Skip to content

Old vulnerabilities from a Security review go to the private record #552

Description

@JacobStephens2

This was generated by AI during triage.

Parent

#427

What to build

Mode decision (2026-10-09)

Jacob chose guidance for the optional Security review after the #549 trial was graded. Use one session to read the relevant security attack-class guidance and review the change with supporting code; do not run the full six-phase audit or delegate auditors for this review. The separate whole-repository Security audit keeps its full-audit workflow. Existing proof-of-concept, private-record, and Self-merge requirements still apply.

Evidence and limits: trial grading and decision. Guidance was cheaper and faster in this sample; detection accuracy and equivalence between modes remain unmeasured. Detailed grades remain private.

The Security review may find a vulnerability that was already on the Base branch: its proof-of-concept test also fails at the merge base. The session reports it in a file thirdshift names, not in the pull request. thirdshift records it privately, as a Security run would: a draft advisory, or a security-finding issue on a private repository, matched by fingerprint. It stays out of the pull request's body and doesn't hold the merge. With fixing allowed, it's left to a Security run to fix.

Acceptance criteria

  • An old vulnerability the review reports becomes a private record, matched by fingerprint, and appears nowhere in the pull request.
  • It doesn't hold the Self-merge.
  • A finding the change introduced still holds it, as in the Ticket for the Security review in a Run.

Activity

  1. JacobStephens2 commented on Oct 9, 2026

    @JacobStephens2
    OwnerAuthor

    This was generated by AI during triage.

    Agent Brief

    Category: enhancement
    Summary: Record pre-existing vulnerabilities reported by a guidance Security review privately.

    Current behavior: Jacob chose guidance after grading #549, resolving this Ticket's mode gate.

    Desired behavior: Use the chosen guidance review's private report file to record a pre-existing vulnerability whose proof-of-concept also fails at the merge base. Reuse the Security run's record rules and fingerprint matching. Keep its details out of the PR body, and do not hold Self-merge solely for that old vulnerability. Introduced findings retain their existing hold.

    Key interfaces: Security review report-file contract; private Security record creation and fingerprint matching; introduced-versus-existing classification and Self-merge result handling.

    Acceptance criteria:

    • All acceptance criteria in the Ticket body are met.
    • Guidance mode supplies the required private-file report contract.
    • A repeated fingerprint updates or reuses the corresponding private record instead of creating a duplicate.
    • Mixed old and introduced findings preserve confidentiality and the introduced-finding hold.

    Out of scope: Publishing advisories or vulnerability details, automatically fixing old findings in the review, and changing the whole-repository audit or chosen review mode.

  2. added
    enhancementNew feature or request
    ready-for-agentFully specified, ready for an AFK agent
    and removed
    needs-triageMaintainer needs to evaluate this issue
    on Oct 9, 2026
  3. JacobStephens2 commented on Oct 9, 2026

    @JacobStephens2
    OwnerAuthor

    Closed by #594, merged into issue-427 by a thirdshift Merge run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions