feat(scanner): missing-domain-access pack finding (DD-341 Phase C) #3
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
needs-info
needs-triage
question
ready-for-agent
ready-for-human
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Stallari/secops-scanner!3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/dd-341-phase-c-scanner"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
src/pack-domain-rules.ts) that fires a"warning"finding when a pack catalog entry lacks thedomain_access:block introduced in stallari-pack-spec v4.3.0 (DD-341 Phase C)ALL_CATALOG_RULESmerge incatalog-scanner.ts—scanCatalogEntry/scanCatalogEntriespick it up automaticallyDomainAccessBlockinterface anddomain_access?:field toCatalogEntryintypes.ts(typed presence check for S-DOM-001)New files
src/pack-domain-rules.ts— S-DOM-001CatalogRule(appliesTo: "pack",severity: "warning") +PACK_DOMAIN_RULESexport arraysrc/pack-domain-rules.test.ts— 12 test cases covering the 3 spec cases + edge casesSeverity rationale —
"warning"per architect lock #5The spec specifies
.infoseverity, but the TypeScript scanner'sLintSeveritytype is"warning" | "error"— there is no"info"level."warning"is the closest analog: non-blocking, informational, drives result to"warn"not"fail". This is intentional per lock #5: 16 currently-sealed packs lack thedomain_access:block. An"error"rule would reject all of them. Sister to DD-333's grandfather pattern (pre-Phase-E sealed packs grandfathered withoutgranularity_conformance). Promote to"error"only after the Pn-author migration cycle via dedicated DEVFU.Convention #23 reader-audit
S-DOM-001 is now a reader of the pack manifest contract (
domain_access:key) introduced in pack-spec v4.3.0. Its presence in the scanner's rule set ensures post-seal audits surface packs predating or omitting the v4.3.0 block. Convention #23 compliance: scanner-as-reader of the new schema dimension is audited and wired (alongside PublicPackManifest, PluginManifest, PackInstaller, PackImportPreview in the harness PR).Test output
Deviations from spec
Sources/StallariSecOpsScanner/Rules/MissingDomainAccessRule.swift). The actual scanner is TypeScript. The implementation follows the existingCatalogRulepattern (catalog-rules.tsshape) rather than a Swift struct..info; TypeScriptLintSeverityonly has"warning"|"error". Used"warning"per the spirit of lock #5 (non-blocking).src/pack-domain-rules.ts(notSources/StallariSecOpsScanner/Rules/) — matches TypeScript project layout.requested_domains:— the implementation correctly emits NO finding forrequested_domains:presence (S-DOM-001 only checksdomain_access:absence). Ifrequested_domains:is present butdomain_access:is absent, S-DOM-001 still fires for the missing block (that's the correct behaviour). Test documents this distinction explicitly.Closes phase C scanner slice of DD-341 (scanner slice).
🤖 Generated with Claude Code