The deployed origin answers over https with a Strict-Transport-Security header whose max-age is at least 180 days.
Inputs
One https request to the root of the deployed origin declared by the repository (following at most three same-host redirects), sent through the engine's outbound helper. Configuration and code files of the checkout are scanned for HSTS declarations and explicit disables. Paths listed in excludes (test, spec and tmp files, __tests__, __mocks__, fixtures, test, tests and audit-scripts folders) are never analysed.
Decision rule
Not applicable when the repository declares no deployed origin, the execution context provides no outbound helper, or the origin does not answer; in that case the checkout is still scanned and an explicit HSTS disable (hsts: false, SECURE_HSTS_SECONDS = 0, max-age=0) is a FAIL. With a deployed origin: FAIL when the header is missing or has no readable max-age (HIGH); max-age below 15552000 seconds is MEDIUM (blocks in Extended suites); a missing includeSubDomains is LOW. PASS when the header is present with max-age of at least 15552000.
Type
deterministic
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
const MIN_MAX_AGE_SECONDS = 15_552_000; // 180 days