feat(controls): promote grounded controls to covered + enable LLM passes by default #224

Merged
sharang merged 1 commits from feat/promote-grounded-controls into main 2026-07-22 07:48:52 +00:00
Owner

The grounded surface path (Stage 5d) is now validated live: against an absence-vuln fixture it flagged cra-ai-11 (unprotected login), cra-ai-24 (unlogged admin action), and cra-ai-28/29/30 (unverified firmware update) — each grounded to a real snippet and control-tagged.

Promotion

  • LUT: the 8 absence-based controls (cra-ai-6,11,12,24,27,28,29,30) move needs_tooling → covered (grounded-control-check binding). CRA coverage is now 21 covered / 0 needs_tooling / 19 not_code_checkable — every code-checkable CRA control is covered.

Enable both advanced LLM passes by default

  • semantic_mapping (validated in C5) and grounded_control_checks (validated here) now default on. They were gated only for cost/verification; the GPU is in-house so cost isn't a constraint. Both remain no-ops unless BREAKPILOT_BASE_URL is set and the catalog is reachable, and both degrade gracefully if it isn't.

Regression tests (ignored, not run by CI --lib): c5_example2.rs (semantic, 4 varied vulns) and grounded_surface_live.rs (Stage 5d validation).

Green locally (clippy -D warnings, fmt, full suite; control-map coverage test updated to 21/0/19).

🤖 Generated with Claude Code

The grounded surface path (Stage 5d) is now **validated live**: against an absence-vuln fixture it flagged `cra-ai-11` (unprotected login), `cra-ai-24` (unlogged admin action), and `cra-ai-28/29/30` (unverified firmware update) — each grounded to a real snippet and control-tagged. **Promotion** - LUT: the 8 absence-based controls (`cra-ai-6,11,12,24,27,28,29,30`) move **needs_tooling → covered** (grounded-control-check binding). CRA coverage is now **21 covered / 0 needs_tooling / 19 not_code_checkable** — every code-checkable CRA control is covered. **Enable both advanced LLM passes by default** - `semantic_mapping` (validated in C5) and `grounded_control_checks` (validated here) now default **on**. They were gated only for cost/verification; the GPU is in-house so cost isn't a constraint. Both remain no-ops unless `BREAKPILOT_BASE_URL` is set and the catalog is reachable, and both degrade gracefully if it isn't. **Regression tests** (ignored, not run by CI `--lib`): `c5_example2.rs` (semantic, 4 varied vulns) and `grounded_surface_live.rs` (Stage 5d validation). Green locally (clippy -D warnings, fmt, full suite; control-map coverage test updated to 21/0/19). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
sharang added 1 commit 2026-07-22 07:42:24 +00:00
feat(controls): promote grounded controls to covered + enable LLM passes by default
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 6m2s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
32abbfb7bb
The grounded surface path (Stage 5d) is validated live: against an absence-vuln
fixture it flags cra-ai-11 (unprotected login), cra-ai-24 (unlogged admin action),
and cra-ai-28/29/30 (unverified firmware update), each grounded + control-tagged.

- LUT: promote the 8 absence-based controls (cra-ai-6,11,12,24,27,28,29,30)
  needs_tooling -> covered (grounded-control-check binding). CRA coverage is now
  21 covered / 0 needs_tooling / 19 not_code_checkable.
- Enable both advanced LLM passes by default: semantic_mapping (validated in C5)
  and grounded_control_checks (validated here). Both were gated only for cost /
  verification; the GPU is in-house so cost isn't a constraint. Still no-ops
  unless breakpilot base_url is set and the catalog is reachable.
- Gated regression tests (ignored, not run by CI --lib): c5_example2.rs (semantic,
  4 varied vulns) and grounded_surface_live.rs (Stage 5d validation).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
sharang merged commit 3e233da128 into main 2026-07-22 07:48:52 +00:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sharang/compliance-scanner-agent#224