Some checks failed
Tests / conformance test (macos-latest, 24) (pull_request) Blocked by required conditions
Tests / conformance test (windows-latest, 24, shard 1/3) (pull_request) Blocked by required conditions
Tests / conformance test (windows-latest, 24, shard 2/3) (pull_request) Blocked by required conditions
Tests / conformance test (windows-latest, 24, shard 3/3) (pull_request) Blocked by required conditions
Tests / Required tests (pull_request) Blocked by required conditions
Changeset Required / PR mergeability (pull_request) Successful in 17s
Default Flip Documentation / PR mergeability (pull_request) Successful in 10s
Dependabot Auto-Merge / auto-merge (pull_request) Has been skipped
Docs Required / PR mergeability (pull_request) Successful in 10s
Mutation Testing / PR mergeability (pull_request) Successful in 10s
Security Scan / PR mergeability (pull_request) Successful in 12s
Tests / PR mergeability (pull_request) Successful in 9s
Tests / Base branch health (pull_request) Successful in 10s
Tests / Detect test scope (pull_request) Successful in 17s
PR Target Validator / validate-target (pull_request_target) Successful in 14s
Branch Cleanup / Delete merged PR branch (pull_request) Failing after 10s
Branch Cleanup / Weekly orphaned branch sweep (pull_request) Has been skipped
Changeset Required / changeset-lint (pull_request) Successful in 29s
Default Flip Documentation / default-flip-documentation (pull_request) Successful in 30s
Docs Required / docs-lint (pull_request) Successful in 5m1s
Mutation Testing / Detect changed covered modules (pull_request) Successful in 19s
Security Scan / security (pull_request) Successful in 5m5s
Tests / lint-tests (pull_request) Failing after 1m48s
Tests / plugin-validate (pull_request) Successful in 1m4s
Tests / test (ubuntu-latest, 24, shard 1/3) (pull_request) Failing after 19s
Tests / test (ubuntu-latest, 24, shard 2/3) (pull_request) Failing after 20s
Tests / test (ubuntu-latest, 24, shard 3/3) (pull_request) Failing after 19s
Tests / test (ubuntu-latest, 24) (pull_request) Failing after 20s
Tests / test (inert CI) (pull_request) Has been skipped
Tests / QA loop walk (smell ratchet) (pull_request) Failing after 20s
Mutation Testing / Stryker (${{ matrix.name }}) (pull_request) Has been skipped
Tests / Coverage gate (merged shards) (pull_request) Has been skipped
Tests / Publish emitted-baseline artifact (pull_request) Has been skipped
Mutation Testing / Stryker mutation score (changed files only) (pull_request) Has been skipped
100 lines
2.3 KiB
JSON
100 lines
2.3 KiB
JSON
{
|
|
"id": "security",
|
|
"role": "feature",
|
|
"version": "2.0.0",
|
|
"title": "Security enforcement",
|
|
"description": "Threat mitigation verification and ship-time security blocking for phases with security enforcement enabled.",
|
|
"tier": "full",
|
|
"requires": [],
|
|
"engines": {
|
|
"msd": ">=1.6.0"
|
|
},
|
|
"runtimeCompat": {
|
|
"supported": [
|
|
"*"
|
|
],
|
|
"unsupported": []
|
|
},
|
|
"skills": [
|
|
"secure-phase"
|
|
],
|
|
"agents": [
|
|
"msd-security-auditor"
|
|
],
|
|
"hooks": [],
|
|
"config": {
|
|
"workflow.security_enforcement": {
|
|
"type": "boolean",
|
|
"default": true,
|
|
"description": "Enable security threat-mitigation verification before phase advancement."
|
|
},
|
|
"workflow.security_asvs_level": {
|
|
"type": "number",
|
|
"default": 1,
|
|
"description": "OWASP ASVS level used by security review guidance."
|
|
},
|
|
"workflow.security_block_on": {
|
|
"type": "enum",
|
|
"values": [
|
|
"critical",
|
|
"high",
|
|
"medium",
|
|
"low",
|
|
"none"
|
|
],
|
|
"default": "high",
|
|
"description": "Minimum open threat severity that blocks advancement."
|
|
}
|
|
},
|
|
"steps": [
|
|
{
|
|
"point": "verify:post",
|
|
"ref": {
|
|
"skill": "secure-phase"
|
|
},
|
|
"produces": [
|
|
"SECURITY.md"
|
|
],
|
|
"consumes": [
|
|
"SUMMARY.md"
|
|
],
|
|
"when": "workflow.security_enforcement",
|
|
"onError": "halt"
|
|
}
|
|
],
|
|
"contributions": [
|
|
{
|
|
"point": "plan:pre",
|
|
"into": "planner",
|
|
"fragment": {
|
|
"inline": "Each PLAN.md must include a <threat_model> block when security enforcement is active. Use the configured ASVS level and blocking threshold from workflow.security_asvs_level and workflow.security_block_on."
|
|
},
|
|
"configValues": {
|
|
"security_asvs_level": "workflow.security_asvs_level",
|
|
"security_block_on": "workflow.security_block_on"
|
|
},
|
|
"produces": [],
|
|
"consumes": [
|
|
"CONTEXT.md"
|
|
],
|
|
"when": "workflow.security_enforcement"
|
|
}
|
|
],
|
|
"gates": [
|
|
{
|
|
"point": "ship:pre",
|
|
"check": {
|
|
"predicate": {
|
|
"kind": "artifact-frontmatter-equals",
|
|
"artifact": "SECURITY.md",
|
|
"field": "threats_open",
|
|
"equals": 0
|
|
}
|
|
},
|
|
"when": "workflow.security_enforcement",
|
|
"blocking": true,
|
|
"onError": "halt"
|
|
}
|
|
]
|
|
}
|