Skip to content

The Security review on a Spec PR #551

Description

@JacobStephens2

This was generated by AI during triage.

Parent

#427

What to build

Mode decision (2026-10-09)

Jacob chose guidance for the optional Security review after the #549 trial was graded. Use one session to read the relevant security attack-class guidance and review the change with supporting code; do not run the full six-phase audit or delegate auditors for this review. The separate whole-repository Security audit keeps its full-audit workflow. Existing proof-of-concept, private-record, and Self-merge requirements still apply.

Evidence and limits: trial grading and decision. Guidance was cheaper and faster in this sample; detection accuracy and equivalence between modes remain unmeasured. Detailed grades remain private.

When the Security review is on, a Spec run runs it once on its Spec PR, after the Spec review and before the push and the Repair loop, over the whole Spec branch. A Ticket's Run never runs one. Unaddressed findings, or a refused review, hold the Spec PR's Self-merge the same way they hold a Run's.

Acceptance criteria

  • With the review on, a Spec run runs one Security review, after its Spec review, and its Tickets' Runs run none.
  • An unaddressed introduced finding, or a refused review, keeps the Spec PR from being merged, leaves it ready for review, and the cause says why.

Activity

  1. JacobStephens2 commented on Oct 9, 2026

    @JacobStephens2
    OwnerAuthor

    This was generated by AI during triage.

    Agent Brief

    Category: enhancement
    Summary: Apply the chosen guidance Security review once to the whole Spec branch.

    Current behavior: Jacob chose guidance after grading #549, resolving this Ticket's mode gate.

    Desired behavior: With the review enabled, run one guidance session on the Spec PR after the Spec review and before pushing and the Repair loop. Scope it to the whole Spec branch against its Base branch. Ticket Runs receive no Security review. Apply the same introduced-finding, refusal, and incomplete-review Self-merge hold as a Run.

    Key interfaces: Spec review-to-Delivery ordering; Security review enablement and result handling; Ticket Run dispatch.

    Acceptance criteria:

    • All acceptance criteria in the Ticket body are met.
    • The Spec PR gets exactly one review in guidance mode; Ticket Runs get none.
    • The prompt covers the complete Spec change, rather than only the last Ticket.
    • Incomplete or refused reviews cannot permit the Spec PR's Self-merge.

    Out of scope: Separate reviews for each Ticket, changing the whole-repository audit, and choosing a different Security review mode.

  2. added
    enhancementNew feature or request
    ready-for-agentFully specified, ready for an AFK agent
    and removed
    needs-triageMaintainer needs to evaluate this issue
    on Oct 9, 2026
  3. JacobStephens2 commented on Oct 9, 2026

    @JacobStephens2
    OwnerAuthor

    Closed by #593, merged into issue-427 by a thirdshift Merge run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions