whitehat-security/evidence
tegwick 75deaf073f Admit fixture-asm for ASM T-06 and calibrate known-bad replay
Reassess the T-06 blocker against the secrets-engine consume client.
Gate House cited 3cd9955; approval_consume.py first appears at 4b4d556.
An in-process CAS disables different-digest conflict for known-bad and
drives consume_approval through a mock opener. No network or OpenBao.
Live asm-t06 stays pending.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
2026-09-02 10:10:53 +02:00
..
offline-asm-t06-calibration.json Admit fixture-asm for ASM T-06 and calibrate known-bad replay 2026-09-02 10:10:53 +02:00
offline-calibration.json Add governed test plane and close T04/T08 2026-08-22 00:44:21 +02:00
offline-capacity-calibration.json Finish WHITEHAT-WP-0001 and own live residuals in WP-0006 2026-09-01 20:26:47 +02:00
offline-e3-calibration.json Admit E3 and capacity on the test plane 2026-08-22 09:40:27 +02:00
README.md Admit fixture-asm for ASM T-06 and calibrate known-bad replay 2026-09-02 10:10:53 +02:00
WH-ENG-20260822-AUDIT-E2-02-abort.json Add WHITEHAT-WP-0002 receipt example, CLI coverage, and abort records 2026-08-22 21:40:33 +02:00
WH-ENG-20260822-AUDIT-E2-03.json Record the audit-core E2-03 target pass and close T03/T07 2026-08-23 00:42:31 +02:00

Evidence

This directory stores sanitized run artifacts. offline-calibration.json, offline-e3-calibration.json, offline-capacity-calibration.json, and offline-asm-t06-calibration.json are generated from repository-created fixtures and prove only that the harness distinguishes known-good from known-bad behavior. They are not target assurance. WH-ENG-20260822-AUDIT-E2-02-abort.json is an abort record (evidence_class: abort), not an E2 pass or finding. WH-ENG-20260822-AUDIT-E2-03.json is the first authorized target pass; SHA-256 2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593. A pass means only that the attempted attacks did not work.

Before committing target evidence, verify that it contains no response body, credential, database URL, real tenant identifier, or real tenant value. A run-local digest is allowed; it must not be reusable across runs as a data oracle.