DD-333 Phase F.4 (scanner) — S-DOM-002 domain_scope honesty lint #4
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
needs-info
needs-triage
question
ready-for-agent
ready-for-human
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Stallari/secops-scanner!4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/dd-333-phase-f4-domain-scope"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
S-DOM-002that flags the "single + scope-arg" contradiction: a plugin tool declaresgranularity.domain_scope: single(or derivednon-conforming-explicitvianon_conformance_rationale.domain_scope_unspecified) while advertising a user-domain-shaped argument (name matches/^(scope|domain|domains|domainName|domain_name)$/i, typestring/enum).// scope-arg-disclaimer: <reason>in the description; findings are then downgraded to info-only (rendered as warning with[info-only]prefix in message body sinceLintSeverityonly ships"warning" | "error").warningseverity per architect lock #7. Mirrors S-DOM-001 posture — promote toerroronly after DD-338 A.2.dom blade-side backfill.Types extension
ToolGranularity.domain_scope?: "single" | "multi" | "non-conforming-explicit"— optional 5th dimension mirroring stallari-pluginscatalog-entry.schema.jsonF.4 schema add.NonConformanceRationale.domain_scope_unspecified?: string[]— sister to existingaffected_tools/scope_filteringderivation.CatalogTool.arguments?: CatalogToolArgument[]— optional per-tool argument inventory consumed by S-DOM-002. Existing catalog entries (which omit the field) pass through unchanged.Tests
22 new cases — 127 baseline + 22 new = 149 tests green;
tsc --noEmitclean.s_dom_002_passes_honest_pack— multi+arg legitimate, single+no-arg legitimate, undeclared silents_dom_002_warns_on_single_plus_scope_arg— contradiction → 1 warnings_dom_002_respects_disclaimer— disclaimer annotation downgrades to info-onlyscanCatalogEntriesaggregator integrationVersion
1.1.0 → 1.2.0(scanner has its own cadence per spec).Convention #23 reader-audit
This rule reads three contract slices — the new
granularity.domain_scopeenum, the optionalarguments[]inventory, and the newnon_conformance_rationale.domain_scope_unspecifiedslot. F.4 is additive; existing 11 packs / 30+ plugins are unaffected.Out of scope
multirequires_meta.domain_attribution) defers to F.5required:+ severity escalation toerrordefer to F.4.b post-DD-338 A.2.domTest plan
npm testgreen (149 tests)npm run lint(tsc --noEmit) cleanCo-Authored-By: Claude Opus 4.7, noSigned-off-byRelated: DD-333, DD-341, DD-338