Skip to content

A failed fix pauses Security runs; the notification offers fixing; Fencing is documented #544

Description

@JacobStephens2

Parent

#427

What to build

A failed fix. A fix whose Run fails keeps its Claim and stays open for the Day shift. No later Security run or Pickup run retries it. Security runs on that repository are skipped while it's open, with an Activity log reason.

The offer. Sometimes a reproduced finding wasn't fixed only because nobody allowed fixing: neither the command nor the User config decided against it. Then the Run notification, and what the run prints, offer both ways to allow it: the command with security-fix, and fix under [security].

The README documents Fencing:

  • a cron line such as thirdshift secure base main harness claude security-fix;
  • that it yields to work a human shaped;
  • that it pauses while a fix has failed, or while a finding waits for triage.

Acceptance criteria

  • After a failed fix, the next Security run is skipped while the fix's issue is open, and no Pickup run takes that issue.
  • Closing the failed fix's issue lets Security runs go on.
  • With fixing not decided either way, a run that left a reproduced finding unfixed offers the command and the setting, in its notification and on stderr. With no-security-fix, or the setting turned off, it offers nothing.
  • The README documents Fencing.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions