Skip to content

Improve access review non-human credential evidence#1965

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/access-review-nonhuman-credential-fixtures-1688
Open

Improve access review non-human credential evidence#1965
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/access-review-nonhuman-credential-fixtures-1688

Conversation

@DENGXUELIN

Copy link
Copy Markdown

Closes #1688.

Summary

  • add a non-human credential and API access review gate to access-review
  • require credential-level owner, backup owner, scope, lifecycle, storage, approval, and emergency revocation evidence
  • add vulnerable and benign fixtures for stale human-owned automation credentials versus governed credential review

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence balance check
  • added-line ASCII check
  • content marker check for AR-NHI-* findings and fixtures
  • git merge-tree --write-tree origin/main HEAD

Bounty

Requested tier: Improver Moderate, USD 100 if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] access-review: add non-human credential evidence gates

1 participant