RISK-WP-0002: findings publish whole; method docs public except escalation

Operator ruled both. Findings publish as the file a reader gets —
including RISK-F-0001's record that this register graded it critical
while its fix notice sat unread. A summary would be a second document per
finding kept in sync by hand, and drift is the failure this repo most
distrusts; and a published register containing only other repos' defects
reads as an accusation, while one containing its own reads as a record.

Method docs public except escalation, which is restricted because it
names spend thresholds and describes when the operator personally is
interrupted — a map of where attention is scarce, needed by nobody
judging a finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-20 22:43:48 +02:00
parent 7dc8d01a63
commit f0db7c83ca
10 changed files with 112 additions and 10 deletions

View file

@ -20,7 +20,13 @@ likelihood: L2
fidelity_modifier: false
production_rescore: false
disclosure: public
publication: pending-handover
publication: requested
publication_id: risk-f-0001-flex-auth-unauthenticated-check
publication_path: "findings/flex-auth-unauthenticated-check/v1/index.html"
publication_subtitle: "The estate's authorization oracle authenticated no caller for as long as the endpoint existed. Found by reading, not by monitoring; fixed in two days."
revision: "graded-1"
last_reviewed: "2026-08-20"
review_interval: 6m
embargo_condition: "met 2026-08-19 — FLEX-WP-0015 finished, live probes return 401"
embargo_since: "2026-08-19"
embargo_review: "2026-08-19"