You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Fixing a reproduced finding with a single Ticket #543
Fixing is off by default, and allowed the way a Base fix is: by security-fix on the command, or by fix under [security] in the User config. no-security-fix forbids it. Both words are accepted on every command that starts Runs, and passed on to the Runs it starts.
With fixing allowed, each Security run first takes the most severe reproduced finding not yet fixed, ties in record order, before it would audit:
A fix-publishing session, shaped like the Architecture review's publishing step, reads the private record. It publishes a terse Ticket, labelled needs-triage, that says only what the fix changes and links the record. It names that Ticket on its final line.
thirdshift checks the Ticket, swaps needs-triage for ready-for-agent, and adds security-fix, creating that label when missing.
thirdshift dispatches a Run on the Ticket, as thirdshift <issue URL> would, and it's a Merge run when the settings ask for one.
The Security run ends as that Run ends.
After an audit in which a finding was reproduced and fixing is allowed, the Security run goes on to that finding's fix.
A reproduced finding waits for the Day shift only while fixing isn't allowed: until its record is closed or published, or it's fixed. For now, the fix is always a single Ticket.
Acceptance criteria
Without security-fix or the setting, nothing is fixed, and reproduced findings wait.
With either, a Security run fixes the most severe reproduced finding first, before auditing, and one fix at most per run.
The published Ticket says what the fix changes, links the private record, and carries none of the write-up. thirdshift marks it ready and labels it security-fix.
The Run on it is dispatched, and the Security run's outcome is that Run's outcome.
no-security-fix on a command overrides the setting.
The words are accepted on Run, Spec run, Architect run, Pickup run and Security run commands, and passed on to the Runs those commands start.
Parent
#427
What to build
Fixing is off by default, and allowed the way a Base fix is: by
security-fixon the command, or byfixunder[security]in the User config.no-security-fixforbids it. Both words are accepted on every command that starts Runs, and passed on to the Runs it starts.With fixing allowed, each Security run first takes the most severe reproduced finding not yet fixed, ties in record order, before it would audit:
needs-triage, that says only what the fix changes and links the record. It names that Ticket on its final line.needs-triageforready-for-agent, and addssecurity-fix, creating that label when missing.thirdshift <issue URL>would, and it's a Merge run when the settings ask for one.After an audit in which a finding was reproduced and fixing is allowed, the Security run goes on to that finding's fix.
A reproduced finding waits for the Day shift only while fixing isn't allowed: until its record is closed or published, or it's fixed. For now, the fix is always a single Ticket.
Acceptance criteria
security-fixor the setting, nothing is fixed, and reproduced findings wait.security-fix.no-security-fixon a command overrides the setting.