docs(phase-10.2): add security threat verification

This commit is contained in:
Jakub Zych
2026-09-28 13:39:14 +02:00
parent 02712ad651
commit da6f0b2eff

View File

@@ -0,0 +1,56 @@
---
phase: "10.2"
slug: nest-framework-packages-under-modules-and-write-run-docs
status: verified
threats_open: 0
asvs_level: 1
created: "2026-09-28"
---
# Phase 10.2 — Security
## Trust Boundaries
| Boundary | Description | Data Crossing |
|----------|-------------|---------------|
| Importer → framework package path | A stale import may fail the build or resolve a shadow root package | Go source and generated import paths |
| Validation scripts → repository tree | A stale or over-broad scan may pass or fail for the wrong reason | Tracked source paths and gate results |
| Application replace → framework tree | Replace directives must keep pointing at the local framework repository | Local module resolution |
| Operator → onboarding docs | Documentation must not imply an unsupported production runbook or disclose secrets | Setup and cutover instructions |
| Module docs → public Git | Module descriptions must not reproduce internal planning material | Public documentation |
## Threat Register
| Threat ID | Category | Component | Severity | Disposition | Mitigation | Status |
|-----------|----------|-----------|----------|-------------|------------|--------|
| T-10.2-01 | Tampering | Root package directories | high | mitigate | All 18 directories were history-preserving moves; layout gate rejects any root shadow directory | closed |
| T-10.2-02 | Tampering | Go/template import paths | high | mitigate | Both repositories compile and the tracked-source gate rejects root-form imports while excluding historical planning artifacts | closed |
| T-10.2-03 | Tampering | Phase/admin scripts and Vite output | high | mitigate | Script, OpenAPI, dist, fixture, and Vite paths point at `modules/`; build and full gate pass | closed |
| T-10.2-04 | Tampering | `go.mod` / `go.work` | medium | mitigate | One root module remains; no package-local `go.mod` exists and workspace entries remain scoped to root/examples | closed |
| T-10.2-05 | Tampering | Go package names | medium | mitigate | Moves retain the beach package declarations; tests compile every controlled consumer | closed |
| T-10.2-06 | Information Disclosure | Root README run/cutover guidance | high | mitigate | Root docs keep app configuration in Fonoteka, provide no production secrets, and guard Phase 15 cutover language | closed |
| T-10.2-07 | Tampering | `scripts/check-phase10.2.sh` | high | mitigate | Gate fails closed on layout, imports, docs, and stale status; scratch self-test plants every detector including tracked historical evidence | closed |
| T-10.2-08 | Information Disclosure | Module READMEs | low | accept | Accepted residual: short public descriptions expose only existing exported concepts; planning prose is excluded | closed |
| T-10.2-09 | Repudiation | Skipped gate self-test | medium | mitigate | Plan verification and this execution ran `--self-test` independently before `--all`; both results are recorded | closed |
| T-10.2-SC | Tampering | Dependency installation | high | mitigate | Git diff shows no Go or npm dependency-file change and execution installed nothing | closed |
## Accepted Risks Log
| Risk ID | Threat Ref | Rationale | Accepted By | Date |
|---------|------------|-----------|-------------|------|
| AR-10.2-01 | T-10.2-08 | One-paragraph public module summaries repeat only exported package concepts and improve onboarding; no internal planning prose is copied | Phase plan | 2026-09-28 |
## Security Audit Trail
| Audit Date | Threats Total | Closed | Open | Run By |
|------------|---------------|--------|------|--------|
| 2026-09-28 | 10 | 10 | 0 | Codex / GSD security L1 |
## Sign-Off
- [x] All threats have a disposition.
- [x] Accepted risks are documented.
- [x] `threats_open: 0` is confirmed.
- [x] `status: verified` is set.
**Approval:** verified 2026-09-28