mirror of
https://github.com/BradGroux/veritas-kanban.git
synced 2026-09-09 14:41:03 +00:00
## Summary - adds a v5 permission coverage manifest with classifications, required permissions, denial reasons, and review justifications across REST, WebSocket, CLI, MCP, workflow, transition hook, command palette, and background job surfaces - adds a Node-based coverage checker that fails when tracked surfaces are missing from the manifest or when REST route prefixes drift from the shared permission map - wires the checker into CI and documents the manifest gate in the security guide Closes #420. ## Verification - `node scripts/check-permission-coverage.mjs` - `./node_modules/.bin/prettier --check package.json .github/workflows/ci.yml scripts/check-permission-coverage.mjs docs/security/permission-coverage.json docs/security.md` - `git diff --check` - `pnpm lint:budget` - `pnpm build` - `pnpm audit --prod --audit-level=high` (passes high gate; 3 existing moderate findings) - GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests |
||
|---|---|---|
| .. | ||
| permission-coverage.json | ||
| v4-governance-audit.md | ||