Skip to content

feat: standing capability-vulnerability taxonomy check - #231

Merged
chaksaray merged 1 commit into
developfrom
feat/capability-vulnerability-taxonomy-check
Aug 30, 2026
Merged

chaksaray merged 1 commit into
developfrom
feat/capability-vulnerability-taxonomy-check

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Closes #230. Optional schema fields (security_boundary, missing_control, vulnerability_rationale) plus scripts/check_vulnerability_taxonomy.py, following the commit/pin_status (#171) and evidence-vantage (#213, #214) precedent exactly.

Real numbers: 0/80 records currently pass (expected — they all predate this design; the soft-warn default confirms it: WARNING: 80 of 80 record(s) missing capability-vulnerability taxonomy fields). --strict --only AVE-2026-NNNNN is wired into CONTRIBUTING.md's new-record checklist to gate future submissions without retroactively requiring the fields on the existing corpus.

Schema fields added to both schema/ave-record-1.1.0.schema.json (used by validate_records.py) and schema/ave-record.schema.json (used by scripts/build-records.js), kept in sync per the existing convention — confirmed via diff these two files were otherwise identical before this change.

Every new test mutation-checked by hand, not just run once: each of the 7 tests in tests/test_vulnerability_taxonomy.py was confirmed to go red under a targeted reversion of the exact behavior it names, and only that test went red each time. Mutations tried: if not (...) → if False, all() → any(), strict/warn exit-code swap, and removing the --only filter.

Validated:

  • python scripts/validate_records.py: 80/80 still valid
  • python scripts/check_fixtures.py: all pass
  • python scripts/check_vulnerability_taxonomy.py: WARNING, 80/80 missing (expected)
  • python -m pytest tests/ -x -q: 434 passed (427 existing + 7 new)
  • node scripts/build-records.js: builds clean against the updated ave-record.schema.json

CI wiring is its own named step in .github/workflows/tests.yml (Capability-vulnerability taxonomy soft warning), not folded into an existing step whose output would get discarded on a pass — the same wiring-gap lesson from #213.

dist/ intentionally left untouched: regenerating it only bumped generated_at, no real content changed since no record uses the new optional fields yet, and there's no reason to bake another manifest-timestamp collision into this PR.

Adds security_boundary, missing_control, and vulnerability_rationale
as optional record fields, plus check_vulnerability_taxonomy.py
reporting corpus-wide coverage (soft warning) and gating new record
submissions (--strict --only) without retroactively requiring the
fields on the 80 existing records. Same pattern as commit/pin_status
(#171) and the evidence-vantage fields (#213, #214).

Schema fields added to both schema/ave-record-1.1.0.schema.json (used
by validate_records.py) and schema/ave-record.schema.json (used by
scripts/build-records.js), kept in sync per the existing convention.

All 80 records still validate; all 80 currently lack the new fields,
expected given they predate this design. Coverage should trend toward
full as the adopted manual audit (docs/audits/capability-vulnerability-
audit.md) reviews the existing corpus and writes real findings into
each record's own fields.

Every new test mutation-checked by hand: each of the 7 tests in
tests/test_vulnerability_taxonomy.py was confirmed to go red under a
targeted reversion of the specific behavior it names, and only that
test, before being trusted.
@chaksaray
chaksaray merged commit 543bb3b into develop Aug 30, 2026
6 checks passed
@chaksaray
chaksaray deleted the feat/capability-vulnerability-taxonomy-check branch August 30, 2026 00:40
chaksaray added a commit that referenced this pull request Aug 30, 2026
Signed-off-by: Sankalp Gilda <sankalp.gilda@gmail.com>
Co-authored-by: Nicolai <245527909+predictor2718@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: chaksaray <15962335+chaksaray@users.noreply.github.com>
Co-authored-by: Sankalp Gilda <sankalp.gilda@gmail.com>
Co-authored-by: Empire Labs Pty Ltd <narko4u@gmail.com>
Co-authored-by: narko4u <narko4u@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Standing capability-vulnerability taxonomy check (schema fields + script)

1 participant