Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
85 commits
Select commit Hold shift + click to select a range
dbd59ba
Prefactor shared Pass lock, skip logging and command words (#536)
JacobStephens2 Oct 8, 2026
ab7d48f
Ship Cloudflare security-audit as a Factory skill (#537)
JacobStephens2 Oct 8, 2026
f859ba9
Complete Pass documentation and update help regressions (#536)
JacobStephens2 Oct 8, 2026
2ddf4b7
Merge pull request #553 from JacobStephens2/issue-537
JacobStephens2 Oct 8, 2026
54b14ae
Merge remote-tracking branch 'origin/issue-427' into issue-536
JacobStephens2 Oct 8, 2026
cc7e3be
Merge pull request #555 from JacobStephens2/issue-536
JacobStephens2 Oct 8, 2026
39278ac
docs: measure Security review modes on three merged PRs (#549)
JacobStephens2 Oct 8, 2026
4c148bf
Add report-only Security runs (#538)
JacobStephens2 Oct 8, 2026
419eb4b
Merge remote-tracking branch 'origin/issue-427' into issue-549
JacobStephens2 Oct 8, 2026
9555cd3
Address Security run review findings (#538)
JacobStephens2 Oct 8, 2026
bdeac1e
Merge pull request #557 from JacobStephens2/issue-549
JacobStephens2 Oct 8, 2026
7502119
Merge remote-tracking branch 'origin/issue-427' into issue-538
JacobStephens2 Oct 8, 2026
aef9d7c
Measure stdout-holder stopping before Failed run preservation (#559)
JacobStephens2 Oct 8, 2026
6001dd8
Reuse hook fixture after Standards review
JacobStephens2 Oct 8, 2026
b532e6d
Merge pull request #560 from JacobStephens2/issue-559
JacobStephens2 Oct 8, 2026
6b1394e
Merge remote-tracking branch 'origin/issue-427' into issue-538
JacobStephens2 Oct 8, 2026
91107ff
Preserve tracked threat-model path casing in Security audits
JacobStephens2 Oct 8, 2026
8b77566
Merge pull request #558 from JacobStephens2/issue-538
JacobStephens2 Oct 8, 2026
83b45b8
Record private repository Security findings as labelled issues (#540)
JacobStephens2 Oct 8, 2026
3faea34
Send private-metadata Security run notifications (#539)
JacobStephens2 Oct 8, 2026
28c7259
Choose the Security Harness and adjust Codex security sessions (#546)
JacobStephens2 Oct 8, 2026
d4821f8
Update Architect account fixture for notification metadata
JacobStephens2 Oct 8, 2026
5ce6fcc
Keep Security session purpose independent of log labels
JacobStephens2 Oct 8, 2026
10d405a
Keep Security audit failure details out of Resend
JacobStephens2 Oct 8, 2026
2cc3a8b
Keep the complete Setup fixture current with Security settings
JacobStephens2 Oct 8, 2026
647c45e
Include the Security section in Setup end-to-end expectations
JacobStephens2 Oct 8, 2026
8efe541
Merge pull request #561 from JacobStephens2/issue-540
JacobStephens2 Oct 8, 2026
990e3d6
Skip Security audits for waiting findings and unchanged Base branches…
JacobStephens2 Oct 8, 2026
2a22d00
Merge remote-tracking branch 'origin/issue-427' into issue-546
JacobStephens2 Oct 8, 2026
e6337a4
Reproduce recorded Security findings in isolated sessions (#542)
JacobStephens2 Oct 8, 2026
857985d
Keep completed audit history per Base branch and simplify skip checks
JacobStephens2 Oct 8, 2026
1cc7f10
Merge origin/issue-427 into issue-539
JacobStephens2 Oct 8, 2026
e6f0e5b
Preserve finding evidence and Day shift grades after Spec review (#542)
JacobStephens2 Oct 8, 2026
b495ebc
Route fake GitHub updates by endpoint rather than body URLs (#542)
JacobStephens2 Oct 8, 2026
5a3311c
Merge pull request #563 from JacobStephens2/issue-546
JacobStephens2 Oct 8, 2026
07d4c97
Merge remote-tracking branch 'origin/issue-427' into issue-539
JacobStephens2 Oct 8, 2026
b6f0654
Merge remote-tracking branch 'origin/issue-427' into issue-542
JacobStephens2 Oct 8, 2026
aeea376
Merge origin/issue-427 into issue-541
JacobStephens2 Oct 8, 2026
3be9324
Merge pull request #562 from JacobStephens2/issue-539
JacobStephens2 Oct 8, 2026
b9b14b2
Fix Security reproduction session purpose after base merge
JacobStephens2 Oct 8, 2026
387ccd3
Merge origin/issue-427 into issue-541
JacobStephens2 Oct 8, 2026
40ea0dc
Merge origin/issue-427 into issue-542
JacobStephens2 Oct 8, 2026
36ac228
Merge pull request #568 from JacobStephens2/issue-541
JacobStephens2 Oct 8, 2026
b07ceca
Merge origin/issue-427 into issue-542
JacobStephens2 Oct 8, 2026
f397e26
Merge pull request #566 from JacobStephens2/issue-542
JacobStephens2 Oct 8, 2026
7379928
Fail refused Security sessions and log their answering Models (#547)
JacobStephens2 Oct 8, 2026
a41f804
Allow Security runs to dispatch one reproduced fix (#543)
JacobStephens2 Oct 8, 2026
755371d
Keep config completion assertions aligned with the fixing default
JacobStephens2 Oct 8, 2026
3718f52
Address #547 review: ignore synthetic Models and report all Harnesses
JacobStephens2 Oct 8, 2026
78afbc7
Address Standards and Spec findings with retained regressions
JacobStephens2 Oct 8, 2026
21f81e3
Allow ordinary fix prose and complete the Setup config fixture
JacobStephens2 Oct 8, 2026
b973076
Merge pull request #577 from JacobStephens2/issue-547
JacobStephens2 Oct 8, 2026
5acd5e2
Merge origin/issue-427 into issue-543
JacobStephens2 Oct 8, 2026
1bff3a0
Merge pull request #578 from JacobStephens2/issue-543
JacobStephens2 Oct 8, 2026
4054927
Ask about Security fixing during Setup (#548)
JacobStephens2 Oct 8, 2026
8fb48cb
Implement Spec-sized Security fixes and reuse private finding issues …
JacobStephens2 Oct 8, 2026
f0288d8
Regenerate Security fix publishing prompts (#545)
JacobStephens2 Oct 8, 2026
41332f1
Pause Security runs after failed fixes and offer fixing (#544)
JacobStephens2 Oct 8, 2026
35ea4f5
Address Standards and Spec review findings for #545
JacobStephens2 Oct 8, 2026
928bb0f
Keep failed fixes paused through GitHub errors and address review fin…
JacobStephens2 Oct 8, 2026
223634e
Document the Security-fix exception to Claim release consistently
JacobStephens2 Oct 8, 2026
46c6ebf
Share the reviewer regression scenario while retaining both tests
JacobStephens2 Oct 8, 2026
dc7b847
Update help contract for Security-fix Pickup exclusion
JacobStephens2 Oct 8, 2026
1f8cfe4
Merge pull request #580 from JacobStephens2/issue-548
JacobStephens2 Oct 8, 2026
405590f
Merge remote-tracking branch 'origin/issue-427' into issue-545
JacobStephens2 Oct 8, 2026
9486dde
Merge remote-tracking branch 'origin/issue-427' into issue-544
JacobStephens2 Oct 8, 2026
4b1cfe8
Merge pull request #581 from JacobStephens2/issue-545
JacobStephens2 Oct 8, 2026
eee47d5
thirdshift: failed run (codex exited 1: Selected model is at capacity…
JacobStephens2 Oct 8, 2026
3ffe3f6
Record completed Security review trial grading
JacobStephens2 Oct 9, 2026
f54c014
Record guidance as the chosen Security review mode
JacobStephens2 Oct 9, 2026
674a642
Merge remote-tracking branch 'origin/issue-427' into issue-544
JacobStephens2 Oct 9, 2026
e8453f7
Merge pull request #582 from JacobStephens2/issue-544
JacobStephens2 Oct 9, 2026
a8d1190
Implement opt-in guidance Security reviews for Runs (#550)
JacobStephens2 Oct 9, 2026
4ca2719
Address Standards and Spec review findings for #550
JacobStephens2 Oct 9, 2026
8e54d91
Update remaining Harness Setup fixtures for Security review
JacobStephens2 Oct 9, 2026
422d954
Merge pull request #592 from JacobStephens2/issue-550
JacobStephens2 Oct 9, 2026
249899e
Record old Security review findings privately (#552)
JacobStephens2 Oct 9, 2026
e07a2ee
Run one guidance Security review on Spec PRs (#551)
JacobStephens2 Oct 9, 2026
ec0eef2
Address Standards and Spec findings for #552
JacobStephens2 Oct 9, 2026
1319bbc
Pin Security review to the full remote ref (#552)
JacobStephens2 Oct 9, 2026
a49d39d
Merge pull request #593 from JacobStephens2/issue-551
JacobStephens2 Oct 9, 2026
aa37f13
Merge remote-tracking branch 'origin/issue-427' into issue-552
JacobStephens2 Oct 9, 2026
58bb0de
Merge pull request #594 from JacobStephens2/issue-552
JacobStephens2 Oct 9, 2026
9942840
Fix integrated Security review behavior (#427)
JacobStephens2 Oct 9, 2026
5456670
Merge origin/main into issue-427
JacobStephens2 Oct 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions CONTEXT.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ The message thirdshift starts or resumes an agent session with. It carries the *
_Avoid_: instructions, system prompt

**Harness**:
The headless agent CLI that runs every agent session of a **Command**, named as its CLI is: Claude Code (`claude`), Codex (`codex`), Antigravity CLI (`agy`), Grok Build (`grok`), Muse Code (`muse`) or OpenCode (`opencode`). One per Command, its child Runs and every **Resume** and **Repair** included. Chosen by the command, else the **User config**, else Claude Code.
The headless agent CLI that runs every agent session of a **Command**, named as its CLI is: Claude Code (`claude`), Codex (`codex`), Antigravity CLI (`agy`), Grok Build (`grok`), Muse Code (`muse`) or OpenCode (`opencode`). One per Command, its child Runs and every **Resume** and **Repair** included. Chosen by the command, else, for a **Security run**, the User config's `security.harness`, else the **User config**'s default Harness, else Claude Code.
_Avoid_: agent, provider, backend

**Model**:
Expand Down Expand Up @@ -69,7 +69,7 @@ One invocation of the factory on a single issue that is not a **Spec**, from lau
A factory-owned checkout, on an **Issue branch** for a **Run** or detached for an **Architecture review**. Acquisition accounts for partial local effects: failed-acquisition recovery rechecks clean-only, instance-specific authority before and after every destructive attempt, including retries, advances only on verified transitions, and retains and names remaining work or uncertain partial effects. Failed-acquisition retention survives later Architecture review attempts. Successful acquisition carries checkout and registration identity through its lifetime; ordinary synchronization, observations and Failed run preservation share acquired-instance checks before and after every Git subprocess attempt, including retries, acting only on that acquired checkout and selected Issue branch and refusing changed or uncertain ownership. Failed run preservation retains work when ownership has changed or is uncertain and finishes after Command interruption without clearing it; ordinary synchronization remains interruptible. Confirmed Self-merge branch deletion uses the captured Launch repository independently of checkout validity. Cleanup checks stage-specific disposal authority before and after every destructive Git attempt, including retries: acquired identity and the captured cleanup head for checkout removal, removed-path absence and an unused expected head for local branch removal, then ref absence and the exact original local subsection for branch configuration removal. Only successful, verified transitions advance disposal; partial failures retain and name every remaining or uncertain resource. Live cleanup finishes after Command interruption without clearing it; stale disposal stays interruptible. Stale Architecture review scratch is disposable only with evidence of successful detached acquisition and unchanged ownership; unmarked or uncertain checkouts are retained.

**Claim**:
The mark that the factory has taken an issue: thirdshift labels the issue `in-progress`, in place of `ready-for-agent` if it has that, when a **Run** or a **Spec run** starts on it, whether started on its **Issue URL** or by an **Architect run**, a **Pickup run** or a **Security run**. A **Ticket**'s Run in a Spec run and a **Base fix** make none. Ending a Claim finishes even after Command interruption. A Claim is released, `ready-for-agent` put back, only when the Run ends with nothing on `origin` to take over: no **Issue branch** and no pull request. Otherwise it stays while the issue is open, whether its pull request is ready for review or the Run failed, until the **Day shift** relabels it, and thirdshift takes the label off once the issue is closed.
The mark that the factory has taken an issue: thirdshift labels the issue `in-progress`, in place of `ready-for-agent` if it has that, when a **Run** or a **Spec run** starts on it, whether started on its **Issue URL** or by an **Architect run**, a **Pickup run** or a **Security run**. A **Ticket**'s Run in a Spec run and a **Base fix** make none. Ending a Claim finishes even after Command interruption. A failed Security fix keeps its Claim even with nothing on `origin`, so it stays with the Day shift. For other Runs, a Claim is released, `ready-for-agent` put back, only when the Run ends with nothing on `origin` to take over: no **Issue branch** and no pull request. Otherwise it stays while the issue is open, whether its pull request is ready for review or the Run failed, until the **Day shift** relabels it, and thirdshift takes the label off once the issue is closed.
_Avoid_: lock (a lock is per machine and ends with its process), assignment

**Spec run**:
Expand Down Expand Up @@ -109,7 +109,7 @@ A **Pickup run**'s removal of `in-progress` from every closed issue in the repos
_Avoid_: cleanup, garbage collection

**Ready issue**:
An open issue a **Pickup run** may take: labelled `ready-for-agent`, with no label that makes an **Unready Ticket** and no **Claim**, not a sub-issue, not a **Base fix**'s issue, with no open blocker, never started (no **Issue branch** and no pull request), not a **Spec** whose **Tickets** are all closed, and left untouched long enough that whoever is shaping it has finished. On a Spec, the label says its Tickets are published. A `ready-for-agent` Ticket inside a Spec is not one: it is reached through its Spec, when the Spec is itself a Ready issue.
An open issue a **Pickup run** may take: labelled `ready-for-agent`, with no label that makes an **Unready Ticket** and no **Claim**, not a sub-issue, not a **Base fix**'s or a **Security run**'s fix issue, with no open blocker, never started (no **Issue branch** and no pull request), not a **Spec** whose **Tickets** are all closed, and left untouched long enough that whoever is shaping it has finished. On a Spec, the label says its Tickets are published. A `ready-for-agent` Ticket inside a Spec is not one: it is reached through its Spec, when the Spec is itself a Ready issue.
_Avoid_: queued issue, backlog item

**Architecture review**:
Expand Down Expand Up @@ -156,7 +156,7 @@ A **Run** asked to end with its pull request merged rather than left for review,
_Avoid_: auto-merge (GitHub's own feature, which thirdshift does not use)

**Run notification**:
A message thirdshift sends when a **Run**, a **Spec run**, an **Architect run** or a **Security run** ends, whatever its outcome (ready, merged, failed or interrupted; for an Architect run that dispatched nothing, plan published, idea filed, idea already filed or review failed), to the address given with the email flag or the default in the **User config**. Each sends one only when asked to, by the flag or by the User config; a Spec run's notification lists each **Ticket**'s outcome, and a Ticket's **Run** never sends one of its own. After an **Inherited failure** it carries, beside the cause, what the Run says on stderr: where the checks fail on the **Base branch**, and the offer of a **Base fix** if nobody decided against one. An Architect run's notification tells how its **Architecture review** ended, naming the plan or idea issue, and how the Spec run or Run it dispatched ended, which sends none of its own; a skipped one sends none. A **Pickup run** that took a **Ready issue** sends the one the Spec run or Run it dispatched would have sent, which sends none of its own; a skipped one sends none. A **Security run**'s notification lists each **Security finding**'s severity, title and private link, never its write-up, since the message passes through a third party; a skipped one sends none. Failing to send one never changes the outcome.
A message thirdshift sends when a **Run**, a **Spec run**, an **Architect run** or a **Security run** ends, whatever its outcome (ready, merged, failed or interrupted; for an Architect run that dispatched nothing, plan published, idea filed, idea already filed or review failed), to the address given with the email flag or the default in the **User config**. Each sends one only when asked to, by the flag or by the User config; a Spec run's notification lists each **Ticket**'s outcome, and a Ticket's **Run** never sends one of its own. After an **Inherited failure** it carries, beside the cause, what the Run says on stderr: where the checks fail on the **Base branch**, and the offer of a **Base fix** if nobody decided against one. An Architect run's notification tells how its **Architecture review** ended, naming the plan or idea issue, and how the Spec run or Run it dispatched ended, which sends none of its own; a skipped one sends none. A **Pickup run** that took a **Ready issue** sends the one the Spec run or Run it dispatched would have sent, which sends none of its own; a skipped one sends none. A **Security run**'s notification lists each **Security finding**'s severity, title and private link, never its write-up, since the message passes through a third party. When a Run leaves a reproduced finding unfixed and nobody decided against fixing, it offers both the command and the User config setting that allow fixing; a skipped one sends none. Failing to send one never changes the outcome.
_Avoid_: completion email, alert

**User config**:
Expand Down
Loading
Loading