CS-02: expose IaC provenance SDK and CLI selectors - #387
Conversation
|
Final receipt-delta adversarial self-review, per repository review exception: pristine Latest Python 3.10–3.14 CI and Cloud Build 4714d82f-ff02-4e38-bd50-ddae951162ba passed; focused receipt suite: 413 passed. New selectors fail closed against an older gateway/reader. Server contract rollout remains required; no package completion or feature activation is claimed. |
LimaCharlie Cloud Security — code scanNo new code findings were introduced by this pull request. This check reports and never fails: no Scanned This comment is updated in place on every push to this pull request. |
|
Composition review at Full local validation: 4,456 passed, six pre-existing skips, 17 warnings. Skips are api/completion missing-docstring checks, optional orjson, and three non-Linux platform checks; no Code Security tests skipped. Python 3.10–3.14 matrix green; full cloud rerunning. Still awaiting additive graph contract before merging this consumer. No deployment, package completion, or independent security approval implied. |
Adds IaC attribution and recorded-origin selectors consistently to finding list/facets/causes/CSV and inventory list/facets/CSV. Explicit false is preserved, malformed values fail before HTTP, and all requests remain bound to the client organization. Missing origin evidence is not proof of no IaC.
Validation: focused SDK/CLI 405 passed; complete unit/microbenchmark correctness suite 4,439 passed, 6 skipped (35.74s). Pristine git-archive review checked selector validation, every callback/HTTP path, false/absent handling and tenant isolation; fixed the legacy docstring’s overly broad truncation claim. The repository is exempt from the review bot; this self-review does not substitute for any independent program security gate.
Requires compatible gateway refractionPOINT/lc_api-go#962 and graph refractionPOINT/legion_graph#228 before using the new selectors; no publishing/tagging or feature enablement. Core contracts PRs364–366 and host283 are merged. Documentation includes rollout/rollback and immutable-link/partial-evidence semantics.
Package: https://github.com/maximelb/claude-config/issues/137
Epic: https://github.com/maximelb/claude-config/issues/134