Repository navigation
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rules Content Changes
FRD-MST(MUST): an absolute requirement that must be met and documented, with failure potentially requiring corrective action or denial of initial or ongoing certification.FRD-MNT(MUST NOT): an absolute prohibition that must be observed and documented, with the same potential consequences for failure.FRD-SHD(SHOULD): departures may have valid reasons, but parties must carefully weigh the implications and document their decisions.FRD-SNT(SHOULD NOT): the discouraged action may be justified in particular circumstances, but parties must carefully weigh the implications and document their decisions.FRD-MAY(MAY): the rule is optional, and parties should explain their decisions in security documentation.FRD-MST,FRD-MNT,FRD-SHD,FRD-SNT, andFRD-MAYunderFRD.data.all, tagged “Force of the Rule,” with uppercase-only applicability,do_not_link: true, andignore_in_terms: true.ignore_in_terms: trueforFRD-ADV(Advisor),FRD-AGY(Agency),FRD-ASR(Assessor), andFRD-PRV(Provider).termsmetadata across 236 FRR requirements and six KSI indicators by removing references to the excluded stakeholder terms (FRD-ADV,FRD-AGY,FRD-ASR, andFRD-PRV); this is mechanical metadata cleanup with no changes to their statements.Schema And Structure Changes
ignore_in_terms, supported as an optional boolean at$defs.frd_definition.properties.ignore_in_termsinschemas/fedramp-consolidated-rules.schema.json; the previous schema rejected this property, so consumers validating the new dataset against the old schema must update.Tooling And Test Changes
tools/src/terms.tsto exclude flagged definitions and their aliases from FRR and KSI term matching, allowing checks to detect existing excluded terms and fixers to remove them; absent or false flags preserve normal matching.ignore_in_terms?: booleantoDefinitionEntryintools/src/types.ts.tools/tests/terms.test.tsto cover absent, false, and true flags; aliases; FRR and class-specific KSI statements; all definition applicability buckets; read-only analysis; and repeatable fixes.tools/tests/fix.test.tsto verify that automatic fixes remove an ignored force term.tools/README.md.