Skip to content

Allow Security runs to fix one reproduced finding - #578

Merged
JacobStephens2 merged 5 commits into
issue-427from
issue-543
Oct 8, 2026
Merged

JacobStephens2 merged 5 commits into
issue-427from
issue-543

Conversation

@JacobStephens2

@JacobStephens2 JacobStephens2 commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

Security runs can fix one reproduced finding when the command or User config allows it, and finish with the dispatched Run's outcome.

secure
  security-fix / [security] fix = true (no-security-fix overrides)
  most severe reproduced finding, ties in record order
    before auditing, or after reproduction
  publish one terse Ticket linking the private record
  check Ticket → needs-triage becomes ready-for-agent + security-fix
  record Ticket link privately → dispatch Run (merge when requested)
  finish as that Run finishes

Closes #543

Evidence

  • Before: cargo test --test security_run fixing_selects_the_most_severe_record_then_dispatches_one_ticket_before_auditing -- --exact failed: unexpected argument after secure: security-fix.
    After: passes, selecting the first critical finding and dispatching exactly one Ticket before any audit.
  • Before: the title-disclosure and open-fix waiting regressions failed.
    After: the Ticket title is checked for copied private text; a reproduced finding still waits without fixing permission until its Ticket closes.
  • Before: the reviewers' focused archive commands reproduced duplicate fix dispatch, copied short private proof-of-concept text, stale severity priority, and rejection of valid terse fix prose.
    After: all four behavioral regressions are retained and pass. The original short-statement test also passes after allowing ordinary identifiers.
  • Validation: cargo test passes (1,577 passed, one ignored); cargo fmt --check and cargo clippy --all-targets -- -D warnings pass.
  • Test seams: the end-to-end scenario harness (real binary and git, fake GitHub and Harness CLIs) and the Pass seam's in-memory adapter, as agreed in Security runs and the Security review: thirdshift finds, reproduces and fixes vulnerabilities #427.

Merge Danger

Door: two-way

Reverting restores report-only behavior. Published Tickets and private record links remain on GitHub.

Blast Radius: factory

Adds shared command/config words and carries the resolved choice into dispatched and child Runs. Existing Runs default to fixing disabled.

Unaddressed findings

Standards

None. Both Standards findings are addressed: the private fix link survives later reproduction, and Severity parsing and ordering share the domain type.

Spec

None. All three Spec findings are addressed: short private statements are rejected, current Day-shift severity decides priority, and ordinary bare identifiers do not block valid fix prose.

Review coverage: both axes left src/setup.rs unread. Its sole change adds fix = false to an existing complete-config test fixture; the focused existing Setup test passed. Every other changed file appears in both final files-read lists.

Built with codex · gpt-6.1-sol · xhigh

@JacobStephens2
JacobStephens2 merged commit 1bff3a0 into issue-427 Oct 8, 2026
13 checks passed
@JacobStephens2
JacobStephens2 deleted the issue-543 branch October 8, 2026 17:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant