feat: standing capability-vulnerability taxonomy check - #231
Merged
Merged
Conversation
Adds security_boundary, missing_control, and vulnerability_rationale as optional record fields, plus check_vulnerability_taxonomy.py reporting corpus-wide coverage (soft warning) and gating new record submissions (--strict --only) without retroactively requiring the fields on the 80 existing records. Same pattern as commit/pin_status (#171) and the evidence-vantage fields (#213, #214). Schema fields added to both schema/ave-record-1.1.0.schema.json (used by validate_records.py) and schema/ave-record.schema.json (used by scripts/build-records.js), kept in sync per the existing convention. All 80 records still validate; all 80 currently lack the new fields, expected given they predate this design. Coverage should trend toward full as the adopted manual audit (docs/audits/capability-vulnerability- audit.md) reviews the existing corpus and writes real findings into each record's own fields. Every new test mutation-checked by hand: each of the 7 tests in tests/test_vulnerability_taxonomy.py was confirmed to go red under a targeted reversion of the specific behavior it names, and only that test, before being trusted.
chaksaray
added a commit
that referenced
this pull request
Aug 30, 2026
Signed-off-by: Sankalp Gilda <sankalp.gilda@gmail.com> Co-authored-by: Nicolai <245527909+predictor2718@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: chaksaray <15962335+chaksaray@users.noreply.github.com> Co-authored-by: Sankalp Gilda <sankalp.gilda@gmail.com> Co-authored-by: Empire Labs Pty Ltd <narko4u@gmail.com> Co-authored-by: narko4u <narko4u@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #230. Optional schema fields (
security_boundary,missing_control,vulnerability_rationale) plusscripts/check_vulnerability_taxonomy.py, following the commit/pin_status (#171) and evidence-vantage (#213, #214) precedent exactly.Real numbers: 0/80 records currently pass (expected — they all predate this design; the soft-warn default confirms it:
WARNING: 80 of 80 record(s) missing capability-vulnerability taxonomy fields).--strict --only AVE-2026-NNNNNis wired into CONTRIBUTING.md's new-record checklist to gate future submissions without retroactively requiring the fields on the existing corpus.Schema fields added to both
schema/ave-record-1.1.0.schema.json(used byvalidate_records.py) andschema/ave-record.schema.json(used byscripts/build-records.js), kept in sync per the existing convention — confirmed via diff these two files were otherwise identical before this change.Every new test mutation-checked by hand, not just run once: each of the 7 tests in
tests/test_vulnerability_taxonomy.pywas confirmed to go red under a targeted reversion of the exact behavior it names, and only that test went red each time. Mutations tried:if not (...)→if False,all()→any(), strict/warn exit-code swap, and removing the--onlyfilter.Validated:
python scripts/validate_records.py: 80/80 still validpython scripts/check_fixtures.py: all passpython scripts/check_vulnerability_taxonomy.py: WARNING, 80/80 missing (expected)python -m pytest tests/ -x -q: 434 passed (427 existing + 7 new)node scripts/build-records.js: builds clean against the updatedave-record.schema.jsonCI wiring is its own named step in
.github/workflows/tests.yml(Capability-vulnerability taxonomy soft warning), not folded into an existing step whose output would get discarded on a pass — the same wiring-gap lesson from #213.dist/intentionally left untouched: regenerating it only bumpedgenerated_at, no real content changed since no record uses the new optional fields yet, and there's no reason to bake another manifest-timestamp collision into this PR.