job3: C6 harden — drop false CLAUDE.md attribution, own-policy framing

This commit is contained in:
Bastien Chanot
2026-07-06 16:55:17 +02:00
parent 215bc2d6b4
commit 2848ff0b77
+3 -3
View File
@@ -593,9 +593,9 @@ NEXT STEPS :
- **Framework awareness.** Don't recommend `.htaccess` on a Next.js / - **Framework awareness.** Don't recommend `.htaccess` on a Next.js /
Astro / Cloudflare Pages project. Use the framework-native mechanism Astro / Cloudflare Pages project. Use the framework-native mechanism
(next.config.js headers(), astro middleware, _headers). (next.config.js headers(), astro middleware, _headers).
- **Respect CLAUDE.md architecture rules.** Security headers and redirects - **Security headers and redirects are non-negotiable defaults of this
are non-negotiable defaults per user's global CLAUDE.md — every public skill** — every public site must ship them. Flag absence as Critique,
site must ship them. Flag absence as Critique, not Moyenne. not Moyenne.
- **External validators are authoritative on live headers, not the code.** - **External validators are authoritative on live headers, not the code.**
If Observatory/SecurityHeaders/SSL Labs and the code audit disagree, If Observatory/SecurityHeaders/SSL Labs and the code audit disagree,
the external grade reflects the deployed production config — the code the external grade reflects the deployed production config — the code