Repository navigation
Old vulnerabilities from a Security review go to the private record #552
Description
Activity
- addedneeds-triageMaintainer needs to evaluate this issueMaintainer needs to evaluate this issue
on Oct 8, 2026 This was generated by AI during triage.
Agent Brief
Category: enhancement
Summary: Record pre-existing vulnerabilities reported by a guidance Security review privately.Current behavior: Jacob chose guidance after grading #549, resolving this Ticket's mode gate.
Desired behavior: Use the chosen guidance review's private report file to record a pre-existing vulnerability whose proof-of-concept also fails at the merge base. Reuse the Security run's record rules and fingerprint matching. Keep its details out of the PR body, and do not hold Self-merge solely for that old vulnerability. Introduced findings retain their existing hold.
Key interfaces: Security review report-file contract; private Security record creation and fingerprint matching; introduced-versus-existing classification and Self-merge result handling.
Acceptance criteria:
- All acceptance criteria in the Ticket body are met.
- Guidance mode supplies the required private-file report contract.
- A repeated fingerprint updates or reuses the corresponding private record instead of creating a duplicate.
- Mixed old and introduced findings preserve confidentiality and the introduced-finding hold.
Out of scope: Publishing advisories or vulnerability details, automatically fixing old findings in the review, and changing the whole-repository audit or chosen review mode.
- addedenhancementNew feature or requestNew feature or requestready-for-agentFully specified, ready for an AFK agentFully specified, ready for an AFK agentand removedneeds-triageMaintainer needs to evaluate this issueMaintainer needs to evaluate this issue
on Oct 9, 2026 Closed by #594, merged into issue-427 by a thirdshift Merge run.
Parent
#427
What to build
Mode decision (2026-10-09)
Jacob chose guidance for the optional Security review after the #549 trial was graded. Use one session to read the relevant security attack-class guidance and review the change with supporting code; do not run the full six-phase audit or delegate auditors for this review. The separate whole-repository Security audit keeps its full-audit workflow. Existing proof-of-concept, private-record, and Self-merge requirements still apply.
Evidence and limits: trial grading and decision. Guidance was cheaper and faster in this sample; detection accuracy and equivalence between modes remain unmeasured. Detailed grades remain private.
The Security review may find a vulnerability that was already on the Base branch: its proof-of-concept test also fails at the merge base. The session reports it in a file thirdshift names, not in the pull request. thirdshift records it privately, as a Security run would: a draft advisory, or a
security-findingissue on a private repository, matched by fingerprint. It stays out of the pull request's body and doesn't hold the merge. With fixing allowed, it's left to a Security run to fix.Acceptance criteria