RISK-WP-0004: five of six tasks done; the executor is the operator's call
T02 inbox check, wired into make check and verified against the actual 2026-08-19 failure — replayed at that moment it surfaces all three messages that were already waiting. T03 sweeps the rest of the quietly-tolerated class: bad dates, cadence off the ladder, undefined disclosure states, dangling constraint_on and related refs, embargoes without conditions, escalations without triggers. T04 requests verification of user-engine's tenant boundary — the first walk down the on-request path, chosen as a consumer not already known to fail it. T05 established by trying what this register can verify: cluster yes, OpenBao 403. T06 puts regulatory records on the findings ladder. T01 stays in progress: the procedure, make due and make checked exist, but arming something that runs them on schedule is a standing compute commitment and the operator's to make. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
97fcc56a4d
commit
36b707f0c3
10 changed files with 296 additions and 9 deletions
|
|
@ -77,6 +77,15 @@ def findings() -> list[dict]:
|
|||
return sorted(items, key=lambda f: f["id"], reverse=True)
|
||||
|
||||
|
||||
def regulatory() -> list[dict]:
|
||||
"""Regulatory records expire, so they ride the same ladder as findings."""
|
||||
d = REPO / "docs" / "regulatory"
|
||||
if not d.exists():
|
||||
return []
|
||||
return sorted((load(p) for p in d.glob("*.md") if p.name != "README.md"),
|
||||
key=lambda r: r.get("id", ""))
|
||||
|
||||
|
||||
def notes() -> list[dict]:
|
||||
if not NOTES.exists():
|
||||
return []
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue