From 36f64ed0ee1ea631b22737f62da07cde128f92c4 Mon Sep 17 00:00:00 2001 From: Ali Bahaloo Date: Tue, 28 Jul 2026 23:09:30 -0700 Subject: [PATCH 1/7] docs: admit Cisco's advisory scope statements as a source (constitution 3.3.0) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit BRD-006 shows, beside each advisory in a reviewed bundle, Cisco's own published "Vulnerable Products" and "Products Confirmed Not Vulnerable" statements. Neither exists in the advisory API, so two constraints blocked the feature: - Networking admitted sec.cloudapps.cisco.com only for a bundle page "read solely to resolve a bundle to its advisory identifiers and its own identity". Per-advisory documents exceed "solely". - Source of truth named only the openVuln API and ended "No scraped or cached-as-authoritative alternatives". A CSAF document is neither scraped nor cached, and is reached by following the pointer the API itself returns (csafUrl) rather than a URL the tool invents — but it was not named, and a governance document should not be satisfied on that technicality. Both are amended narrowly. The new Advisory scope statements bullet is bounded to the two statements, requires the API-supplied pointer, requires the document to identify the advisory it was fetched for, forbids the statements from informing any determination, and resolves disagreement with the API in the API's favour. It adds a faithful-rendering obligation — no summarising or paraphrasing, every alteration enumerated and tested — as the mirror of Principle IV's ban on inventing an advisory fact. Scope selectors is deliberately not relaxed; both bullets now state that neither widens the other. Recorded explicitly: this reverses part of the spec-007 decommission, under narrower terms (no on-disk retention, no temporary folder, no AI processing). Principle VI gains the capability in its public contract; the Tests gate gains a per-normalisation obligation. Product version moves to 4.3.0 when the feature lands. Co-Authored-By: Claude Opus 5 --- .specify/memory/constitution.md | 170 +++++++++++++-- brds/006-affected-products-column.md | 299 +++++++++++++++++++++++++++ 2 files changed, 457 insertions(+), 12 deletions(-) create mode 100644 brds/006-affected-products-column.md diff --git a/.specify/memory/constitution.md b/.specify/memory/constitution.md index 20b1465..7576244 100644 --- a/.specify/memory/constitution.md +++ b/.specify/memory/constitution.md @@ -1,6 +1,106 @@ + + + +