Skip to content

Add non-human credential access review gates#1698

Open
modelsbridgeaicom-ship-it wants to merge 1 commit into
UnitOneAI:mainfrom
modelsbridgeaicom-ship-it:improve/nonhuman-credential-gates-1688
Open

Add non-human credential access review gates#1698
modelsbridgeaicom-ship-it wants to merge 1 commit into
UnitOneAI:mainfrom
modelsbridgeaicom-ship-it:improve/nonhuman-credential-gates-1688

Conversation

@modelsbridgeaicom-ship-it
Copy link
Copy Markdown

Summary

  • add a non-human credential and API access review step to access-review
  • require first-class evidence for API keys, PATs, OAuth grants, deploy keys, webhook secrets, CI/CD tokens, and bot credentials
  • add AR-NHI-* findings, evidence quality guidance, severity guidance, report output fields, common pitfall, cross-reference, and version bump

Validation

  • git diff --check
  • Markdown fence balance check: 20 fences, balanced
  • Marker checks for AR-NHI-01, AR-SCOPE-07, Non-Human Credentials, Credential-level blind spot, and version: 1.1.0

Closes #1688

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] access-review: add non-human credential evidence gates

1 participant