whitehat-security/evidence/README.md
tegwick 75deaf073f Admit fixture-asm for ASM T-06 and calibrate known-bad replay
Reassess the T-06 blocker against the secrets-engine consume client.
Gate House cited 3cd9955; approval_consume.py first appears at 4b4d556.
An in-process CAS disables different-digest conflict for known-bad and
drives consume_approval through a mock opener. No network or OpenBao.
Live asm-t06 stays pending.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
2026-09-02 10:10:53 +02:00

17 lines
911 B
Markdown

# Evidence
This directory stores sanitized run artifacts. `offline-calibration.json`,
`offline-e3-calibration.json`, `offline-capacity-calibration.json`, and
`offline-asm-t06-calibration.json` are generated from repository-created
fixtures and prove only that the harness distinguishes known-good from
known-bad behavior. They are not target assurance. `WH-ENG-20260822-AUDIT-E2-02-abort.json`
is an abort record (`evidence_class: abort`), not an E2 pass or finding.
`WH-ENG-20260822-AUDIT-E2-03.json` is the first authorized target pass; SHA-256
`2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593`. A pass
means only that the attempted attacks did not work.
Before committing target evidence, verify that it contains no response body,
credential, database URL, real tenant identifier, or real tenant value. A
run-local digest is allowed; it must not be reusable across runs as a data
oracle.