Skip to content

Add firewall IPv6 temporary rule evidence fixtures#1483

Open
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/firewall-ipv6-expiry-1260
Open

Add firewall IPv6 temporary rule evidence fixtures#1483
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/firewall-ipv6-expiry-1260

Conversation

@jddark62

@jddark62 jddark62 commented Jun 6, 2026

Copy link
Copy Markdown

Summary

  • adds IPv6 parity evidence gates for enabled/routed status, IPv4/IPv6 default-deny parity, privileged ::/0 ingress, unrestricted IPv6 egress, and IPv6 logging parity
  • adds temporary-rule and exception evidence gates for owner, ticket, expiry/review date, renewal/removal plan, dependency validation, and broad emergency-access governance
  • extends report output with IPv6 parity and temporary-rule tables
  • adds 7 fixtures covering IPv6 disabled Not Applicable, reachable IPv6 SSH exposure, iptables/ip6tables default-policy drift, controlled IPv6 HTTPS egress via proxy, unrestricted IPv6 egress, expired temporary DB access, and zero-hit removal after counter reset

Validation

  • git diff --check
  • verified SKILL.md frontmatter fields
  • verified Markdown fence balance
  • parsed all 7 YAML fixture blocks
  • verified markers for FW-IPV6-*, FW-TEMP-*, ::/0, ip6tables, ipv6_cidr_blocks, temporary-rule output, Not Applicable, and Not Evaluable
  • verified added lines and fixture file are ASCII-only
  • verified AWS, Azure, and Google Cloud firewall reference links returned HTTP 200
  • privacy scan passed for changed files

/claim #1260

Payment details can be coordinated privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant