Skip to content

Align ledger with portfolio standards#85

Merged
ChelseaKR merged 1 commit into
mainfrom
agent/portfolio-standards-conformance
Jul 12, 2026
Merged

Align ledger with portfolio standards#85
ChelseaKR merged 1 commit into
mainfrom
agent/portfolio-standards-conformance

Conversation

@ChelseaKR

Copy link
Copy Markdown
Owner

What changed

  • close all five failures from the current portfolio-standards Tier-1 checker
  • declare all thirteen current standards and add incident/data-governance evidence
  • add SHA-pinned OpenSSF Scorecard, runtime/standards pins, ADR seed, and review controls
  • enable private vulnerability reporting and issue-backed tracking for remaining human/account controls

Why

The repository had drifted from both the shared standards and its own documentation. Several controls already existed but were still described as absent, while the official checker reported incomplete citation metadata, no runtime pin, an incomplete conformance table, no ADR seed, and undiscoverable packaged catalogs.

Primary ISO/IEC 25010:2023 characteristics: security, maintainability, safety, and functional suitability.

Impact

No runtime behavior or archive data format changes. CI gains a Scorecard evidence workflow; documentation and GitHub metadata now reflect the controls actually in force. Remaining controls that require human attestation, observed egress allowlists, account setup, or substantial follow-up engineering are tracked in #78#84.

Rollback

Revert this PR. It has no database migration, archive migration, feature flag, or production data effect. GitHub private vulnerability reporting and incident labels are safe to leave enabled independently.

Validation

  • portfolio-standards/automation/conformance_check.py --repo . --strict --network — 31/31
  • make verify — 980 tests plus lint, strict types, i18n, accessibility, pip-audit, gitleaks, claims, and zizmor
  • actionlint
  • workflow YAML parse and local Markdown-link validation
  • git diff --check

Checklist

  • Acceptance criteria and ISO characteristic stated
  • make verify green
  • No-outing and redaction-safe: no record/identity data changed
  • Tests and documentation verified
  • Observability/runtime behavior unchanged
  • Workflow/control decisions recorded in ADR 0009 and the audit artifact
  • Rollback documented
  • CHANGELOG updated under Unreleased

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@ChelseaKR
ChelseaKR merged commit df1afa5 into main Jul 12, 2026
16 checks passed
@ChelseaKR
ChelseaKR deleted the agent/portfolio-standards-conformance branch July 12, 2026 05:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants