Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)
check_all runs every check stage even when one fails; malformed dates are reported rather than aborting; accepted findings and closure evidence are shown; defer requires a valid future date. Adds SCOPE.md, the scope assessment, the open-findings source review and a unittest suite. Stops tracking __pycache__. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
parent
29f50d5143
commit
bbbede5f47
25 changed files with 1007 additions and 43 deletions
|
|
@ -365,3 +365,17 @@ achievable. An accepted risk still gets checked.
|
|||
- **2026-08-20** — not clean: Trigger list ruled: no external determination in build mode; accepted with the legal policy set as the compensating control. Cadence instant → instant; checked again immediately.
|
||||
- **2026-09-01** — not clean: the regulatory record now states target periods per category; the remaining gap is whether platform-pg co-residency can achieve them, while the keyed-commitment question is unchanged. Grade and acceptance hold. Cadence instant → instant; checked again immediately.
|
||||
- **2026-09-02** — clean check: acceptance, RISK-REG-0001, and the audit-core keyed-commitment wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z.
|
||||
|
||||
## Evidence inspection — 2026-09-05 (review remains due)
|
||||
|
||||
[RISK-V-0003](../docs/verifications/2026-09-05-open-findings-source-review.md)
|
||||
records a source/inbox inspection. The technical owner still documents the
|
||||
cleartext-hash limitation; no new answer to the existing wait appeared in the
|
||||
fetched risk-nexus inbox. The report now displays this record's existing
|
||||
accepter, ending condition, determination and review date as a recorded
|
||||
acceptance obligation, rather than inventing a fix plan to fill `fix_tracking`.
|
||||
|
||||
This is not a clean check or a renewed acceptance. Whether the real-person or
|
||||
counterparty condition has fired, and the substantive regulatory review, remain
|
||||
unestablished here. The overdue review, existing grade and acceptance terms are
|
||||
preserved; absence of a new inbox answer cannot certify the condition false.
|
||||
|
|
|
|||
|
|
@ -12,7 +12,9 @@ date_filed: "2026-08-23"
|
|||
system: railiance-platform
|
||||
environment: production
|
||||
fix_owner: railiance-platform
|
||||
fix_tracking: unset
|
||||
fix_tracking: RPF-WP-0029-T02
|
||||
closure_condition: "provider invalidation plus governed ciphertext upload and restore receipts; source fallback removal alone does not lift the embargo"
|
||||
verification: RISK-V-0003
|
||||
# Graded by risk-nexus 2026-09-01 — docs/rulings/2026-09-01-inbox-sweep.md
|
||||
severity: low
|
||||
severity_at_production: low
|
||||
|
|
@ -25,20 +27,20 @@ embargo_condition: "the provider credential is revoked or invalidated and the li
|
|||
embargo_since: "2026-09-01"
|
||||
embargo_review: "2026-09-15"
|
||||
escalation: none
|
||||
last_checked: "2026-09-02T08:11:17Z"
|
||||
next_check: "2026-09-02T09:11:17Z"
|
||||
cadence: 1h
|
||||
clean_streak: 1
|
||||
last_checked: "2026-09-05T00:05:51Z"
|
||||
next_check: "2026-09-05T00:05:51Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
waiting_on:
|
||||
- who: railiance-platform
|
||||
what: "revoke or invalidate the provider credential, remove the source default, name fix tracking, and demonstrate governed ciphertext upload plus restore"
|
||||
what: "complete RPF-WP-0029-T02: revoke or invalidate the provider credential and demonstrate governed ciphertext upload plus restore; source fallback removal is established"
|
||||
since: "2026-09-01"
|
||||
would_change: "the finding becomes fixed and the embargo lifts"
|
||||
default: "the low grade and embargo stand; missing fix tracking is recorded as a stalled remediation"
|
||||
default: "the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation"
|
||||
default_at: "2026-09-15"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-09-01-A
|
||||
checked_by: "grok/risk-nexus"
|
||||
checked_by: "codex/risk-nexus"
|
||||
---
|
||||
|
||||
# RISK-F-0010 — Forgejo backup source embeds a WebDAV credential default
|
||||
|
|
@ -118,7 +120,21 @@ does not soften the assessment.
|
|||
|
||||
Reasoning: `docs/rulings/2026-09-01-inbox-sweep.md`.
|
||||
|
||||
## Source remediation reconciled — 2026-09-05
|
||||
|
||||
RPF-WP-0029-T01 records source fallback removal and fail-closed input checks.
|
||||
This register confirmed the named fallback is absent in the current script
|
||||
without displaying or testing any credential. RPF-WP-0029-T02 remains `wait`
|
||||
for provider invalidation and governed encrypted upload/restore receipts.
|
||||
|
||||
[RISK-V-0003](../docs/verifications/2026-09-05-open-findings-source-review.md)
|
||||
records the boundary: source removal does not establish invalidation of the
|
||||
predecessor. Open, low, embargoed and no escalation remain appropriate on the
|
||||
available evidence. The 2026-09-15 review/default is unchanged. The historical
|
||||
source-default statements above describe the earlier assessments.
|
||||
|
||||
## Reviews
|
||||
|
||||
- **2026-09-01** — graded from the filed report and a redacted current-source check. The literal default remains; no fix record was found. Cadence starts at instant.
|
||||
- **2026-09-02** — clean check: literal source default remains; no fix tracking; embargo and 2026-09-15 wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z.
|
||||
- **2026-09-05** — not clean: Confirmed source fallback removal and RPF-WP-0029 tracking; provider invalidation and encrypted upload/restore receipts remain pending. Low grade and embargo retained; see RISK-V-0003. Cadence 1h → instant; checked again immediately.
|
||||
|
|
|
|||
|
|
@ -12,7 +12,9 @@ date_filed: "2026-09-02"
|
|||
system: qonto-assistant
|
||||
environment: production
|
||||
fix_owner: qonto-assistant
|
||||
fix_tracking: unset
|
||||
fix_tracking: QONTO-WP-0005 / KG-WP-0005-T03
|
||||
closure_condition: "authorized deployed-instance capture accepted by kings-guard: heartbeat timing, sequence continuity and same-instance reconciliation"
|
||||
verification: RISK-V-0003
|
||||
# Graded by risk-nexus 2026-09-02 — docs/rulings/2026-09-02-qonto-deny-stream.md
|
||||
severity: medium
|
||||
severity_at_production: medium
|
||||
|
|
@ -29,20 +31,20 @@ revision: "graded-1"
|
|||
last_reviewed: "2026-09-02"
|
||||
review_interval: 6m
|
||||
escalation: none
|
||||
last_checked: "2026-09-02T07:20:00Z"
|
||||
next_check: "2026-09-02T07:20:00Z"
|
||||
last_checked: "2026-09-05T00:05:51Z"
|
||||
next_check: "2026-09-05T00:05:51Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
waiting_on:
|
||||
- who: qonto-assistant
|
||||
what: "publish a heartbeat or emission-cadence declaration and a reconciliation view for the audit.deny stream, or reject that obligation"
|
||||
what: "supply runtime-owner deployed-instance capture for kings-guard acceptance under KG-WP-0005-T03; source cadence and reconciliation now exist"
|
||||
since: "2026-09-02"
|
||||
would_change: "a published cadence plus a reconciliation view would let a later observation support completeness; a rejection keeps the grade and records that estate observation must not treat the stream as complete"
|
||||
default: "the medium grade stands; missing cadence is recorded as a stalled remediation, and observation remains staffed with completeness pending"
|
||||
would_change: "accepted deployed-instance evidence supports bounded stream completeness and permits closure; source-only evidence keeps the finding open"
|
||||
default: "the medium grade stands; missing deployed acceptance is recorded as a stalled remediation, and observation remains staffed with completeness pending"
|
||||
default_at: "2026-09-16"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-09-02-A
|
||||
checked_by: "grok/risk-nexus"
|
||||
checked_by: "codex/risk-nexus"
|
||||
---
|
||||
|
||||
# RISK-F-0011 — qonto-assistant audit.deny stream completeness is not established
|
||||
|
|
@ -141,6 +143,22 @@ wait makes that last statement expire.
|
|||
|
||||
Reasoning: `docs/rulings/2026-09-02-qonto-deny-stream.md`.
|
||||
|
||||
## Source remediation reconciled — 2026-09-05
|
||||
|
||||
The missing-source statements above describe intake, not the current checkout.
|
||||
QONTO-WP-0005 is finished: cadence, heartbeat lifecycle, instance/sequence fields
|
||||
and an identity-checked reconciliation view now exist. King's Guard's local
|
||||
source-path checks are recorded complete, but KG-WP-0005-T03 waits for an
|
||||
authorized deployed capture. Notice `c6442eef-34fc-46a7-9639-10f2cd6120fc`
|
||||
explicitly requests independent deployed-stream acceptance before closure.
|
||||
|
||||
[RISK-V-0003](../docs/verifications/2026-09-05-open-findings-source-review.md)
|
||||
records the inspected evidence and bounded acceptance requirements. Status
|
||||
remains open, medium, public, no escalation: deployed completeness is still
|
||||
unknown, with no evidence of suppression or an authorization bypass. The
|
||||
2026-09-16 default is retained, now describing the actual remaining obligation.
|
||||
|
||||
## Reviews
|
||||
|
||||
- **2026-09-02** — graded from the Gate House intake, the named conformance review, and a current-source check of qonto-assistant. Local lockout is in-process; the emitted deny stream still has no cadence or reconciliation view. Cadence starts at instant.
|
||||
- **2026-09-05** — not clean: Reviewed owner notice, cadence/logger/endpoint and KG-WP-0005; source remediation exists, deployed-instance acceptance remains pending under KG-WP-0005-T03. See RISK-V-0003. Cadence instant → instant; checked again immediately.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue