-config.yaml",
"pattern": "id: gitleaks"
}
]
},
{
"rule": "No secrets anywhere in history",
"table": "Blocked at commit",
"artifacts": [
{
"holder": "this",
"path": ".github/workflows/ci.yml",
"pattern": "gitleaks\" git --redact"
},
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "gitleaks\" git --redact"
}
]
},
{
"rule": "Writing rules hold",
"table": "Blocked at commit",
"artifacts": [
{
"holder": "this",
"path": ".pre-commit-config.yaml",
"pattern": "id: vale"
},
{
"holder": "this",
"path": ".vale.ini",
"pattern": "BasedOnStyles = BuildGuidelines"
}
],
"note": "The template ships the secret hook only, and ENFORCEMENT.md says so under the table. A template referencing style files it did not ship would fail on a project's first commit."
},
{
"rule": "No common idioms or corporate speak",
"table": "Blocked at commit",
"artifacts": [
{
"holder": "this",
"path": ".vale/styles/Proselint/Cliches.yml",
"pattern": "extends"
},
{
"holder": "this",
"path": ".vale/styles/Proselint/CorporateSpeak.yml",
"pattern": "extends"
},
{
"holder": "this",
"path": ".vale.ini",
"pattern": "Proselint.Cliches = error"
}
]
},
{
"rule": "Commit messages follow the writing rules",
"table": "Blocked at commit",
"artifacts": [
{
"holder": "this",
"path": "scripts/check_commit_message.sh",
"pattern": "commit message check"
},
{
"holder": "this",
"path": ".pre-commit-config.yaml",
"pattern": "stages: \\[commit-msg\\]"
}
]
},
{
"rule": "Behavior matches its tests",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "pytest -q"
}
]
},
{
"rule": "No known-vulnerable dependency",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "pip-audit"
}
]
},
{
"rule": "No obvious insecure code pattern",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "bandit -r app"
}
]
},
{
"rule": "No secret in any commit",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "gitleaks\" git --redact"
},
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "fetch-depth: 0"
}
],
"note": "Both patterns are required together. The fetched history is what the binary reads, and the action this replaced read only the event's commit range while the fetch-depth line sat above it looking like proof."
},
{
"rule": "Dependencies install as pinned",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "pip install --require-hashes"
},
{
"holder": "template",
"path": "Dockerfile",
"pattern": "--require-hashes"
}
]
},
{
"rule": "No fixable vulnerability in the image",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "ignore-unfixed: true"
}
]
},
{
"rule": "Third-party actions cannot change under us",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "uses: actions/checkout@[0-9a-f]{40}"
}
]
},
{
"rule": "Dependency updates are reviewed, not automatic",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/dependabot.yml",
"pattern": "package-ecosystem"
}
]
},
{
"rule": "Workflow tokens hold least permission, and no workflow runs fork code with the token",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "permissions:"
},
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "actionlint"
},
{
"holder": "template",
"path": ".github/workflows/ci.yml",
"pattern": "zizmor"
}
],
"note": "The template had no permissions block and no lint job until the audit added them, and the audit found the missing block by running the job it had just added."
},
{
"rule": "Parsers survive input nobody wrote a test for",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": ".github/workflows/cflite.yml",
"pattern": "sanitizer: address"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": ".clusterfuzzlite/project.yaml",
"pattern": "language"
}
]
},
{
"rule": "Releases carry provenance",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": ".github/workflows/attest-release.yml",
"pattern": "attest-build-provenance"
}
]
},
{
"rule": "Every route answers to the role matrix, and none answers without a session",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_matrix.py",
"pattern": "def test_matrix_rows_are_enforced_for_every_role"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_matrix.py",
"pattern": "def test_unauthenticated_calls_get_401_not_403"
}
]
},
{
"rule": "The documented route surface matches the live one, in both directions",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_matrix.py",
"pattern": "def test_routes_match_the_documented_enumeration"
}
]
},
{
"rule": "The spreadsheet exit stays escaped",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_reports.py",
"pattern": "def test_formula_leaders_are_neutralized"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": "scripts/check_mutation.py",
"pattern": "formula escaping removed from the CSV exit"
}
]
},
{
"rule": "Ingestion stays bounded and in memory",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_ingest_properties.py",
"pattern": "def test_"
}
]
},
{
"rule": "Sensitive reads carry their headers and their audit row",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_frontend.py",
"pattern": "nosniff"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_audit_chain.py",
"pattern": "def test_"
}
]
},
{
"rule": "Security-relevant events are structured and parseable",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_logs.py",
"pattern": "def test_"
}
]
},
{
"rule": "No retired project name in active text",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "this",
"path": "scripts/check_names.py",
"pattern": "deprecated-names"
},
{
"holder": "this",
"path": ".github/workflows/ci.yml",
"pattern": "check_names"
}
]
},
{
"rule": "Every lesson a scanner taught after a push is a rule at commit time",
"table": "Blocked at commit",
"artifacts": [
{
"holder": "template",
"path": ".pre-commit-config.yaml",
"pattern": "id: semgrep"
},
{
"holder": "template",
"path": ".semgrep/rules.yml",
"pattern": "rules:"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": ".semgrep/rules.yml",
"pattern": "rules:"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": "scripts/check_python.sh",
"pattern": "semgrep"
}
]
},
{
"rule": "The pipeline's semantic analysis runs before the push",
"table": "Blocked at commit",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "scripts/scan.sh",
"pattern": "codeql-bundle"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": ".pre-commit-config.yaml",
"pattern": "stages: \\[pre-push\\]"
}
]
},
{
"rule": "A promise nobody awaits in a page script",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "eslint.config.mjs",
"pattern": "no-floating-promises"
},
{
"holder": "application",
"repository": "manifest-identity",
"path": ".github/workflows/ci.yml",
"pattern": "npm ci --ignore-scripts"
}
]
},
{
"rule": "A path containment check as a string prefix",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".semgrep/rules.yml",
"pattern": "id: no-path-containment-by-string-prefix"
}
]
},
{
"rule": "A handler that catches everything and says nothing",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "template",
"path": ".semgrep/rules.yml",
"pattern": "id: no-silenced-exception"
}
]
},
{
"rule": "A commit that names a cause without its reproduction",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "this",
"path": "scripts/check_commit_message.sh",
"pattern": "Reproduced with: "
}
]
},
{
"rule": "The standards copy behind the source",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "this",
"path": "scripts/check_doctrine_copy.py",
"pattern": "AGENTS.md"
}
]
},
{
"rule": "A committed score badge behind the scorer",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "this",
"path": "scripts/score.py",
"pattern": "--badge"
}
]
},
{
"rule": "A runtime package with no record, or a record with no package",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "this",
"path": "scripts/check_dependency_records.py",
"pattern": "DEPENDENCIES.md"
}
]
},
{
"rule": "Bulk disclosure, bulk change, or credential creation on a stale session",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_step_up.py",
"pattern": "step_up_required"
}
]
},
{
"rule": "A bulk export that leaves no record",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_step_up.py",
"pattern": "test_every_export_leaves_a_record"
}
]
},
{
"rule": "Rejected input that comes back",
"table": "Blocked in the pipeline",
"artifacts": [
{
"holder": "application",
"repository": "manifest-identity",
"path": "tests/test_markers_at_every_door.py",
"pattern": "MARKER"
}
]
}
]
}