diff --git a/docs/Secure_Build_Scorecard_MEFOR.md b/docs/Secure_Build_Scorecard_MEFOR.md index 768c8c3..d32d683 100644 --- a/docs/Secure_Build_Scorecard_MEFOR.md +++ b/docs/Secure_Build_Scorecard_MEFOR.md @@ -120,7 +120,8 @@ This scorecard is graded under the same declared deviation that governs Secure_D The canonical verdicts-of-record live in the cited `docs/security/` set. That set is maintainer-internal and is **not published in this repository**, so the entries below are cited by name for provenance, not linked — this scorecard is the public-facing summary and stands on its own. It grades on top of them and does not restate their per-requirement outcomes. Where an in-tree doc is superseded, it is flagged, not credited. **Evidence base — `docs/security/` (cited, not restated):** -- **ASVS-L3-RESCORE-2026-07-31** — the **current** verdict-of-record. Do not grade off any earlier assessment; the counts are maintainer-internal and are deliberately not restated here. Two things a reader of the older documents must know: the **Posture A / Posture B split is retired** (there is one scored posture, not two), and **V3 Web Frontend Security is scored in full** — the exclusion premise died when the browser console replaced the PySide6 desktop app. +- ⭐ **`asvs-scorecard.toml` — THE verdict-of-record, and it is not a prose document.** [ADR 0156](adr/0156-asvs-scorecard-as-data-a-derived-count-verified-evidence-anchors-and-a-fail-closed-drift-gate.md) retired the dated-assessment lineage: verdicts and evidence anchors live in one structured file, rendered to `ASVS-CURRENT.md` and drift-gated in CI. **Do not cite any dated prose assessment as the record** — including the ones below, which are provenance only. *This entry is the third thing in this file's history to be called the verdict-of-record; the reason there is now a single machine-checked source is precisely that prose pointers keep going quietly stale, as the entry beneath this one documents about itself.* +- **ASVS-L3-RESCORE-2026-07-31** — the last of the dated prose re-scores, retained for provenance. Do not grade off it, or off any earlier assessment; the counts are maintainer-internal and are deliberately not restated here. Two things a reader of the older documents must know: the **Posture A / Posture B split is retired** (there is one scored posture, not two), and **V3 Web Frontend Security is scored in full** — the exclusion premise died when the browser console replaced the PySide6 desktop app. - ⛔ **ASVS-L3-ASSESSMENT-2026-07-16 — SUPERSEDED; do not cite.** This entry previously called it "the **current** canonical verdict-of-record" and told the reader to "grade off this doc". Both were wrong by 2026-07-31: its Posture A/B counts (175 / 50 / 2 / 118 and 199 / 51 / 2 / 93, at `363db4e3`) rest on a posture split that no longer exists, and four dated re-scores have landed since. It likewise supersedes ASVS-L3-ASSESSMENT-2026-07-09 (179 / 46 / 5 / 115), which the §2/§3 reconciliation narrative describes. - **ASVS-L3-RISK-ACCEPTANCE-REGISTER** — 8 sign-off themes with re-score triggers; signed 2026-07-14 (was a v1.0 draft with all blocks unsigned). - **ASVS-L3-STATUS.md** + **ASVS-FAILS-REMEDIATION-PLAN.md** — superseded, rosier scorecards (212/0/0/133 and 192/20/0/133 via the discarded "conditional Pass"); now carry SUPERSEDED banners; flagged, not credited.