Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion docs/Secure_Build_Scorecard_MEFOR.md
Original file line number Diff line number Diff line change
Expand Up @@ -120,7 +120,8 @@ This scorecard is graded under the same declared deviation that governs Secure_D
The canonical verdicts-of-record live in the cited `docs/security/` set. That set is maintainer-internal and is **not published in this repository**, so the entries below are cited by name for provenance, not linked — this scorecard is the public-facing summary and stands on its own. It grades on top of them and does not restate their per-requirement outcomes. Where an in-tree doc is superseded, it is flagged, not credited.

**Evidence base — `docs/security/` (cited, not restated):**
- **ASVS-L3-RESCORE-2026-07-31** — the **current** verdict-of-record. Do not grade off any earlier assessment; the counts are maintainer-internal and are deliberately not restated here. Two things a reader of the older documents must know: the **Posture A / Posture B split is retired** (there is one scored posture, not two), and **V3 Web Frontend Security is scored in full** — the exclusion premise died when the browser console replaced the PySide6 desktop app.
- ⭐ **`asvs-scorecard.toml` — THE verdict-of-record, and it is not a prose document.** [ADR 0156](adr/0156-asvs-scorecard-as-data-a-derived-count-verified-evidence-anchors-and-a-fail-closed-drift-gate.md) retired the dated-assessment lineage: verdicts and evidence anchors live in one structured file, rendered to `ASVS-CURRENT.md` and drift-gated in CI. **Do not cite any dated prose assessment as the record** — including the ones below, which are provenance only. *This entry is the third thing in this file's history to be called the verdict-of-record; the reason there is now a single machine-checked source is precisely that prose pointers keep going quietly stale, as the entry beneath this one documents about itself.*
- **ASVS-L3-RESCORE-2026-07-31** — the last of the dated prose re-scores, retained for provenance. Do not grade off it, or off any earlier assessment; the counts are maintainer-internal and are deliberately not restated here. Two things a reader of the older documents must know: the **Posture A / Posture B split is retired** (there is one scored posture, not two), and **V3 Web Frontend Security is scored in full** — the exclusion premise died when the browser console replaced the PySide6 desktop app.
- ⛔ **ASVS-L3-ASSESSMENT-2026-07-16 — SUPERSEDED; do not cite.** This entry previously called it "the **current** canonical verdict-of-record" and told the reader to "grade off this doc". Both were wrong by 2026-07-31: its Posture A/B counts (175 / 50 / 2 / 118 and 199 / 51 / 2 / 93, at `363db4e3`) rest on a posture split that no longer exists, and four dated re-scores have landed since. It likewise supersedes ASVS-L3-ASSESSMENT-2026-07-09 (179 / 46 / 5 / 115), which the §2/§3 reconciliation narrative describes.
- **ASVS-L3-RISK-ACCEPTANCE-REGISTER** — 8 sign-off themes with re-score triggers; signed 2026-07-14 (was a v1.0 draft with all blocks unsigned).
- **ASVS-L3-STATUS.md** + **ASVS-FAILS-REMEDIATION-PLAN.md** — superseded, rosier scorecards (212/0/0/133 and 192/20/0/133 via the discarded "conditional Pass"); now carry SUPERSEDED banners; flagged, not credited.
Expand Down
Loading