From 61f57715f09237ee6f3c31881d913c3d2b2de872 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:49:00 +0900 Subject: [PATCH] docs: document issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/audit-scoring.md | 3 +++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 11 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be3168f6..3299ddaa 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/CHANGELOG.md b/CHANGELOG.md index effd312c..6063057a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) diff --git a/docs/audit-scoring.md b/docs/audit-scoring.md index 6c29c7a0..f3c60f5f 100644 --- a/docs/audit-scoring.md +++ b/docs/audit-scoring.md @@ -65,3 +65,6 @@ JSON retains the definition/version/hash, profile plan and source provenance, ac Version 1.0.0 is defined in `config/audit_scoring.json` as `native-audit-score-v1`. Changing weights requires a reviewed definition-version change, rather than silently moving the denominator. Exact profile and corpus fingerprints let a reviewer identify what was assessed. The profile hash must match before and after planning and the plan's returned hash; observed source changes abort reporting. Hashes bind recorded content, not the trustworthiness of a malicious evidence author. Letter grades and a combined security score are deliberately not defined by this first implementation of issue #10. Tests cover exact/minimum mask truth tables, optional/role omissions, unknown and empty denominators, severity weights, exclusions/unique IDs, evidence-context preservation, source changes, output collisions, HTML encoding and public command isolation. Windows Server 2022/2025 PowerShell 5.1/7 tests read real policy and verify that native masks/precedence remain unchanged. Synthetic Ready rows test arithmetic only. No Windows 11/DC/AD CS deployment or backend query evidence is claimed by those tests. ++### Issue 10 coverage + +Audit scoring uses weighted rule metadata and reports numerator, denominator, exclusions, and conditional evidence. A score summarizes reviewed eligibility states; it does not prove event generation, forwarding, or detection. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c6d60d09..6b572496 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 4799aff0..3b3e7ddb 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385)