Benjamin Admin
|
8937f105ea
|
feat(bridge): security-updates obligation cut (CRA Annex I (2)(c)/Art 13) — 9 obligations
- obligations/cra_updates.json: 9 (6 LEGAL_MINIMUM + 3 BEST_PRACTICE), Beziehungen.
Pipeline 670->318 micro->15 review-units -> Opus-Synthese. Synthese gut kalibriert ->
light review (KEINE Hart-Re-Tier, vs Auth/Remote-Access). out_of_scope M4/M7.
5 capability_candidate-Marker (signed/trusted/automatic/rollback/testing) fuer
Phase-4-Capability-Pruefung. Anker approximativ (curation.anchor_quality).
- obligation_join_keys.json: 84 -> 93 (updates 9). Alle 6 CRA-P1-Domaenen abgedeckt.
- precluster.py: updates-Scope.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
2026-06-25 18:51:09 +02:00 |
|
Benjamin Admin
|
e1b270c36e
|
Add obligation discovery pipeline tooling
Sichert die validierte Obligation Discovery Pipeline aus /tmp als dauerhaftes,
committetes Tooling (scripts/obligation_discovery/) — der eigentliche Vermögenswert.
Stufen: precluster (Embedding-Cache + Mikro-Cluster) → meta_cluster (Review Units,
Skalierungs-Fix) → synthesize_obligations (Opus, Key aus ENV, Streaming, harte Tier-Regel,
Provenance) → validate_registry → merge_review_diff. Reine Helfer in _core.py, 16 Unit-Tests.
Doku docs-src/development/obligation_discovery_pipeline_v1.md mit Meilensteinen
(SBOM/Vuln reproduziert, Auth 4408→170 Review Units→54→kuriert 29) und der Architekturregel:
Runtime deterministisch, Discovery LLM-gestützt.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
2026-06-25 07:41:45 +02:00 |
|