--- phase: "10.2" slug: nest-framework-packages-under-modules-and-write-run-docs status: verified threats_open: 0 asvs_level: 1 created: "2026-09-28" --- # Phase 10.2 — Security ## Trust Boundaries | Boundary | Description | Data Crossing | |----------|-------------|---------------| | Importer → framework package path | A stale import may fail the build or resolve a shadow root package | Go source and generated import paths | | Validation scripts → repository tree | A stale or over-broad scan may pass or fail for the wrong reason | Tracked source paths and gate results | | Application replace → framework tree | Replace directives must keep pointing at the local framework repository | Local module resolution | | Operator → onboarding docs | Documentation must not imply an unsupported production runbook or disclose secrets | Setup and cutover instructions | | Module docs → public Git | Module descriptions must not reproduce internal planning material | Public documentation | ## Threat Register | Threat ID | Category | Component | Severity | Disposition | Mitigation | Status | |-----------|----------|-----------|----------|-------------|------------|--------| | T-10.2-01 | Tampering | Root package directories | high | mitigate | All 18 directories were history-preserving moves; layout gate rejects any root shadow directory | closed | | T-10.2-02 | Tampering | Go/template import paths | high | mitigate | Both repositories compile and the tracked-source gate rejects root-form imports while excluding historical planning artifacts | closed | | T-10.2-03 | Tampering | Phase/admin scripts and Vite output | high | mitigate | Script, OpenAPI, dist, fixture, and Vite paths point at `modules/`; build and full gate pass | closed | | T-10.2-04 | Tampering | `go.mod` / `go.work` | medium | mitigate | One root module remains; no package-local `go.mod` exists and workspace entries remain scoped to root/examples | closed | | T-10.2-05 | Tampering | Go package names | medium | mitigate | Moves retain the beach package declarations; tests compile every controlled consumer | closed | | T-10.2-06 | Information Disclosure | Root README run/cutover guidance | high | mitigate | Root docs keep app configuration in Fonoteka, provide no production secrets, and guard Phase 15 cutover language | closed | | T-10.2-07 | Tampering | `scripts/check-phase10.2.sh` | high | mitigate | Gate fails closed on layout, imports, docs, and stale status; scratch self-test plants every detector including tracked historical evidence | closed | | T-10.2-08 | Information Disclosure | Module READMEs | low | accept | Accepted residual: short public descriptions expose only existing exported concepts; planning prose is excluded | closed | | T-10.2-09 | Repudiation | Skipped gate self-test | medium | mitigate | Plan verification and this execution ran `--self-test` independently before `--all`; both results are recorded | closed | | T-10.2-SC | Tampering | Dependency installation | high | mitigate | Git diff shows no Go or npm dependency-file change and execution installed nothing | closed | ## Accepted Risks Log | Risk ID | Threat Ref | Rationale | Accepted By | Date | |---------|------------|-----------|-------------|------| | AR-10.2-01 | T-10.2-08 | One-paragraph public module summaries repeat only exported package concepts and improve onboarding; no internal planning prose is copied | Phase plan | 2026-09-28 | ## Security Audit Trail | Audit Date | Threats Total | Closed | Open | Run By | |------------|---------------|--------|------|--------| | 2026-09-28 | 10 | 10 | 0 | Codex / GSD security L1 | ## Sign-Off - [x] All threats have a disposition. - [x] Accepted risks are documented. - [x] `threats_open: 0` is confirmed. - [x] `status: verified` is set. **Approval:** verified 2026-09-28