Skip to content

Add firewall rule evidence fixtures#1518

Open
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/firewall-evidence-fixtures-59
Open

Add firewall rule evidence fixtures#1518
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/firewall-evidence-fixtures-59

Conversation

@jddark62
Copy link
Copy Markdown

@jddark62 jddark62 commented Jun 6, 2026

Summary

Adds a structured rule evidence matrix to firewall-review so findings are tied to concrete source-of-truth evidence before severity is assigned.

This includes:

  • Evidence confidence levels for source-controlled policy, exported config, runtime/log evidence, screenshots, stale exports, and missing evidence.
  • Not Evaluable reason codes for missing object expansion, runtime counters, NAT or route context, IPv6 policy, egress path, export freshness, owner/ticket evidence, and logging proof.
  • Output fields for evidence confidence, Not Evaluable reasons, IPv6 default-deny status, and NAT/related policy context.
  • Seven YAML calibration fixtures covering controlled private traffic, object-group expansion, missing expansions, counter reset baselines, NAT exposure, missing IPv6 policy, and missing SIEM/log destination proof.

Validation

  • git diff --check
  • Skill frontmatter YAML parse
  • Fixture YAML parse: 7 YAML blocks
  • Markdown fence balance check
  • Public-file privacy scan

/claim #59

Payment details can be coordinated privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant