fix(harden): severity rule defers to the calibrated guide; SSL Labs late-finalize gets an assigned actor (main loop edits HARDEN.md row)

This commit is contained in:
Bastien Chanot
2026-08-26 20:35:35 +02:00
parent 1743f7683f
commit ab75fc5e1f
+8 -6
View File
@@ -493,10 +493,10 @@ else
fi fi
``` ```
Update `.harden-cache/external-scores.md` with the final SSL Labs verdict Update `.harden-cache/external-scores.md` with the final SSL Labs verdict,
so the HARDEN.md "External validators" table reflects it. If the user then edit the SSL Labs row of HARDEN.md's "External validators" table in
already read HARDEN.md, they can re-run `/harden <url>` to pick up the place — YOU do this in the main loop (the agent that wrote HARDEN.md in
cached (now-READY) SSL Labs result. STEP 1 has already exited; without this edit the late grade never lands).
--- ---
@@ -621,8 +621,10 @@ NEXT STEPS :
Astro / Cloudflare Pages project. Use the framework-native mechanism Astro / Cloudflare Pages project. Use the framework-native mechanism
(next.config.js headers(), astro middleware, _headers). (next.config.js headers(), astro middleware, _headers).
- **Security headers and redirects are non-negotiable defaults of this - **Security headers and redirects are non-negotiable defaults of this
skill** — every public site must ship them. Flag absence as Critique, skill** — every public site must ship them. Grade each absence at the
not Moyenne. severity guide's level (CSP absent = Critique, HSTS/X-Frame-Options =
Haute, Referrer-Policy = Moyenne); the guide's table is authoritative —
never demote a missing default below it.
- **External validators are authoritative on live headers, not the code.** - **External validators are authoritative on live headers, not the code.**
If Observatory/SecurityHeaders/SSL Labs and the code audit disagree, If Observatory/SecurityHeaders/SSL Labs and the code audit disagree,
the external grade reflects the deployed production config — the code the external grade reflects the deployed production config — the code