Skip to content

Commit d4b788e

Browse files
authored
docs(scorecard): the evidence base still told readers to grade off a superseded assessment (#114)
`Secure_Build_Scorecard_MEFOR.md` named ASVS-L3-ASSESSMENT-2026-07-16 as "the CURRENT canonical verdict-of-record" and instructed "Grade off this doc." Both claims were wrong. Four dated re-scores have landed since, and its Posture A/B counts rest on a posture split that no longer exists -- there is one scored posture now, not two. Repoints at the current verdict-of-record and marks the old entry superseded. Following this file's existing "cited, not restated" convention for the maintainer-internal corpus, no new counts are published here; the pre-existing published figures are retained only to mark them stale. Replaces PR #112, whose other half (the ASVS V3 exclusion row) was fixed independently by #111 while it was open.
1 parent ef45c04 commit d4b788e

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

‎docs/Secure_Build_Scorecard_MEFOR.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -120,7 +120,8 @@ This scorecard is graded under the same declared deviation that governs Secure_D
120120
The canonical verdicts-of-record live in the cited `docs/security/` set. That set is maintainer-internal and is **not published in this repository**, so the entries below are cited by name for provenance, not linked — this scorecard is the public-facing summary and stands on its own. It grades on top of them and does not restate their per-requirement outcomes. Where an in-tree doc is superseded, it is flagged, not credited.
121121

122122
**Evidence base — `docs/security/` (cited, not restated):**
123-
- **ASVS-L3-ASSESSMENT-2026-07-16** — the **current** canonical verdict-of-record (Posture A 175 P / 50 Part / 2 Fail / 118 N/A; Posture B 199 / 51 / 2 / 93, at `363db4e3`; 11.7.1 full memory encryption scoped N/A as infrastructure). Grade off this doc. Supersedes ASVS-L3-ASSESSMENT-2026-07-09 (179 / 46 / 5 / 115; the reconciliation narrative in §2/§3 describes the state at that earlier assessment).
123+
- **ASVS-L3-RESCORE-2026-07-31** — the **current** verdict-of-record. Do not grade off any earlier assessment; the counts are maintainer-internal and are deliberately not restated here. Two things a reader of the older documents must know: the **Posture A / Posture B split is retired** (there is one scored posture, not two), and **V3 Web Frontend Security is scored in full** — the exclusion premise died when the browser console replaced the PySide6 desktop app.
124+
- ⛔ **ASVS-L3-ASSESSMENT-2026-07-16 — SUPERSEDED; do not cite.** This entry previously called it "the **current** canonical verdict-of-record" and told the reader to "grade off this doc". Both were wrong by 2026-07-31: its Posture A/B counts (175 / 50 / 2 / 118 and 199 / 51 / 2 / 93, at `363db4e3`) rest on a posture split that no longer exists, and four dated re-scores have landed since. It likewise supersedes ASVS-L3-ASSESSMENT-2026-07-09 (179 / 46 / 5 / 115), which the §2/§3 reconciliation narrative describes.
124125
- **ASVS-L3-RISK-ACCEPTANCE-REGISTER** — 8 sign-off themes with re-score triggers; signed 2026-07-14 (was a v1.0 draft with all blocks unsigned).
125126
- **ASVS-L3-STATUS.md** + **ASVS-FAILS-REMEDIATION-PLAN.md** — superseded, rosier scorecards (212/0/0/133 and 192/20/0/133 via the discarded "conditional Pass"); now carry SUPERSEDED banners; flagged, not credited.
126127
- **SDS-CONFORMANCE-REVIEW-2026-06-12** — self-assessment scorecard, point-in-time, superseded by its own 2026-06-16 note; several Fails now stale-against-HEAD.

0 commit comments

Comments
 (0)