Repository navigation
Reproduce recorded Security findings - #566
Merged
Merged
Conversation
JacobStephens2
marked this pull request as ready for review
October 8, 2026 11:31
The base branch added a required session Purpose, but reproduction still called the old two-argument API. This caused E0061 in both CI test jobs and both release builds. Pass Purpose::Security and extend the Codex integration scenario to cover reproduction and its Resume with the Security launch policy. Validated with cargo fmt --check, cargo clippy --all-targets -- -D warnings, cargo test, cargo nextest run (1541 passed), and the Linux musl dist artifact build plus its version command.
Preserve private Security notifications alongside sequential finding reproduction. Retain safe record metadata through failures, report successfully stored reproduction severity, and preserve Day shift triage and private evidence. Keep both branches' Security tests and cover notifications for completed and failed reproductions in advisory and private-issue storage. Validated with cargo check --locked --all-targets, cargo clippy --locked --all-targets -- -D warnings, cargo fmt --check, and the full cargo test --locked suite (1554 passed, 1 ignored).
Preserve the waiting-finding and unchanged-Base audit gates from #541 alongside #542's sequential reproduction sessions and post-audit record refresh. Retain both branches' tests and adapt reproduction fixtures and repeat audits to the new gates. Validation: cargo check --all-targets; cargo clippy --all-targets -- -D warnings; cargo test --quiet (1,562 passed, 1 ignored); cargo fmt --check.
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Incomplete sessions leave the finding unchanged. The prompt asks for harmless local tests against untouched code, the skill's severity rubric and the fix size. Factory skills are linked into each Worktree; progress names each reproduction and outcome. A record edited or triaged during reproduction is preserved.
Closes #542
Evidence
CI repair — Before: the base merge added a required
session::Purpose, while reproduction still called the old two-argument API. All four reported jobs failed with E0061.After: reproduction selects
Purpose::Security; the Codex integration scenario now checks the audit, reproduction and both Resumes retain the Security launch policy.cargo fmt --check,cargo clippy --all-targets -- -D warnings, fullcargo test, fullcargo nextest run(1,541 passed), anddist build --print=linkage --output-format=json --artifacts=local --target=x86_64-unknown-linux-muslpass locally. The static musl binary also passesthirdshift version. Native macOS validation runs in CI.Before:
cargo test --test security_run a_reproduction_scores_the_finding_and_keeps_its_test_in_the_private_record -- --exactfailed: severity wasnullinstead ofhigh, with no reproduction session.After: passes; the record carries severity, notes, fix size and test text.
Before: each Spec review regression failed at its asserted behavior: an ordinary Markdown heading deleted evidence, a published advisory received fresh test evidence and a replacement grade, and a private issue rejected
informational.After: all three supplied commands pass, and all three tests are retained:
Validation: all 32 Security run scenarios pass;
cargo testpasses;cargo clippy --all-targets -- -D warningsandcargo fmt --checkpass. Generated prompts and the Prompts and skills page were regenerated withUPDATE_PROMPTS=1 cargo test prompts_page(9 tests pass).Seams under test, from #427:
Merge Danger
Door: two-way
Blast Radius: Security
Security runs launch additional sessions and update untriaged private records. Informational findings on public repositories stop with an explicit cause while the Day shift decides how their grade should be represented.
Unaddressed findings
Standards
None. Standards reported 0 findings.
Spec
informational: the private-issue bug is fixed. The remaining call belongs to the Day shift and is tracked in the policy issue. The skill's rubric includes informational, while GitHub's advisory update API accepts critical/high/medium/low/null. Neither the Spec nor an ADR authorizes substituting another grade. The guard preserves the advisory and fails with an explicit cause.cargo test --test security_run an_informational_advisory_requires_a_day_shift_decision_without_an_invented_grade -- --exactpasses and exercises that case.Spec reported 3 findings: S1 and S2 are addressed; S3 is fixed for private issues and its public-advisory policy remains above. Both axes reviewed through
b495ebc, including every changed file. Unread changed files: none on either axis.Built with codex · gpt-6.1-sol · xhigh