feat(security): implement deterministic weighted posture scoring engine and service - #204
Merged
mijinummi merged 1 commit intoJul 19, 2026
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🎯 Core Overview
Problem Statement
Security analysts currently process high volumes of loose alert telemetry across environments, but lack a clear, single key performance indicator (KPI) summarizing an organization's overall operational security risk. This makes it difficult to track risk levels over time or flag gradual security degradation before an incident occurs.
Proposed Solution
This PR adds the core elements of the
SecurityPostureScoringSystemundersrc/modules/security-posture/. It introduces a deterministic scoring engine that processes configurable weighted risk parameters, caps deduction vectors, and normalizes output scores on a 0–100 scale. It also includes an alert hook to catch score drops below configured thresholds.Closes #153
🛠️ Technical Implementation Details
1. Deterministic Calculation Architecture
PostureScoreEnginewith isolated pure evaluation logic. Given the same configuration arrays and inputs, the system returns identical scores, ensuring testability and compliance.2. Fault-Isolated Processing
3. Metric Weights & Contribution Caps
weightcoefficients andmaxContributioncaps) to ensure that a massive burst of minor alerts cannot completely wipe out an organization's security score on its own.📋 Quality Assurance Matrix
npm run build).