feat(controls): B3 — categorize the rest of needs_tooling (architectural + RBAC) (#220)
CI / Check (push) Skipped
CI / Detect Changes (push) Successful in 2s
CI / Deploy Dashboard (push) Skipped
CI / Deploy Docs (push) Skipped
CI / Deploy MCP (push) Skipped
CI / Deploy Agent (push) Failing after 4s

This commit was merged in pull request #220.
This commit is contained in:
2026-07-21 13:15:27 +00:00
parent 4ef257bfe2
commit a7ff36edf3
3 changed files with 43 additions and 10 deletions
+9 -9
View File
@@ -25,29 +25,29 @@
"control": "cra-ai-2",
"title": "Minimale Angriffsflaeche",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"note": "design property (minimal attack surface) — not derivable from local code patterns; architecture/threat-model review",
"status": "not_code_checkable"
},
{
"control": "cra-ai-3",
"title": "Sichere Systemarchitektur",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"note": "design property (secure system architecture) — architecture review, not statically code-checkable",
"status": "not_code_checkable"
},
{
"control": "cra-ai-4",
"title": "Least-Privilege-Prinzip",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"note": "design property (least-privilege) — deployment/IAM & architecture review, not a local code pattern",
"status": "not_code_checkable"
},
{
"control": "cra-ai-5",
"title": "Manipulationsschutz",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"note": "design property (tamper protection) — hardware/runtime & operational control, not statically code-checkable",
"status": "not_code_checkable"
},
{
"control": "cra-ai-6",
@@ -146,7 +146,7 @@
"control": "cra-ai-12",
"title": "Rollenbasierte Autorisierung",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
"status": "needs_tooling"
},
{