Skip to content

Skip Security audits for waiting findings and unchanged Base branches - #568

Merged
JacobStephens2 merged 4 commits into
issue-427from
issue-541
Oct 8, 2026
Merged

JacobStephens2 merged 4 commits into
issue-427from
issue-541

Conversation

@JacobStephens2

@JacobStephens2 JacobStephens2 commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

Security runs check these gates before starting an audit:

another Pass running → Ready issue → waiting finding → unchanged Base branch
       any skip → one Activity line when the reason changes
       all clear → audit and record findings privately

Public draft advisories without severity and private open findings with needs-triage wait for the Day shift. Completed audits are read per Base branch from the skill's existing run record. Skips keep no Command log and send no Run notification.

Closes #541

Testing seams

  • Pass seam with its in-memory double: gate order and advisory/issue waiting rules.
  • End-to-end scenario harness: audit history, Activity logs, quiet skips, Command logs, and Run notifications.

Evidence

  • Before: the waiting-finding test failed its skip assertion; the unchanged-Base test started another session. Both failed before implementation.
    After: both pass, with triage release and origin movement covered.
  • Before: the Spec review's exact command, bash /tmp/thirdshift-541-spec-p1.sh, failed: auditing main, then stable, then unchanged main started 3 sessions instead of 2.
    After: the retained cargo test --test security_run unchanged_base_is_remembered_separately_for_each_branch -- --exact --nocapture passes; history now identifies its Base branch inside source_ref.
  • Validation: cargo fmt --check, cargo check, cargo clippy --all-targets -- -D warnings, and full cargo test passed (1533 tests passed; 1 ignored).

Unaddressed findings

Standards

None. S1's duplicated skip assertions were extracted into a shared helper; the reviewer confirmed it resolved.

Spec

None. P1 was reproduced, fixed, and retained as a regression test; the reviewer confirmed it resolved.

Review coverage: Standards and Spec each read every changed file. No changed files were left unread by either axis. Both reports include the combined initial and follow-up files-read lists.

Merge Danger

Door: two-way

Code and existing audit metadata only; no separate state file or migration.

Blast Radius: Security

Controls when Security audits start. Ready issues and findings waiting for the Day shift take precedence over the unchanged-Base gate.

Built with codex · gpt-6.1-sol · xhigh

Preserve Security Harness selection and Codex session settings alongside the audit skip gates in the README.
Preserve the Security skip gates and per-Base audit history alongside private-metadata Run notifications. Keep both branches regression tests and move the Base branch before the failed-send test starts its second audit.
@JacobStephens2
JacobStephens2 merged commit 36ac228 into issue-427 Oct 8, 2026
13 checks passed
@JacobStephens2
JacobStephens2 deleted the issue-541 branch October 8, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant