From ce8fb70afd40f43afec6c05c9467bcc716dceb9c Mon Sep 17 00:00:00 2001 From: tegwick Date: Thu, 20 Aug 2026 22:44:46 +0200 Subject: [PATCH] Type the publication handover as a wait like any other policy-nexus owes entries; if none arrive by 2026-09-17 the findings sit as disclosure: public with no address, which this register records as a claim rather than a publication. Same rule we apply to everyone else. Co-Authored-By: Claude Opus 5 --- REGISTER.md | 1 + WORK-RECORDS.md | 8 ++++---- .../RISK-F-0001-flex-auth-unauthenticated-check.md | 12 ++++++++++-- 3 files changed, 15 insertions(+), 6 deletions(-) diff --git a/REGISTER.md b/REGISTER.md index f51948f..ffa23de 100644 --- a/REGISTER.md +++ b/REGISTER.md @@ -41,6 +41,7 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`. | RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 | | RISK-F-0004 | tenant-engine | grade rises if the log carries tenant payload rather than metadata | grade stands as recorded; absent fix tracking is recorded as a stall | 2026-09-03 | | RISK-F-0002 | ops-warden | if it admits no ingress, enabling the gate stops all signing — an availability blocker, not a risk one | the register records the ordering as unverified and re-raises it; the finding stands at medium | 2026-08-27 | +| RISK-F-0001 | policy-nexus | publication: published plus the permanent URL comes back onto each record | the findings stay disclosure: public with no address, which the register records as a claim rather than a publication | 2026-09-17 | ## Embargoes diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 0d79fc0..3b5c124 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -9,7 +9,7 @@ | Kind | ID | Status | Lane | Source | | --- | --- | --- | --- | --- | | workplan | RISK-WP-0001 | active | — | workplans/RISK-WP-0001-make-the-register-decidable.md | -| workplan | RISK-WP-0002 | proposed | — | workplans/RISK-WP-0002-publication-handover.md | +| workplan | RISK-WP-0002 | active | — | workplans/RISK-WP-0002-publication-handover.md | | workplan | RISK-WP-0003 | proposed | — | workplans/RISK-WP-0003-regulatory-intake.md | | workplan | RISK-WP-0004 | finished | — | workplans/RISK-WP-0004-run-the-register.md | | task | RISK-WP-0001-T01 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md | @@ -20,9 +20,9 @@ | task | RISK-WP-0001-T06 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md | | task | RISK-WP-0001-T07 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md | | task | RISK-WP-0001-T08 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md | -| task | RISK-WP-0002-T01 | todo | — | workplans/RISK-WP-0002-publication-handover.md | -| task | RISK-WP-0002-T02 | todo | — | workplans/RISK-WP-0002-publication-handover.md | -| task | RISK-WP-0002-T03 | todo | — | workplans/RISK-WP-0002-publication-handover.md | +| task | RISK-WP-0002-T01 | progress | — | workplans/RISK-WP-0002-publication-handover.md | +| task | RISK-WP-0002-T02 | done | — | workplans/RISK-WP-0002-publication-handover.md | +| task | RISK-WP-0002-T03 | done | — | workplans/RISK-WP-0002-publication-handover.md | | task | RISK-WP-0003-T01 | todo | — | workplans/RISK-WP-0003-regulatory-intake.md | | task | RISK-WP-0003-T02 | todo | — | workplans/RISK-WP-0003-regulatory-intake.md | | task | RISK-WP-0003-T03 | todo | — | workplans/RISK-WP-0003-regulatory-intake.md | diff --git a/findings/RISK-F-0001-flex-auth-unauthenticated-check.md b/findings/RISK-F-0001-flex-auth-unauthenticated-check.md index a8c2de7..a9030f0 100644 --- a/findings/RISK-F-0001-flex-auth-unauthenticated-check.md +++ b/findings/RISK-F-0001-flex-auth-unauthenticated-check.md @@ -34,10 +34,17 @@ escalation: withdrawn escalation_trigger: 1 escalation_status: withdrawn-before-sending date_fixed: "2026-08-19" -last_checked: "2026-08-19T21:30:00Z" -next_check: "2026-08-19T21:30:00Z" # due now: the ladder starts at instant +last_checked: "2026-08-20T20:44:46Z" +next_check: "2026-08-20T20:44:46Z" cadence: instant clean_streak: 0 +waiting_on: + - who: policy-nexus + what: "publication.json entries for RISK-F-0001, RISK-F-0008 and the five public method documents" + since: "2026-08-20" + would_change: "publication: published plus the permanent URL comes back onto each record" + default: "the findings stay disclosure: public with no address, which the register records as a claim rather than a publication" + default_at: "2026-09-17" graded_by: risk-nexus ruling: RISK-RULING-2026-08-19 --- @@ -220,3 +227,4 @@ inbox is now step 0 of grading and question 0 of every review — see - **2026-08-19** — re-graded `high`, closed `fixed`, disclosure `public`, escalation withdrawn. Remaining: handover to `policy-nexus`; the CNI enforcement question is `flex-auth`'s and no longer this finding's. +- **2026-08-20** — not clean: Publication handover requested; publication front-matter applied and the wait on policy-nexus typed. Cadence instant → instant; checked again immediately.