From 31c61727a919d243b57503ba10bdf64ac24dbb2e Mon Sep 17 00:00:00 2001 From: wshallwshall Date: Sun, 2 Aug 2026 20:01:06 -0500 Subject: [PATCH] docs(scorecard): the verdict-of-record is asvs-scorecard.toml, not a dated prose assessment This file named ASVS-L3-RESCORE-2026-07-31 as "the current verdict-of-record" and told the reader not to grade off any earlier assessment. ADR 0156 retired that lineage: verdicts and evidence anchors live in docs/security/asvs-scorecard.toml, rendered to ASVS-CURRENT.md and drift-gated in CI. A prose file cannot be the record when the record is machine-checked. The correction is small; the reason it matters is that the very next bullet in this same file documents this file being wrong about its own pointer once already -- it says ASVS-L3-ASSESSMENT-2026-07-16 "previously called it the current canonical verdict-of-record" and that this was wrong by 2026-07-31. So a dated prose pointer has now gone stale here twice. Naming the structured source is what stops a third. Prose entries are kept, demoted to provenance rather than deleted, so a reader following an old citation still lands somewhere that explains why it is not the record. --- docs/Secure_Build_Scorecard_MEFOR.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/Secure_Build_Scorecard_MEFOR.md b/docs/Secure_Build_Scorecard_MEFOR.md index 768c8c35..d32d683b 100644 --- a/docs/Secure_Build_Scorecard_MEFOR.md +++ b/docs/Secure_Build_Scorecard_MEFOR.md @@ -120,7 +120,8 @@ This scorecard is graded under the same declared deviation that governs Secure_D The canonical verdicts-of-record live in the cited `docs/security/` set. That set is maintainer-internal and is **not published in this repository**, so the entries below are cited by name for provenance, not linked — this scorecard is the public-facing summary and stands on its own. It grades on top of them and does not restate their per-requirement outcomes. Where an in-tree doc is superseded, it is flagged, not credited. **Evidence base — `docs/security/` (cited, not restated):** -- **ASVS-L3-RESCORE-2026-07-31** — the **current** verdict-of-record. Do not grade off any earlier assessment; the counts are maintainer-internal and are deliberately not restated here. Two things a reader of the older documents must know: the **Posture A / Posture B split is retired** (there is one scored posture, not two), and **V3 Web Frontend Security is scored in full** — the exclusion premise died when the browser console replaced the PySide6 desktop app. +- ⭐ **`asvs-scorecard.toml` — THE verdict-of-record, and it is not a prose document.** [ADR 0156](adr/0156-asvs-scorecard-as-data-a-derived-count-verified-evidence-anchors-and-a-fail-closed-drift-gate.md) retired the dated-assessment lineage: verdicts and evidence anchors live in one structured file, rendered to `ASVS-CURRENT.md` and drift-gated in CI. **Do not cite any dated prose assessment as the record** — including the ones below, which are provenance only. *This entry is the third thing in this file's history to be called the verdict-of-record; the reason there is now a single machine-checked source is precisely that prose pointers keep going quietly stale, as the entry beneath this one documents about itself.* +- **ASVS-L3-RESCORE-2026-07-31** — the last of the dated prose re-scores, retained for provenance. Do not grade off it, or off any earlier assessment; the counts are maintainer-internal and are deliberately not restated here. Two things a reader of the older documents must know: the **Posture A / Posture B split is retired** (there is one scored posture, not two), and **V3 Web Frontend Security is scored in full** — the exclusion premise died when the browser console replaced the PySide6 desktop app. - ⛔ **ASVS-L3-ASSESSMENT-2026-07-16 — SUPERSEDED; do not cite.** This entry previously called it "the **current** canonical verdict-of-record" and told the reader to "grade off this doc". Both were wrong by 2026-07-31: its Posture A/B counts (175 / 50 / 2 / 118 and 199 / 51 / 2 / 93, at `363db4e3`) rest on a posture split that no longer exists, and four dated re-scores have landed since. It likewise supersedes ASVS-L3-ASSESSMENT-2026-07-09 (179 / 46 / 5 / 115), which the §2/§3 reconciliation narrative describes. - **ASVS-L3-RISK-ACCEPTANCE-REGISTER** — 8 sign-off themes with re-score triggers; signed 2026-07-14 (was a v1.0 draft with all blocks unsigned). - **ASVS-L3-STATUS.md** + **ASVS-FAILS-REMEDIATION-PLAN.md** — superseded, rosier scorecards (212/0/0/133 and 192/20/0/133 via the discarded "conditional Pass"); now carry SUPERSEDED banners; flagged, not credited.