Files
summercms/scripts/check-phase12.sh
Jakub Zych 6f4386c2f9 chore(12-05): add the fail-closed Phase 12 gate
scripts/check-phase12.sh, modelled on check-phase11.sh:
- --go: vet and test both repositories, golang.org/x/image pinned at v0.46.0
- --parity: 99 ported routes in the manifest, TestParityCorpus with its
  coverage subtest, all four broadcast goldens, both Nuxt flows,
  check_corpus --require-recorded --check-secrets and a secret scan of the
  fuzz seed corpus
- --named: every test 12-VALIDATION.md names, by exact name, the fonoteka
  plugin's under -race
- --removal: 25 anchor-exact mutations behind 12-SECURITY-REVIEW.md, each
  required to fail its named test on an assertion; a dirty file is
  refused and every file is restored and compared with cmp
- --coverage: an 80% floor per Phase 12 package in both repositories
- --evidence: one review row per T-12 threat, a removal row per high
  mitigated threat, a green validation file naming only tests the gate runs
- --self-test: every detector, plant and harness branch fails closed
2026-10-02 16:39:03 +02:00

38 KiB
Executable File