Skip to content

Fixing a reproduced finding with a single Ticket #543

Description

@JacobStephens2

Parent

#427

What to build

Fixing is off by default, and allowed the way a Base fix is: by security-fix on the command, or by fix under [security] in the User config. no-security-fix forbids it. Both words are accepted on every command that starts Runs, and passed on to the Runs it starts.

With fixing allowed, each Security run first takes the most severe reproduced finding not yet fixed, ties in record order, before it would audit:

  1. A fix-publishing session, shaped like the Architecture review's publishing step, reads the private record. It publishes a terse Ticket, labelled needs-triage, that says only what the fix changes and links the record. It names that Ticket on its final line.
  2. thirdshift checks the Ticket, swaps needs-triage for ready-for-agent, and adds security-fix, creating that label when missing.
  3. thirdshift dispatches a Run on the Ticket, as thirdshift <issue URL> would, and it's a Merge run when the settings ask for one.
  4. The Security run ends as that Run ends.

After an audit in which a finding was reproduced and fixing is allowed, the Security run goes on to that finding's fix.

A reproduced finding waits for the Day shift only while fixing isn't allowed: until its record is closed or published, or it's fixed. For now, the fix is always a single Ticket.

Acceptance criteria

  • Without security-fix or the setting, nothing is fixed, and reproduced findings wait.
  • With either, a Security run fixes the most severe reproduced finding first, before auditing, and one fix at most per run.
  • The published Ticket says what the fix changes, links the private record, and carries none of the write-up. thirdshift marks it ready and labels it security-fix.
  • The Run on it is dispatched, and the Security run's outcome is that Run's outcome.
  • no-security-fix on a command overrides the setting.
  • The words are accepted on Run, Spec run, Architect run, Pickup run and Security run commands, and passed on to the Runs those commands start.

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions