From da6f0b2effcd32da3252c73a5c028f672558e06f Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Mon, 28 Sep 2026 13:39:14 +0200 Subject: [PATCH] docs(phase-10.2): add security threat verification --- .../10.2-SECURITY.md | 56 +++++++++++++++++++ 1 file changed, 56 insertions(+) create mode 100644 .planning/phases/10.2-nest-framework-packages-under-modules-and-write-run-docs/10.2-SECURITY.md diff --git a/.planning/phases/10.2-nest-framework-packages-under-modules-and-write-run-docs/10.2-SECURITY.md b/.planning/phases/10.2-nest-framework-packages-under-modules-and-write-run-docs/10.2-SECURITY.md new file mode 100644 index 0000000..a11d052 --- /dev/null +++ b/.planning/phases/10.2-nest-framework-packages-under-modules-and-write-run-docs/10.2-SECURITY.md @@ -0,0 +1,56 @@ +--- +phase: "10.2" +slug: nest-framework-packages-under-modules-and-write-run-docs +status: verified +threats_open: 0 +asvs_level: 1 +created: "2026-09-28" +--- + +# Phase 10.2 — Security + +## Trust Boundaries + +| Boundary | Description | Data Crossing | +|----------|-------------|---------------| +| Importer → framework package path | A stale import may fail the build or resolve a shadow root package | Go source and generated import paths | +| Validation scripts → repository tree | A stale or over-broad scan may pass or fail for the wrong reason | Tracked source paths and gate results | +| Application replace → framework tree | Replace directives must keep pointing at the local framework repository | Local module resolution | +| Operator → onboarding docs | Documentation must not imply an unsupported production runbook or disclose secrets | Setup and cutover instructions | +| Module docs → public Git | Module descriptions must not reproduce internal planning material | Public documentation | + +## Threat Register + +| Threat ID | Category | Component | Severity | Disposition | Mitigation | Status | +|-----------|----------|-----------|----------|-------------|------------|--------| +| T-10.2-01 | Tampering | Root package directories | high | mitigate | All 18 directories were history-preserving moves; layout gate rejects any root shadow directory | closed | +| T-10.2-02 | Tampering | Go/template import paths | high | mitigate | Both repositories compile and the tracked-source gate rejects root-form imports while excluding historical planning artifacts | closed | +| T-10.2-03 | Tampering | Phase/admin scripts and Vite output | high | mitigate | Script, OpenAPI, dist, fixture, and Vite paths point at `modules/`; build and full gate pass | closed | +| T-10.2-04 | Tampering | `go.mod` / `go.work` | medium | mitigate | One root module remains; no package-local `go.mod` exists and workspace entries remain scoped to root/examples | closed | +| T-10.2-05 | Tampering | Go package names | medium | mitigate | Moves retain the beach package declarations; tests compile every controlled consumer | closed | +| T-10.2-06 | Information Disclosure | Root README run/cutover guidance | high | mitigate | Root docs keep app configuration in Fonoteka, provide no production secrets, and guard Phase 15 cutover language | closed | +| T-10.2-07 | Tampering | `scripts/check-phase10.2.sh` | high | mitigate | Gate fails closed on layout, imports, docs, and stale status; scratch self-test plants every detector including tracked historical evidence | closed | +| T-10.2-08 | Information Disclosure | Module READMEs | low | accept | Accepted residual: short public descriptions expose only existing exported concepts; planning prose is excluded | closed | +| T-10.2-09 | Repudiation | Skipped gate self-test | medium | mitigate | Plan verification and this execution ran `--self-test` independently before `--all`; both results are recorded | closed | +| T-10.2-SC | Tampering | Dependency installation | high | mitigate | Git diff shows no Go or npm dependency-file change and execution installed nothing | closed | + +## Accepted Risks Log + +| Risk ID | Threat Ref | Rationale | Accepted By | Date | +|---------|------------|-----------|-------------|------| +| AR-10.2-01 | T-10.2-08 | One-paragraph public module summaries repeat only exported package concepts and improve onboarding; no internal planning prose is copied | Phase plan | 2026-09-28 | + +## Security Audit Trail + +| Audit Date | Threats Total | Closed | Open | Run By | +|------------|---------------|--------|------|--------| +| 2026-09-28 | 10 | 10 | 0 | Codex / GSD security L1 | + +## Sign-Off + +- [x] All threats have a disposition. +- [x] Accepted risks are documented. +- [x] `threats_open: 0` is confirmed. +- [x] `status: verified` is set. + +**Approval:** verified 2026-09-28