diff --git a/docs/features/bio-compliance-assessment.md b/docs/features/bio-compliance-assessment.md index 063691e5..430c7757 100644 --- a/docs/features/bio-compliance-assessment.md +++ b/docs/features/bio-compliance-assessment.md @@ -13,7 +13,7 @@ per-organisation **BIO coverage report**, and a declarative notification for overdue DPIA reviews. Specifications: -[`openspec/specs/bio-compliance-assessment/spec.md`](../../openspec/specs/bio-compliance-assessment/spec.md) +[`openspec/specs/bio-compliance-assessment/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/bio-compliance-assessment/spec.md) (new capability) and the `module-compliance-assessment` MODIFIED delta (BIO-measure column source on the compliance matrix). diff --git a/docs/features/catalog-ratings.md b/docs/features/catalog-ratings.md index a3c194e1..586fa3a2 100644 --- a/docs/features/catalog-ratings.md +++ b/docs/features/catalog-ratings.md @@ -12,7 +12,7 @@ create/update/delete rules, no attributable author). See [VNG Softwarecatalogus issue #49](https://github.com/VNG-Realisatie/Softwarecatalogus/issues/49) and stackiq#375. -Specification: [`openspec/specs/catalog-ratings/spec.md`](../../openspec/specs/catalog-ratings/spec.md). +Specification: [`openspec/specs/catalog-ratings/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/catalog-ratings/spec.md). ## Why it existed but didn't work diff --git a/docs/features/eol-feed-integration.md b/docs/features/eol-feed-integration.md index e1443e45..25c8d747 100644 --- a/docs/features/eol-feed-integration.md +++ b/docs/features/eol-feed-integration.md @@ -14,7 +14,7 @@ roadmap, and `eol-approaching` notification rule declared in what populates the field they already read. Specification: -[`openspec/specs/eol-feed-integration/spec.md`](../../openspec/specs/eol-feed-integration/spec.md). +[`openspec/specs/eol-feed-integration/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/eol-feed-integration/spec.md). ## Architecture: stackiq never calls endoflife.date diff --git a/docs/features/multi-org-membership.md b/docs/features/multi-org-membership.md index 0bb3456c..3111089d 100644 --- a/docs/features/multi-org-membership.md +++ b/docs/features/multi-org-membership.md @@ -15,7 +15,7 @@ gemeentelijke herindeling. See [#60](https://github.com/VNG-Realisatie/Softwarecatalogus/issues/60), and [#65](https://github.com/VNG-Realisatie/Softwarecatalogus/issues/65). -Specification: [`openspec/specs/multi-org-membership/spec.md`](../../openspec/specs/multi-org-membership/spec.md). +Specification: [`openspec/specs/multi-org-membership/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/multi-org-membership/spec.md). Everything in this feature is built on OpenRegister's own, already-shipped `OrganisationService`/`OrganisationController` — Stackiq does not diff --git a/docs/features/organisation-merge.md b/docs/features/organisation-merge.md index ee42db62..f383b0cc 100644 --- a/docs/features/organisation-merge.md +++ b/docs/features/organisation-merge.md @@ -12,7 +12,7 @@ Every relation that references the source organisation is re-pointed onto the target, and the source is soft-retired with a tombstone rather than deleted. See [VNG Softwarecatalogus issue #141](https://github.com/VNG-Realisatie/Softwarecatalogus/issues/141). -Specification: [`openspec/specs/organisation-merge/spec.md`](../../openspec/specs/organisation-merge/spec.md). +Specification: [`openspec/specs/organisation-merge/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/organisation-merge/spec.md). ## What gets re-pointed diff --git a/docs/features/portfolio-rationalization-time.md b/docs/features/portfolio-rationalization-time.md index 243f2c85..43d73566 100644 --- a/docs/features/portfolio-rationalization-time.md +++ b/docs/features/portfolio-rationalization-time.md @@ -15,7 +15,7 @@ quadrant counts with existing end-of-support exposure [VNG Softwarecatalogus issue #54](https://github.com/VNG-Realisatie/Softwarecatalogus/issues/54). Specification: -[`openspec/changes/portfolio-rationalization-time/specs/portfolio-rationalization-time/spec.md`](../../openspec/changes/portfolio-rationalization-time/specs/portfolio-rationalization-time/spec.md). +[`openspec/specs/portfolio-rationalization-time/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/portfolio-rationalization-time/spec.md). > Screenshots of the report page are still pending a live-instance capture — > this document ships with the implementation; the Playwright-captured diff --git a/docs/features/sbom-import.md b/docs/features/sbom-import.md index 3ece825c..038af280 100644 --- a/docs/features/sbom-import.md +++ b/docs/features/sbom-import.md @@ -12,7 +12,7 @@ SPDX 2.3 JSON as an optional second format — for a specific `moduleVersie` tab with licenses, summary counts, and a render-time cross-reference against the existing `kwetsbaarheid` (vulnerability) register. -Specification: [`openspec/specs/sbom-import/spec.md`](../../openspec/specs/sbom-import/spec.md). +Specification: [`openspec/specs/sbom-import/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/sbom-import/spec.md). ## Uploading an SBOM diff --git a/docs/features/suite-wizard.md b/docs/features/suite-wizard.md index ad74ff90..6becaf90 100644 --- a/docs/features/suite-wizard.md +++ b/docs/features/suite-wizard.md @@ -12,7 +12,7 @@ replaces the retired incumbent "product" concept per [VNG Softwarecatalogus issue #242](https://github.com/VNG-Realisatie/Softwarecatalogus/issues/242) and stackiq#372. -Specification: [`openspec/specs/suite-wizard/spec.md`](../../openspec/specs/suite-wizard/spec.md). +Specification: [`openspec/specs/suite-wizard/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/suite-wizard/spec.md). ## Registering a suite diff --git a/docs/security/vendor-visibility-rbac.md b/docs/security/vendor-visibility-rbac.md index 21dee488..9f10981c 100644 --- a/docs/security/vendor-visibility-rbac.md +++ b/docs/security/vendor-visibility-rbac.md @@ -4,16 +4,16 @@ Task 6 of `openspec/changes/vendor-visibility-rbac/tasks.md`: every route in `appinfo/routes.php` whose controller method reads a `gebruik`, `koppeling`, or `contract` OpenRegister object, enumerated with its authorization posture and the test(s) that cover it, per -[REQ-007](../../openspec/specs/vendor-visibility-rbac/spec.md#requirement-every-route-touching-gebruik-koppeling-or-contract-objects-must-have-a-documented-tested-authorization-posture-req-007). +[REQ-007](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/vendor-visibility-rbac/spec.md). **Updated by `schema-rbac-hardening`** (stackiq #379, #390, #378): closed the two follow-up gaps this audit originally flagged below — the `gebruik`/`koppeling`/`organisatie` schema-level RBAC gap and the `AanbodController::getAanbod()` implicit-guard gap — and extended the `contract` schema fix (REQ-006) to the roles it had not yet covered. See -[REQ-008](../../openspec/specs/vendor-visibility-rbac/spec.md#requirement-gebruik-koppeling-and-organisatie-schema-level-rbac-reads-must-deny-cross-organisation-access-for-gebruik-beheerder-req-008) +[REQ-008](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/vendor-visibility-rbac/spec.md) and -[REQ-009](../../openspec/specs/vendor-visibility-rbac/spec.md#requirement-the-aanbod-listing-endpoint-must-require-authentication-explicitly-not-implicitly-req-009). +[REQ-009](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/vendor-visibility-rbac/spec.md). Both the schema-RBAC layer and the one deliberately accepted residual (deelnemer-array sharing) are documented in the new section below.