Skip to content

feat(verdict): provenance tier + configurable severity floor - #6

Merged
eric-sabe merged 1 commit into
mainfrom
feat/verdict-policy
Jul 8, 2026
Merged

feat(verdict): provenance tier + configurable severity floor#6
eric-sabe merged 1 commit into
mainfrom
feat/verdict-policy

Conversation

@eric-sabe

Copy link
Copy Markdown
Owner

Replaces #2 (auto-closed when the stacked base branch was deleted during merge). Same change; CI green.

The baseline pins specific reviewed findings; this is the broad dial. Provenance: a finding matching HONEY_TRUSTED_PATTERNS (default claude-plugins-official) is first-party. Severity floor: below-floor findings move to a non-blocking review tier (still printed/counted). Safe by default (floors none); bumblebee + MUTATED pins always block. See docs/VERDICT.plan.md.

🤖 Generated with Claude Code

The baseline pins specific reviewed findings; this is the broad dial for the
daily marketplace noise. Two settings, applied after suppression:

  • Provenance: a finding whose location matches HONEY_TRUSTED_PATTERNS
    (default claude-plugins-official) is first-party; the report tags it
    [1st-party].
  • Severity floor: a finding escalates OVERALL only at/above the floor for its
    provenance (HONEY_VERDICT_FLOOR / HONEY_VERDICT_FLOOR_TRUSTED). Below-floor
    findings move to a non-blocking "review" tier — still printed and counted
    (`OVERALL: … (65 review)`), but they don't flip the verdict.

Every classified finding now carries _provenance and _blocking; report.sh /
daily-cycle.sh (and the PowerShell mirrors) share the same classification, so
they agree. A review-only run is CLEAN.

Safe by default: floors default to `none` (everything blocks, as before) — a
security tool must not silently hide findings out of the box. Overrides that
the floor can never mute: bumblebee always blocks (known-compromised catalog),
and a MUTATED pin always blocks (rug-pull tripwire); incomplete/scan_error are
never reclassified.

Multi-OS parity: lib/verdict.sh + win/lib/Verdict.psm1; report/daily-cycle
updated on both sides. shellcheck clean; PSScriptAnalyzer clean; default verdict
unchanged when no floor is set. Docs: docs/VERDICT.plan.md, README (section +
3 config vars), routine-prompt.md + triage-guide.md (the review tier).

Stacked on feat/suppression-baseline.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@eric-sabe
eric-sabe merged commit 9cc1e14 into main Jul 8, 2026
4 checks passed
@eric-sabe
eric-sabe deleted the feat/verdict-policy branch July 8, 2026 03:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant