Skip to content

Core repository readiness

Profile: prc/core-repository@1.0

Deterministic repository governance, documentation, workflow, dependency, security, API-contract, and test foundations.

This pilot demonstrates the structured control-to-assertion model. A listed assertion is not a claim that the scanner implementation exists unless its implementation is present and verified by the scanner test suite.

Assertions

Assertion Objective Severity Gate Evidence Remediation
PRC-A-CORE-001 — README is present USEQ-FDCA6C71 medium required repository-file R2
PRC-A-CORE-002 — License is present USEQ-6497B434 medium required repository-file R0
PRC-A-CORE-003 — Contribution guidance is present USEQ-89F5E97A low advisory repository-file R0
PRC-A-CORE-004 — Security policy is present USEQ-AC6AC548 medium required repository-file R0
PRC-A-CORE-005 — Code of conduct is present USEQ-D73106BF low advisory repository-file R0
PRC-A-CORE-006 — Code ownership is declared USEQ-CA602113 medium required repository-file R0
PRC-A-CORE-007 — Dependency resolution is reproducible USEQ-D1076D92 high required repository-file R2
PRC-A-CORE-008 — GitHub Actions use immutable references USEQ-F4D6E3B3 high required workflow-parse R2
PRC-A-CORE-009 — Continuous integration is configured USEQ-12655775 medium required repository-file R2
PRC-A-CORE-010 — Automated tests are discoverable USEQ-12655775 high required repository-structure R2
PRC-A-CORE-011 — Workflow permissions are explicit USEQ-73488048 high required workflow-parse R2
PRC-A-CORE-012 — Generated code follows normal review controls USEQ-F0F5ACE7 high required reviewer-attestation R0
PRC-A-CORE-013 — Configured secret detection has executed USEQ-70E9D5AA high required analysis-result R2
PRC-A-CORE-014 — Source files end with a newline USEQ-DAF77C8F low advisory source-format R1
PRC-A-CORE-015 — Source revision is identifiable USEQ-72088469 medium required repository-identity R0
PRC-A-CORE-016 — Dependency updates are configured PRC-36-011 medium advisory repository-file R2
PRC-A-CORE-017 — Workflow definitions parse USEQ-F4D6E3B3 high required workflow-parse R2
PRC-A-CORE-018 — Workflows define executable jobs USEQ-12655775 high required workflow-parse R2
PRC-A-CORE-019 — Workflow jobs have bounded runtimes USEQ-B66A3064 medium required workflow-parse R2
PRC-A-CORE-020 — pull_request_target workflows receive security review USEQ-73488048 critical required workflow-parse R0
PRC-A-CORE-021 — Unresolved merge conflicts are absent USEQ-12655775 high no-go source-integrity R2
PRC-A-CORE-022 — Repository files are not broadly writable USEQ-D60E6950 medium advisory repository-metadata R1
PRC-A-CORE-023 — Dependency manifests are nonempty USEQ-D1076D92 high required repository-file R2
PRC-A-CORE-024 — Dependency locks are nonempty USEQ-D1076D92 high required repository-file R2
PRC-A-CORE-025 — Runtime versions are declared USEQ-0B7FDB5F medium required runtime-declaration R2
PRC-A-CORE-026 — Container base images are immutable USEQ-7D4DA192 high required containerfile-parse R2
PRC-A-CORE-027 — Final container stages declare a non-root user USEQ-A3559C64 high required containerfile-parse R2
PRC-A-CORE-028 — Terraform provider selections are locked USEQ-D1076D92 medium advisory repository-file R2
PRC-A-CORE-029 — Kubernetes workloads require non-root containers USEQ-A3559C64 high required kubernetes-parse R2
PRC-A-CORE-030 — Kubernetes containers declare resource policy USEQ-13CBD6C6 high required kubernetes-parse R2
PRC-A-K8S-001 — Kubernetes workloads avoid privileged host access USEQ-A3559C64 high required kubernetes-parse R2
PRC-A-K8S-002 — Kubernetes Linux containers disable privilege escalation USEQ-A3559C64 high required kubernetes-parse R2
PRC-A-K8S-003 — Kubernetes Linux containers restrict capabilities USEQ-A3559C64 high required kubernetes-parse R2
PRC-A-K8S-004 — Kubernetes Linux containers use bounded seccomp profiles USEQ-A3559C64 medium required kubernetes-parse R2
PRC-A-CORE-031 — Private-key armor is absent from repository files USEQ-E85957E3 critical no-go sensitive-material-scan R2
PRC-A-GO-001 — Go net/http package helpers do not use the default client USEQ-F6ACEF15 high required go-ast-analysis R2
PRC-A-GO-002 — Go HTTP servers use configurable Server instances USEQ-B66A3064 high required go-ast-analysis R2
PRC-A-API-001 — OpenAPI documents expose required root metadata USEQ-13208C54 medium required openapi-parse R2
PRC-A-API-002 — OpenAPI operations define valid responses USEQ-13208C54 high required openapi-parse R2
PRC-A-API-003 — Declared OpenAPI operation IDs are unique USEQ-13208C54 medium required openapi-parse R2

Result interpretation

The profile is satisfied only when every applicable required assertion has current passing evidence and no configured gate blocks the result. Manual or external evidence remains visible and cannot be inferred from repository files.