CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m44s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
Second slice of B (hybrid coverage): the controls violated by an *absence* (no rate limiting, no security logging, no update-signature check) have no syntactic pattern for semgrep, so we retrieve the code surface each governs and let the grounded judge decide whether the control holds. - controls/surface.rs: deterministic, bounded surface retrieval (keyword + window, capped per control) for cra-ai-6,11,24,27,28,29,30. - grounded_surface_findings(): retrieve surfaces -> GroundedControlChecker -> net-new findings, each already tagged with its control and grounded to a real snippet (ground() drops anything not quoting verbatim code). - orchestrator Stage 5d, gated on breakpilot.grounded_control_checks (BREAKPILOT_GROUNDED_CHECKS, default off) — absence detection is the least deterministic path, kept off until tuned against live scans. - LUT: the 7 controls' notes now point to the gated grounded mechanism (kept needs_tooling; coverage stays honest until live-validated). Local validation (real Qwen, temp 0), correct positive+negative discrimination: cra-ai-11 unprotected login -> violates, CWE-307, grounded; protected -> false cra-ai-24 unlogged admin del -> violates, CWE-778, grounded; logged -> false Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
441 lines
12 KiB
JSON
441 lines
12 KiB
JSON
{
|
|
"version": "1.0",
|
|
"framework": "cra",
|
|
"controls": [
|
|
{
|
|
"control": "cra-ai-1",
|
|
"title": "Secure-by-Default-Konfiguration",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-1-flask-debug-enabled",
|
|
"cra-ai-1-django-debug-true",
|
|
"cra-ai-1-tls-verify-disabled",
|
|
"cra-ai-1-cors-wildcard"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-2",
|
|
"title": "Minimale Angriffsflaeche",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-3",
|
|
"title": "Sichere Systemarchitektur",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-4",
|
|
"title": "Least-Privilege-Prinzip",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-5",
|
|
"title": "Manipulationsschutz",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-6",
|
|
"title": "Integritaetspruefung",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-7",
|
|
"title": "Starke Authentifizierung",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-7-weak-password-hash"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-8",
|
|
"title": "Keine Default-Passwoerter",
|
|
"scans": [
|
|
{
|
|
"tool": "gitleaks",
|
|
"scan_type": "secret_detection",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-798",
|
|
"CWE-259"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-9",
|
|
"title": "Sicheres Credential-Management",
|
|
"scans": [
|
|
{
|
|
"tool": "gitleaks",
|
|
"scan_type": "secret_detection",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-798",
|
|
"CWE-522"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-10",
|
|
"title": "Sitzungsmanagement",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-10-session-cookie-insecure",
|
|
"cra-ai-10-express-cookie-insecure"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-11",
|
|
"title": "Brute-Force-Schutz",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-12",
|
|
"title": "Rollenbasierte Autorisierung",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-13",
|
|
"title": "Verschluesselung sensibler Daten",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-327",
|
|
"CWE-326"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-14",
|
|
"title": "Speicher-Schutz (Data at Rest)",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-14-python-weak-cipher",
|
|
"cra-ai-14-node-weak-cipher"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-15",
|
|
"title": "Transport-Schutz (Data in Transit)",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-319",
|
|
"CWE-311"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-16",
|
|
"title": "Sicheres Schluesselmanagement",
|
|
"scans": [
|
|
{
|
|
"tool": "gitleaks",
|
|
"scan_type": "secret_detection",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-798",
|
|
"CWE-321"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-17",
|
|
"title": "Datenminimierung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-18",
|
|
"title": "Strukturierter SSDLC",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-19",
|
|
"title": "Systematische Code Reviews",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-20",
|
|
"title": "Automatisierte Sicherheitstests",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-89",
|
|
"CWE-78",
|
|
"CWE-79",
|
|
"CWE-22"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-21",
|
|
"title": "Supply-Chain-Security",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-22",
|
|
"title": "Dependency-Monitoring",
|
|
"scans": [
|
|
{
|
|
"tool": "osv",
|
|
"scan_type": "cve",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "syft",
|
|
"scan_type": "sbom",
|
|
"cwe": [],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-23",
|
|
"title": "Software Bill of Materials (SBOM)",
|
|
"scans": [
|
|
{
|
|
"tool": "syft",
|
|
"scan_type": "sbom",
|
|
"cwe": [],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-24",
|
|
"title": "Security-Logging",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-25",
|
|
"title": "Ereignis-Monitoring",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-26",
|
|
"title": "Anomalie-Erkennung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-27",
|
|
"title": "Log-Integritaet und -Aufbewahrung",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-28",
|
|
"title": "Sichere Update-Mechanismen",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-29",
|
|
"title": "Update-Authentizitaet",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-30",
|
|
"title": "Update-Integritaet",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-31",
|
|
"title": "Lifecycle-Support",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-32",
|
|
"title": "Schwachstellen-Identifikation",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-33",
|
|
"title": "SBOM-Pflege und Analyse",
|
|
"scans": [
|
|
{
|
|
"tool": "syft",
|
|
"scan_type": "sbom",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "osv",
|
|
"scan_type": "cve",
|
|
"cwe": [],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-34",
|
|
"title": "Risikobasierte Priorisierung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-35",
|
|
"title": "Coordinated Vulnerability Disclosure",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-36",
|
|
"title": "Incident-Response-Prozess",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-37",
|
|
"title": "Fruehwarnung (24h)",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-38",
|
|
"title": "Detaillierter Vorfallsbericht (72h)",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-39",
|
|
"title": "Patch-Bereitstellung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-40",
|
|
"title": "Dokumentation und Nachbereitung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
}
|
|
]
|
|
}
|