Repository navigation
Skip Security audits for waiting findings and unchanged Base branches - #568
Merged
Merged
Conversation
Preserve Security Harness selection and Codex session settings alongside the audit skip gates in the README.
Preserve the Security skip gates and per-Base audit history alongside private-metadata Run notifications. Keep both branches regression tests and move the Base branch before the failed-send test starts its second audit.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security runs check these gates before starting an audit:
Public draft advisories without severity and private open findings with
needs-triagewait for the Day shift. Completed audits are read per Base branch from the skill's existing run record. Skips keep no Command log and send no Run notification.Closes #541
Testing seams
Evidence
After: both pass, with triage release and origin movement covered.
bash /tmp/thirdshift-541-spec-p1.sh, failed: auditingmain, thenstable, then unchangedmainstarted 3 sessions instead of 2.After: the retained
cargo test --test security_run unchanged_base_is_remembered_separately_for_each_branch -- --exact --nocapturepasses; history now identifies its Base branch insidesource_ref.cargo fmt --check,cargo check,cargo clippy --all-targets -- -D warnings, and fullcargo testpassed (1533 tests passed; 1 ignored).Unaddressed findings
Standards
None. S1's duplicated skip assertions were extracted into a shared helper; the reviewer confirmed it resolved.
Spec
None. P1 was reproduced, fixed, and retained as a regression test; the reviewer confirmed it resolved.
Review coverage: Standards and Spec each read every changed file. No changed files were left unread by either axis. Both reports include the combined initial and follow-up files-read lists.
Merge Danger
Door: two-way
Code and existing audit metadata only; no separate state file or migration.
Blast Radius: Security
Controls when Security audits start. Ready issues and findings waiting for the Day shift take precedence over the unchanged-Base gate.
Built with codex · gpt-6.1-sol · xhigh