From bbcc8ab1001a24e08d3ff09579c5549f1c06dfbb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cau=C3=AA=20Faleiros?= Date: Mon, 21 Sep 2026 11:45:23 -0300 Subject: [PATCH] docs: record the release gates and what they do not cover Co-Authored-By: Claude Opus 5 --- ROADMAP.md | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/ROADMAP.md b/ROADMAP.md index 481d963..7f5dbf9 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -7,9 +7,9 @@ > Update the **Current step** line and the item status every time something moves. > Add new findings at the bottom of the relevant block rather than rewriting history. -**Current step:** Block 0 closed, plus 2.1, 2.2, 2.3, 2.5 and 5.1. Next: 2.4 (the -release gate the docs describe but the workflow never ran — partly addressed by -5.1), then 2.6/2.7. Block 1 still waits on client inputs for 1.1/1.2. +**Current step:** Block 0 closed, plus 2.1–2.5 and 5.1. Next: 2.6 (pin base image +digests and triage the fixable image findings, which is what would let the image +scan gate), then 2.7–2.11. Block 1 still waits on client inputs for 1.1/1.2. **Last audit:** 2026-09-18, full read of `local/`, `dtf-site.html`, `deploy/`, `.gitea/`, docs and legacy prototypes. Findings below carry their audit IDs. @@ -202,7 +202,7 @@ It passes `DATABASE_URL_FILE`, `AWS_ACCESS_KEY_ID_FILE`, `OPERATOR_PASSWORD_FILE - **Accept:** the stack renders and boots against Swarm secrets; missing operator config yields 503, not 500. -### `[ ]` 2.4 — The documented release gate does not exist `(F8)` +### `[x]` 2.4 — The documented release gate does not exist `(F8)` `PORTAINER.md` and `SECURITY_REPORT.md` claim the workflow runs the full isolated suite, Trivy HIGH/CRITICAL image gates, secret scanning and the source preflight @@ -429,6 +429,18 @@ charges. Fix as part of 1.1. blockers stay, so the gate still refuses a release while the payment and messaging adapters are fake. +- `[x]` 2.4 — A blocking Trivy secret scan was added and verified both ways: a + planted AWS key pair, GitHub token and private key block the job; the repository + passes clean. Worth knowing: Trivy allowlists documented example credentials, so + my first probe passed with AWS's own sample keys — the gate is a backstop, not + permission to commit secrets. The source preflight now runs and always prints its + verdict, enforcing only when `ENFORCE_PRODUCTION_PREFLIGHT` is `true`; enforcing + it today would block every deploy, since it refuses a release while the adapters + are fake. Image vulnerabilities are reported after each build, not enforced — + 56 HIGH and 3 CRITICAL, only 15 with an upstream fix. `PORTAINER.md` and + `SECURITY_REPORT.md` now carry a table of what gates and what does not, replacing + descriptions of checks that never ran. + ### Reporting - `[x]` Week-1 client report (`Relatorio-Semana-1-DTF.docx`), corrected 2026-09-18 to