Severity (impact x likelihood, fidelity modifier for controls that lie, headline-vs-constraint, build-mode double grade, the floor), disclosure (publish/embargoed/restricted, and the build-mode deferral re-taken and narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers settled plus an ordering-hazard trigger the RISK-F-0002 case forced; proposed, awaiting the custodian), review (intervals, what a review is, what missing one produces, the production re-score). Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002 medium with a high constraint on RISK-F-0001's remediation, filed as a peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no escalation. No unset field remains. REGISTER.md is generated; make check reports overdue, stalled, ungraded and unanswered escalations without changing anything. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
37 lines
2.1 KiB
Markdown
37 lines
2.1 KiB
Markdown
# Register
|
|
|
|
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-08-19.
|
|
|
|
3 open of 3 findings; 0 notes below the floor.
|
|
|
|
## Findings
|
|
|
|
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Review by |
|
|
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
|
| [RISK-F-0003](findings/RISK-F-0003-ops-warden-read-boundary-ungraded-lanes.md) | ops-warden agent read-boundary does not fire on ungraded catalog lanes | ops-warden | **high** | embargoed | none | ops-warden | open | 2026-09-18 |
|
|
| [RISK-F-0002](findings/RISK-F-0002-ops-warden-sign-ungated.md) | ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe | ops-warden | medium | embargoed | **required** (t6, pending-operator) | ops-warden | open | 2026-11-17 |
|
|
| [RISK-F-0001](findings/RISK-F-0001-flex-auth-unauthenticated-check.md) | flex-auth /v1/check authenticates no caller | flex-auth | **critical** | embargoed | **required** (t1, pending-operator) | flex-auth | open | 2026-08-26 |
|
|
|
|
## Constraints
|
|
|
|
Hazards created by acting in the wrong order. Each binds another finding's remediation.
|
|
|
|
| From | Binds | Severity | Constraint |
|
|
| --- | --- | --- | --- |
|
|
| RISK-F-0002 | RISK-F-0001 | **high** | policy.enabled must not be turned on while flex-auth /v1/check answers unauthenticated callers — the gate would sign a false attestation |
|
|
|
|
## Embargoes
|
|
|
|
Held from publication with a stated condition. A hold with no moving condition is a stall.
|
|
|
|
| Finding | Since | Lifts when | Re-decided |
|
|
| --- | --- | --- | --- |
|
|
| RISK-F-0003 | 2026-08-19 | the five exec_capable lanes graded under WARDEN-WP-0032-T05 | 2026-09-18 |
|
|
| RISK-F-0002 | 2026-08-19 | FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production | 2026-11-17 |
|
|
| RISK-F-0001 | 2026-08-19 | FLEX-WP-0015-T02 ships to production | 2026-08-26 |
|
|
|
|
## How to read this
|
|
|
|
Severity is `docs/method/severity.md`; disclosure `docs/method/disclosure.md`;
|
|
escalation `docs/method/escalation.md`; review dates `docs/method/review.md`.
|
|
A constraint may be graded higher than the finding that carries it — read both.
|