/** * SMI-5879 (design §3.5): required witness fixture SW-1. * * A single realistic fixture, with a fully specified category budget, that * makes the RC-1 verdict swing concrete: the pre-fix "first-match-only" bug * (packages/core/src/security/scanner/SecurityScanner.helpers.ts's * scanPatternsWithMultilineSupport, before commit 82d2ccaa0) finds only the * FIRST occurrence of a 'content'/'both'-scope pattern in the whole document; * the RC-1 fix records every distinct matching line. `baselineScanWithFirstMatchOnly` * below is a frozen, verbatim reconstruction of the exact pre-fix pass-1 loop * (git show 82d2ccaa0^:.../SecurityScanner.helpers.ts) — not a synthetic * approximation — reusing the SAME (unchanged-by-RC-1) evidence * classification/severity/scope functions the real scanner uses today, so the * ONLY behavioral difference under test is the traversal bug itself. * * Category budget (see design §3.5 for the exact numbers): * - privilege_escalation: 2 non-doc critical findings -> saturated at 11.00 * - data_exfiltration: 2 non-doc high findings -> saturated at 8.00 * - suspicious_pattern: 6 non-doc medium findings -> saturated at 7.00 * - jailbreak: 7 non-doc mention findings -> 4.20 (unaffected by the RC-1 * bug: all 4 mention-tier patterns used here are 'line'-scope, so pass 2 — * always per-line, never buggy — finds all 7 both before and after the fix) * - ai_defence (design's "prompt_injection"): 1 non-doc role_turn_with_body * finding (AD_AN2_ROLE_BODY_NEXT_LINE) under the baseline bug -> 6.84; * both occurrences under the fix -> 12.00 * * non-AI subtotal: 11.00 + 8.00 + 7.00 + 4.20 = 30.20 (design's stated value). * baseline total: 30.20 + 6.84 = 37.04 -> round 37 (< 40, clean). * ported total: 30.20 + 12.00 = 42.20 -> round 42 (>= 40, quarantine). */ export {}; //# sourceMappingURL=scanner-witness-sw1.test.d.ts.map