Skip to content

feat(data): verification methods and links data model (refs #191) - #215

Open
a-moskvin wants to merge 1 commit into
GenAI-Security-Project:mainfrom
a-moskvin:feat/verification-data-model
Open

a-moskvin wants to merge 1 commit into
GenAI-Security-Project:mainfrom
a-moskvin:feat/verification-data-model

Conversation

@a-moskvin

Copy link
Copy Markdown

What this PR changes

Implements the verification-methods data model agreed in #191 (follow-up to #101 / #186). Data, schemas and validator only; no methods yet. The pilot follows in a separate PR.

  • data/verification-methods-schema.json, data/verification-links-schema.json: Draft-07 schemas
  • data/verification-methods.json: empty methods array
  • data/verification-links/: one file per framework (none yet)
  • scripts/verification.js: schema-derived checks plus cross-file rules; called from scripts/validate.js on full runs
  • scripts/verification.test.mjs: 34 tests; each rule has a breaking fixture, cross-checked against the schemas with Ajv
  • docs/VERIFICATION_METHODS.md: specification; data/README.md and CHANGELOG.md updated

No changes to generate.js, exports, webapp or the npm package contents. Regenerating produces no data changes.

Type of change

  • New mapping file
  • Update to existing mapping (content, controls, CVE refs)
  • Bug fix (broken link, typo, incorrect cross-ref)
  • New recipe (shared/RECIPES.md)
  • New tool (shared/TOOLS.md)
  • Infrastructure (scripts, CI, templates)
  • Translation (i18n/)

Source / evidence

#191 (follow-up to #101 / #186)

Checklist

  • npm run build passes: 0 errors, warnings unchanged from main
  • npm test passes: 129/129
  • CHANGELOG.md updated

Content

  • Follows the file template structure (header comment, H1, Why section, quick-reference table, audience
    tags, detailed per-entry mappings, references, changelog)
  • Severity ratings consistent with AIVSS / OWASP definitions in shared/SEVERITY.md
  • Cross-references are bidirectional — if this file mentions Agentic_X.md, that file mentions this one back
  • All referenced vulnerability IDs are valid (LLM01–LLM10, ASI01–ASI10, DSGAI01–DSGAI21)
  • License header present: CC BY-SA 4.0

Links & data

  • All internal .md links resolve to real files
  • All external URLs return 200 (checked manually or via lychee)
  • data/schema.json compatible (if adding a new entry type)

Project hygiene

  • Changelog entry added at bottom of every modified file (YYYY-MM-DD format)
  • CHANGELOG.md updated if this is a new mapping file (include in correct version section)
  • README.md counts updated if file count changed (badge + summary table + section heading + repo tree)
  • Ran node scripts/validate.js --file <path> locally and it passes

For new mapping files only

  • Added to correct section in README.md mapping table with "Standout content" description
  • Added to CROSSREF.md primary frameworks column where relevant
  • Framework coverage matrix in README.md updated (✅ for the new cell)
  • File named correctly: SourceList_Framework.md (e.g., Agentic_SAMM.md)

Notes for reviewers

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant