## Summary Marks the pen-test plan document as **CANCELLED** per Jeppe's instruction 2026-08-16 20:00 UTC. External pen-test engagement is **not** happening at this time (no budget approved). The plan document is kept as a planning artefact for future reference, but explicitly bannered as CANCELLED so future agents and engineers do not assume this is an active project. ## Changes - Added ⛔ CANCELLED banner to the top of `documentation/security/pen-test-plan.md` - Banner includes: status, reason, meaning, owner, and how to re-open in the future - Original content preserved below the banner (296 lines → 304 lines with banner) ## Context - TRU-80 (Linear): remains in **Done** state (planning artefact complete, execution not authorised) - Qodana Cloud: remains active (no workflow changes) - GitHub Dependabot + secret scanning: remain active (free tier) - This PR supersedes PR #385 (which was rolled back because it also removed Qodana by mistake) ## Checklist - [x] No external vendor will be engaged - [x] No workflow changes - [x] No secret removals - [x] Original plan content preserved --------- Co-authored-by: bugfix <bugfix@truckwash.local>
Security documentation
This folder holds security-related planning, post-mortems, and pen-test artefacts for the Truck Wash ApS platform.
| Doc | Purpose | Status |
|---|---|---|
pen-test-plan.md |
TRU-80: scope, methodology, schedule and budget for the next white-hat pen test. | Draft v1, awaiting management sign-off. |
Conventions:
- Pen-test reports and any raw findings live in date-stamped subfolders
(e.g.
2026-q4-pentest/) and are never committed to the public repository — only the planning docs and re-test acceptance letters are. - All security work is tracked under the Linear project UI Library & Pen Testing.