Commit 7ac5ef9
authored
feat(security): surface Dependabot posture in portfolio render surfaces (#28)
* feat(security): surface Dependabot posture in portfolio render surfaces
The radar's truth-layer security dimension (RiskFields.security_risk,
SecurityFields Dependabot counts, the active-high-severity-alerts factor)
was wired into the risk model and weekly digest in #27, but the two
human-facing render surfaces — PORTFOLIO-AUDIT-REPORT.md and
project-registry.md — did not surface it. This adds that, mirroring the
digest's Security Posture treatment:
- Portfolio report: a Coverage Summary line + a dedicated '## Security
Posture' section (TOC entry included) with the same three states as the
digest — per-repo open high/critical (critical-first, capped at 5),
'all N scanned clear', or 'overlay not run'.
- Registry: a pipe-free per-repo security flag in the Notes column (fires
only for scanned repos with open high/critical) plus four aggregate rows
in the Portfolio Summary table.
Shared _security_overview / _security_attention_items helpers mirror the
digest's aggregation on the in-memory snapshot. The Notes flag is pipe-free
and the summary rows are digit-valued, so the registry still round-trips
through parse_registry unchanged; both markdown validators stay green.
5 new tests cover all three report states, the registry flag + round-trip,
and the unscanned case.
* test(security): guard Security Posture section + cover cap/sort and registry clean path
Addresses code-review findings on the render surfaces:
- validate_portfolio_report_markdown now requires the '## Security Posture'
header, so the section can't silently vanish in a future refactor (every
other section header is already guarded).
- New unit test pins _security_attention_items' cap-at-5 and critical-desc /
high-desc / name-asc sort — the one behavior unique to the attention list.
- Extends the scanned-clear test to assert the registry's per-repo flag is
absent for a medium-only repo while it still counts as scanned.1 parent 1e9a8a7 commit 7ac5ef9
3 files changed
Lines changed: 305 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
8 | 56 | | |
9 | 57 | | |
10 | 58 | | |
| |||
57 | 105 | | |
58 | 106 | | |
59 | 107 | | |
| 108 | + | |
60 | 109 | | |
61 | 110 | | |
62 | 111 | | |
| |||
72 | 121 | | |
73 | 122 | | |
74 | 123 | | |
75 | | - | |
76 | | - | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
77 | 127 | | |
78 | 128 | | |
79 | 129 | | |
| |||
119 | 169 | | |
120 | 170 | | |
121 | 171 | | |
| 172 | + | |
122 | 173 | | |
123 | 174 | | |
124 | 175 | | |
| |||
150 | 201 | | |
151 | 202 | | |
152 | 203 | | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
153 | 225 | | |
154 | 226 | | |
155 | 227 | | |
| |||
284 | 356 | | |
285 | 357 | | |
286 | 358 | | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
287 | 372 | | |
288 | 373 | | |
289 | 374 | | |
| |||
292 | 377 | | |
293 | 378 | | |
294 | 379 | | |
295 | | - | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
296 | 385 | | |
297 | 386 | | |
298 | 387 | | |
299 | 388 | | |
300 | 389 | | |
301 | 390 | | |
| 391 | + | |
302 | 392 | | |
303 | 393 | | |
304 | 394 | | |
| |||
314 | 404 | | |
315 | 405 | | |
316 | 406 | | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
317 | 411 | | |
318 | 412 | | |
319 | 413 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
145 | 145 | | |
146 | 146 | | |
147 | 147 | | |
| 148 | + | |
148 | 149 | | |
149 | 150 | | |
150 | 151 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
20 | 23 | | |
| 24 | + | |
21 | 25 | | |
22 | 26 | | |
23 | 27 | | |
| |||
34 | 38 | | |
35 | 39 | | |
36 | 40 | | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
37 | 82 | | |
38 | 83 | | |
39 | 84 | | |
| |||
469 | 514 | | |
470 | 515 | | |
471 | 516 | | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
| 662 | + | |
| 663 | + | |
| 664 | + | |
| 665 | + | |
| 666 | + | |
| 667 | + | |
| 668 | + | |
| 669 | + | |
| 670 | + | |
| 671 | + | |
| 672 | + | |
| 673 | + | |
| 674 | + | |
| 675 | + | |
| 676 | + | |
| 677 | + | |
472 | 678 | | |
473 | 679 | | |
474 | 680 | | |
| |||
0 commit comments