{"category_id":"repository","default_severity":"error","description":"Retired verifier basenames are prohibited everywhere. Other executable-script basenames beginning with verify require objective source, test, script, bin, or component ownership, including at the repository root. Operational placement remains prohibited except for conventional source inside an objectively owned tool or harness.","examples":[{"after":"explicit environment tfvars","before":"iac/scripts/verify-dev-apply-plan.jq","expected_severity":"error","id":"sarj-artifact-no-bespoke-iac-verifiers","language":"text","title":"Bespoke IaC verifier"}],"fix":"Delete the one-off verifier and every invocation. Express the invariant in Terraform, shared policy, or a provider or runtime contract; if executable verification is durable product code, place it in conventional source inside a declared or workspace-backed tool or harness. Relocating, renaming, or translating the same check, including to TypeScript, is not remediation.","kind":"rule","references":[],"rule_id":"repository/artifacts/bespoke-iac-verifiers","rule_version":5,"slug":"bespoke-iac-verifiers","source":{"path":"src/repo_standards/policy_sarj/policy.py","symbol":"repository/artifacts/bespoke-iac-verifiers"},"title":"Do not commit bespoke verifier scripts","topic_id":"artifacts","why":"Repository-specific verifier entrypoints create parallel validation paths that drift from shared policy, owned test suites, and deployment contracts. Durable executable verification belongs in an objectively owned tool or harness."}
