Core repository readiness¶
Profile: prc/core-repository@1.0
Deterministic repository governance, documentation, workflow, dependency, security, API-contract, and test foundations.
This pilot demonstrates the structured control-to-assertion model. A listed assertion is not a claim that the scanner implementation exists unless its implementation is present and verified by the scanner test suite.
Assertions¶
| Assertion | Objective | Severity | Gate | Evidence | Remediation |
|---|---|---|---|---|---|
PRC-A-CORE-001 — README is present |
USEQ-FDCA6C71 | medium | required | repository-file | R2 |
PRC-A-CORE-002 — License is present |
USEQ-6497B434 | medium | required | repository-file | R0 |
PRC-A-CORE-003 — Contribution guidance is present |
USEQ-89F5E97A | low | advisory | repository-file | R0 |
PRC-A-CORE-004 — Security policy is present |
USEQ-AC6AC548 | medium | required | repository-file | R0 |
PRC-A-CORE-005 — Code of conduct is present |
USEQ-D73106BF | low | advisory | repository-file | R0 |
PRC-A-CORE-006 — Code ownership is declared |
USEQ-CA602113 | medium | required | repository-file | R0 |
PRC-A-CORE-007 — Dependency resolution is reproducible |
USEQ-D1076D92 | high | required | repository-file | R2 |
PRC-A-CORE-008 — GitHub Actions use immutable references |
USEQ-F4D6E3B3 | high | required | workflow-parse | R2 |
PRC-A-CORE-009 — Continuous integration is configured |
USEQ-12655775 | medium | required | repository-file | R2 |
PRC-A-CORE-010 — Automated tests are discoverable |
USEQ-12655775 | high | required | repository-structure | R2 |
PRC-A-CORE-011 — Workflow permissions are explicit |
USEQ-73488048 | high | required | workflow-parse | R2 |
PRC-A-CORE-012 — Generated code follows normal review controls |
USEQ-F0F5ACE7 | high | required | reviewer-attestation | R0 |
PRC-A-CORE-013 — Configured secret detection has executed |
USEQ-70E9D5AA | high | required | analysis-result | R2 |
PRC-A-CORE-014 — Source files end with a newline |
USEQ-DAF77C8F | low | advisory | source-format | R1 |
PRC-A-CORE-015 — Source revision is identifiable |
USEQ-72088469 | medium | required | repository-identity | R0 |
PRC-A-CORE-016 — Dependency updates are configured |
PRC-36-011 | medium | advisory | repository-file | R2 |
PRC-A-CORE-017 — Workflow definitions parse |
USEQ-F4D6E3B3 | high | required | workflow-parse | R2 |
PRC-A-CORE-018 — Workflows define executable jobs |
USEQ-12655775 | high | required | workflow-parse | R2 |
PRC-A-CORE-019 — Workflow jobs have bounded runtimes |
USEQ-B66A3064 | medium | required | workflow-parse | R2 |
PRC-A-CORE-020 — pull_request_target workflows receive security review |
USEQ-73488048 | critical | required | workflow-parse | R0 |
PRC-A-CORE-021 — Unresolved merge conflicts are absent |
USEQ-12655775 | high | no-go | source-integrity | R2 |
PRC-A-CORE-022 — Repository files are not broadly writable |
USEQ-D60E6950 | medium | advisory | repository-metadata | R1 |
PRC-A-CORE-023 — Dependency manifests are nonempty |
USEQ-D1076D92 | high | required | repository-file | R2 |
PRC-A-CORE-024 — Dependency locks are nonempty |
USEQ-D1076D92 | high | required | repository-file | R2 |
PRC-A-CORE-025 — Runtime versions are declared |
USEQ-0B7FDB5F | medium | required | runtime-declaration | R2 |
PRC-A-CORE-026 — Container base images are immutable |
USEQ-7D4DA192 | high | required | containerfile-parse | R2 |
PRC-A-CORE-027 — Final container stages declare a non-root user |
USEQ-A3559C64 | high | required | containerfile-parse | R2 |
PRC-A-CORE-028 — Terraform provider selections are locked |
USEQ-D1076D92 | medium | advisory | repository-file | R2 |
PRC-A-CORE-029 — Kubernetes workloads require non-root containers |
USEQ-A3559C64 | high | required | kubernetes-parse | R2 |
PRC-A-CORE-030 — Kubernetes containers declare resource policy |
USEQ-13CBD6C6 | high | required | kubernetes-parse | R2 |
PRC-A-K8S-001 — Kubernetes workloads avoid privileged host access |
USEQ-A3559C64 | high | required | kubernetes-parse | R2 |
PRC-A-K8S-002 — Kubernetes Linux containers disable privilege escalation |
USEQ-A3559C64 | high | required | kubernetes-parse | R2 |
PRC-A-K8S-003 — Kubernetes Linux containers restrict capabilities |
USEQ-A3559C64 | high | required | kubernetes-parse | R2 |
PRC-A-K8S-004 — Kubernetes Linux containers use bounded seccomp profiles |
USEQ-A3559C64 | medium | required | kubernetes-parse | R2 |
PRC-A-CORE-031 — Private-key armor is absent from repository files |
USEQ-E85957E3 | critical | no-go | sensitive-material-scan | R2 |
PRC-A-GO-001 — Go net/http package helpers do not use the default client |
USEQ-F6ACEF15 | high | required | go-ast-analysis | R2 |
PRC-A-GO-002 — Go HTTP servers use configurable Server instances |
USEQ-B66A3064 | high | required | go-ast-analysis | R2 |
PRC-A-API-001 — OpenAPI documents expose required root metadata |
USEQ-13208C54 | medium | required | openapi-parse | R2 |
PRC-A-API-002 — OpenAPI operations define valid responses |
USEQ-13208C54 | high | required | openapi-parse | R2 |
PRC-A-API-003 — Declared OpenAPI operation IDs are unique |
USEQ-13208C54 | medium | required | openapi-parse | R2 |
Result interpretation¶
The profile is satisfied only when every applicable required assertion has current passing evidence and no configured gate blocks the result. Manual or external evidence remains visible and cannot be inferred from repository files.