Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)

check_all runs every check stage even when one fails; malformed dates are
reported rather than aborting; accepted findings and closure evidence are
shown; defer requires a valid future date. Adds SCOPE.md, the scope
assessment, the open-findings source review and a unittest suite. Stops
tracking __pycache__.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
tegwick 2026-09-22 07:56:58 +02:00
parent 29f50d5143
commit bbbede5f47
25 changed files with 1007 additions and 43 deletions

View file

@ -40,6 +40,18 @@ Then, per due finding:
be met while the embargo still holds, if a sibling finding would be exposed
by publishing (`RISK-F-0003`).
Also work the non-finding obligations printed by `make due`: review the sources
and activation context for each due regulatory determination or full policy;
re-decide due embargoes; and reconcile pending publication handovers with the
publication owner's evidence, including for closed findings. Regulatory reviews
use `make checked ARGS="<RISK-REG-or-RISK-POL-id> clean|moved ..."` after the
review. A handover report is not authorization to publish embargoed content.
Index validation failure does not suppress later `make check` stages. Read the
reports before regenerating the index. A successful regeneration is not a
review outcome. Invalid date fields remain work to repair rather than evidence
that a check is current.
Then record it, in the same sitting:
```