mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
Adds scripts/validate_schema.py and a validate-data.yml PR gate that checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml: required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic folder consistency, and that referenced Sigma paths exist on disk. (Replaces the validate_schema.py that cp-drafter referenced but was never created.) Validator tolerates the authored conventions for Variations.Status and ExpectedFPRate (leading token + detail). Fixes surfaced by the validator/link audit: - 2 invalid Ids regenerated as real UUIDv4 (ransomware-service- manipulation, remote-execution-tools) - 4 dead reference citations repaired (Proofpoint moved URL; Trustwave via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a wrong slug -> correct article) Adds scripts/check_links.py — advisory external-link sweep (not a CI gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API endpoints and bot-blocked blogs are not mistaken for rot. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>