[
  {
    "id": "nist-ssdf-sp-800-218-candidate",
    "title": "NIST Secure Software Development Framework SP 800-218",
    "url": "https://csrc.nist.gov/pubs/sp/800/218/final",
    "allowed_origin": "https://csrc.nist.gov",
    "allowed_path_prefix": "/pubs/sp/800/218/final",
    "source_type": "secure_software_development_framework",
    "trust_label": "authoritative_public_standard_candidate",
    "freshness_label": "periodic_review_required",
    "claim_boundary": "current_public_secure_software_guidance_only_not_package_authority",
    "source_owner": "NIST Computer Security Resource Center",
    "proposed_approver": "package_governance_owner_review_required",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "review_cadence": "before_production_enablement_then_periodic",
    "intended_use_cases": [
      "compare package-first source-grounded assistant guidance with public secure software development guidance",
      "screen secure engineering and software supply-chain claims after approved package support exists"
    ],
    "non_use_cases": [
      "tool approval",
      "vendor approval",
      "production approval",
      "company policy approval",
      "replacement for package or owner-validated authority"
    ],
    "limitations": [
      "Voluntary public guidance can be mistaken for enterprise approval if source lanes are not preserved.",
      "HTML extraction may lose tables, caveats, or publication metadata."
    ],
    "reason_for_inclusion": "Authoritative NIST secure software development framework material with a public HTTPS HTML landing page and narrow stable path.",
    "enablement_priority": "1 - strongest next candidate after NIST AI RMF",
    "notes": "Candidate-only review artifact. This is not production configuration and not approved package authority.",
    "verification": {
      "checked_date": "2026-06-24",
      "method": "non-authenticated HTTP HEAD/GET probe",
      "final_url": "https://csrc.nist.gov/pubs/sp/800/218/final",
      "http_status": 200,
      "content_type": "text/html; charset=utf-8",
      "redirect_count": 0,
      "login_required": false,
      "credentials_in_url": false,
      "private_or_internal_hostname": false,
      "wildcard_domain": false,
      "text_like_content": true
    }
  },
  {
    "id": "nist-ai-rmf-playbook-candidate",
    "title": "NIST AI RMF Playbook",
    "url": "https://airc.nist.gov/airmf-resources/playbook/",
    "allowed_origin": "https://airc.nist.gov",
    "allowed_path_prefix": "/airmf-resources/playbook/",
    "source_type": "public_standards_or_regulatory",
    "trust_label": "authoritative_public_standard_candidate",
    "freshness_label": "living_resource_review_required",
    "claim_boundary": "current_public_context_only_not_package_authority",
    "source_owner": "NIST AI Resource Center",
    "proposed_approver": "package_governance_owner_review_required",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "review_cadence": "before_production_enablement_then_periodic",
    "intended_use_cases": [
      "compare package-first source-grounded assistant behavior with NIST AI RMF playbook suggestions",
      "support bounded current/public context after package support exists"
    ],
    "non_use_cases": [
      "package authority",
      "policy approval",
      "production approval",
      "complete AI governance checklist",
      "replacement for the enabled NIST AI RMF source"
    ],
    "limitations": [
      "The page states the AI RMF is being updated and the Playbook will be updated after the AI RMF is revised.",
      "Living resource content requires freshness review before enablement."
    ],
    "reason_for_inclusion": "Official NIST AI RMF knowledge-base material related to the already enabled NIST AI RMF source, verified as public HTML at a canonical AIRC path.",
    "enablement_priority": "2 - same-family NIST expansion",
    "notes": "Candidate-only review artifact. This is not production configuration and not approved package authority.",
    "verification": {
      "checked_date": "2026-06-24",
      "method": "non-authenticated HTTP HEAD/GET probe",
      "final_url": "https://airc.nist.gov/airmf-resources/playbook/",
      "http_status": 200,
      "content_type": "text/html; charset=utf-8",
      "redirect_count": 0,
      "login_required": false,
      "credentials_in_url": false,
      "private_or_internal_hostname": false,
      "wildcard_domain": false,
      "text_like_content": true
    }
  },
  {
    "id": "owasp-genai-llm-top-10-2025-candidate",
    "title": "OWASP Top 10 for LLMs and Gen AI Apps 2025",
    "url": "https://genai.owasp.org/llm-top-10/",
    "allowed_origin": "https://genai.owasp.org",
    "allowed_path_prefix": "/llm-top-10/",
    "source_type": "llm_application_security_framework",
    "trust_label": "respected_security_framework_candidate",
    "freshness_label": "periodic_review_required",
    "claim_boundary": "current_public_security_guidance_only_not_package_authority",
    "source_owner": "OWASP Foundation GenAI Security Project",
    "proposed_approver": "package_governance_owner_review_required",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "review_cadence": "before_production_enablement_then_periodic",
    "intended_use_cases": [
      "compare package source-grounding boundaries with LLM application security risk categories",
      "screen prompt injection, disclosure, supply-chain, agency, and consumption risk claims after package support exists"
    ],
    "non_use_cases": [
      "company policy approval",
      "complete control set",
      "production approval",
      "tool approval",
      "package authority"
    ],
    "limitations": [
      "Community-maintained material may change and may be broader than this package's field guidance scope.",
      "It should not be treated as a complete security program or implementation approval."
    ],
    "reason_for_inclusion": "Respected public LLM application security framework with a 2025 Top 10 page and a narrow stable project path.",
    "enablement_priority": "3 - LLM application security",
    "notes": "Candidate-only review artifact. This is not production configuration and not approved package authority.",
    "verification": {
      "checked_date": "2026-06-24",
      "method": "non-authenticated HTTP HEAD/GET probe",
      "final_url": "https://genai.owasp.org/llm-top-10/",
      "http_status": 200,
      "content_type": "text/html; charset=UTF-8",
      "redirect_count": 0,
      "login_required": false,
      "credentials_in_url": false,
      "private_or_internal_hostname": false,
      "wildcard_domain": false,
      "text_like_content": true
    }
  },
  {
    "id": "cisa-secure-by-design-candidate",
    "title": "CISA Secure by Design",
    "url": "https://www.cisa.gov/securebydesign",
    "allowed_origin": "https://www.cisa.gov",
    "allowed_path_prefix": "/securebydesign",
    "source_type": "government_cybersecurity_guidance",
    "trust_label": "authoritative_public_government_candidate",
    "freshness_label": "periodic_review_required",
    "claim_boundary": "current_public_cybersecurity_guidance_only_not_package_authority",
    "source_owner": "Cybersecurity and Infrastructure Security Agency",
    "proposed_approver": "package_governance_owner_review_required",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "review_cadence": "before_production_enablement_then_periodic",
    "intended_use_cases": [
      "compare package secure engineering guidance with public government secure-by-design guidance",
      "support implementation screening after approved package support exists"
    ],
    "non_use_cases": [
      "enterprise policy approval",
      "Cloudflare configuration approval",
      "provider or model approval",
      "production approval",
      "package authority"
    ],
    "limitations": [
      "Public guidance does not approve this repository's architecture, deployment, or production operation.",
      "Owner review must confirm the page supports the intended claim at the time of enablement."
    ],
    "reason_for_inclusion": "Official CISA public cybersecurity guidance relevant to secure product and engineering practices.",
    "enablement_priority": "4 - government secure engineering guidance",
    "notes": "Candidate-only review artifact. This is not production configuration and not approved package authority.",
    "verification": {
      "checked_date": "2026-06-24",
      "method": "non-authenticated HTTP HEAD/GET probe",
      "final_url": "https://www.cisa.gov/securebydesign",
      "http_status": 200,
      "content_type": "text/html; charset=UTF-8",
      "redirect_count": 0,
      "login_required": false,
      "credentials_in_url": false,
      "private_or_internal_hostname": false,
      "wildcard_domain": false,
      "text_like_content": true
    }
  },
  {
    "id": "cisa-ai-guidance-candidate",
    "title": "CISA Artificial Intelligence",
    "url": "https://www.cisa.gov/ai",
    "allowed_origin": "https://www.cisa.gov",
    "allowed_path_prefix": "/ai",
    "source_type": "government_cybersecurity_guidance",
    "trust_label": "authoritative_public_government_candidate",
    "freshness_label": "periodic_review_required",
    "claim_boundary": "current_public_cybersecurity_guidance_only_not_package_authority",
    "source_owner": "Cybersecurity and Infrastructure Security Agency",
    "proposed_approver": "package_governance_owner_review_required",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "review_cadence": "before_production_enablement_then_periodic",
    "intended_use_cases": [
      "compare package AI governance and data-boundary guidance with public CISA AI cybersecurity guidance",
      "screen AI cybersecurity posture claims after approved package support exists"
    ],
    "non_use_cases": [
      "enterprise AI policy approval",
      "model approval",
      "provider approval",
      "production approval",
      "package authority"
    ],
    "limitations": [
      "Landing-page content may aggregate programs and announcements.",
      "Owner review must verify the exact claim supported before any enablement."
    ],
    "reason_for_inclusion": "Official CISA AI page with a public HTTPS HTML path relevant to AI cybersecurity guidance.",
    "enablement_priority": "5 - government AI cybersecurity guidance",
    "notes": "Candidate-only review artifact. This is not production configuration and not approved package authority.",
    "verification": {
      "checked_date": "2026-06-24",
      "method": "non-authenticated HTTP HEAD/GET probe",
      "final_url": "https://www.cisa.gov/ai",
      "http_status": 200,
      "content_type": "text/html; charset=UTF-8",
      "redirect_count": 0,
      "login_required": false,
      "credentials_in_url": false,
      "private_or_internal_hostname": false,
      "wildcard_domain": false,
      "text_like_content": true
    }
  },
  {
    "id": "google-sre-book-candidate",
    "title": "Google Site Reliability Engineering Book",
    "url": "https://sre.google/sre-book/table-of-contents/",
    "allowed_origin": "https://sre.google",
    "allowed_path_prefix": "/sre-book/table-of-contents/",
    "source_type": "respected_engineering_guidance",
    "trust_label": "respected_engineering_guidance_candidate",
    "freshness_label": "periodic_review_required",
    "claim_boundary": "current_public_engineering_guidance_only_not_package_authority",
    "source_owner": "Google SRE",
    "proposed_approver": "package_governance_owner_review_required",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "review_cadence": "before_production_enablement_then_periodic",
    "intended_use_cases": [
      "compare package operating-model guidance with respected reliability engineering practices",
      "support interpretation of SLO, toil, risk, and operations claims after approved package support exists"
    ],
    "non_use_cases": [
      "vendor endorsement",
      "tool approval",
      "hosting approval",
      "provider or model approval",
      "package authority"
    ],
    "limitations": [
      "Vendor-published engineering material is not neutral standards authority.",
      "It does not approve this repository's tooling, hosting, model, or production practices."
    ],
    "reason_for_inclusion": "Mature and widely respected engineering practice reference with a public HTTPS HTML table-of-contents path.",
    "enablement_priority": "6 - respected engineering practice after higher-authority sources",
    "notes": "Candidate-only review artifact. This is not production configuration and not approved package authority.",
    "verification": {
      "checked_date": "2026-06-24",
      "method": "non-authenticated HTTP HEAD/GET probe",
      "final_url": "https://sre.google/sre-book/table-of-contents/",
      "http_status": 200,
      "content_type": "text/html",
      "redirect_count": 0,
      "login_required": false,
      "credentials_in_url": false,
      "private_or_internal_hostname": false,
      "wildcard_domain": false,
      "text_like_content": true
    }
  }
]
