workflow.security_block_on was documented as the minimum threat severity that blocks advancement, but threats carried no severity and the auditor's threats_open count (the SECURITY.md gate field) counted every open threat regardless of severity — so the threshold had no effect, and the auditor's block_on vocabulary (open/unregistered/none) did not even match the config enum (critical/high/medium/low/none). - planner: add a Severity column to the STRIDE threat register; assign severity per threat. - auditor: read severity; reconcile the <config> block_on domain to the severity enum; redefine threats_open as the count of OPEN threats whose severity is at or above block_on (none => 0). Below-threshold opens are reported as non-blocking and excluded from threats_open. - SECURITY.md template + planning-config.md reconciled. No gate-check site changed: threats_open == 0 stays the gate everywhere; only its computation is now severity-filtered. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
1.8 KiB
1.8 KiB
phase, slug, status, threats_open, asvs_level, created
| phase | slug | status | threats_open | asvs_level | created | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
draft | 0 | 1 |
|
Phase {N} — Security
Per-phase security contract: threat register, accepted risks, and audit trail.
Trust Boundaries
| Boundary | Description | Data Crossing |
|---|---|---|
| {boundary} | {description} | {data type / sensitivity} |
Threat Register
| Threat ID | Category | Component | Severity | Disposition | Mitigation | Status |
|---|---|---|---|---|---|---|
| T-{N}-01 | {STRIDE category} | {component} | {critical / high / medium / low} | {mitigate / accept / transfer} | {control or reference} | open |
Status: open · closed · open — below {block_on} threshold (non-blocking) Severity: critical > high > medium > low — only open threats at or above workflow.security_block_on count toward threats_open Disposition: mitigate (implementation required) · accept (documented risk) · transfer (third-party)
Accepted Risks Log
| Risk ID | Threat Ref | Rationale | Accepted By | Date |
|---|
Accepted risks do not resurface in future audit runs.
If none: "No accepted risks."
Security Audit Trail
| Audit Date | Threats Total | Closed | Open | Run By |
|---|---|---|---|---|
| {YYYY-MM-DD} | {N} | {N} | {N} | {name / agent} |
Sign-Off
- All threats have a disposition (mitigate / accept / transfer)
- Accepted risks documented in Accepted Risks Log
threats_open: 0confirmedstatus: verifiedset in frontmatter
Approval: {pending / verified YYYY-MM-DD}