feat(control-map): deterministic control->scan LUT crate (CRA, 40 controls)
New standalone crate — the 'transcribing' layer that maps each control to the static-scan step(s) that check it, or marks it needs_tooling / not_code_checkable. Authored + human-reviewed: no LLM decides coverage. The LLM only triages the tool's findings downstream (in the agent), never here. - ControlMap / ControlEntry / ScanBinding / Coverage types + embedded JSON LUT - query API: coverage(control), controls_for(tool, cwe), summary() - CRA LUT: 40 controls -> 9 covered (semgrep/gitleaks/syft/osv) / 16 needs_tooling / 15 not_code_checkable - wired into CI (clippy + test). 4 lib tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
d1f42a1a83
commit
b7534d1123
@@ -109,6 +109,8 @@ jobs:
|
||||
run: cargo clippy -p compliance-mcp -- -D warnings
|
||||
- name: Clippy (werkbank-exec)
|
||||
run: cargo clippy -p werkbank-exec -- -D warnings
|
||||
- name: Clippy (control-map)
|
||||
run: cargo clippy -p control-map -- -D warnings
|
||||
|
||||
# Security audit
|
||||
- name: Security Audit
|
||||
@@ -117,8 +119,8 @@ jobs:
|
||||
RUSTC_WRAPPER: ""
|
||||
|
||||
# Tests (reuses compilation artifacts from clippy)
|
||||
- name: Tests (core + agent + werkbank-exec)
|
||||
run: cargo test -p compliance-core -p compliance-agent -p werkbank-exec --lib
|
||||
- name: Tests (core + agent + werkbank-exec + control-map)
|
||||
run: cargo test -p compliance-core -p compliance-agent -p werkbank-exec -p control-map --lib
|
||||
- name: Tests (dashboard server)
|
||||
run: cargo test -p compliance-dashboard --features server --no-default-features
|
||||
- name: Tests (dashboard web)
|
||||
|
||||
Reference in New Issue
Block a user