Repository navigation
Support larger Security fixes and reuse private finding issues - #581
Merged
Merged
Conversation
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Honor the reproduction's fix-size decision and use a private finding's own issue for its fix.
Every new issue links the private record; publication checks every issue before dispatch. Private finding evidence stays in its original issue. The Security run inherits the dispatched Run or Spec run's ending.
Closes #545
Evidence
Before:
cargo test --test security_run a_bigger_public_fix_publishes_tickets_and_ends_as_the_spec_run -- --exactfailed because the publishing session's Spec final line was rejected. After: passes, with ordered Ticket merges and a ready Spec PR.Before:
cargo test --test security_run a_private_one_session_fix_reuses_the_findings_issue_and_preserves_its_evidence -- --exactfailed because a publishing session was still required. After: passes with one issue, preserved evidence and one implementation session.Before:
cargo test --test security_run a_bigger_private_fix_adds_tickets_to_the_findings_issue -- --exactfailed because the existing finding's issue was rejected as too old. After: passes with native sub-issues and the merged Spec PR.Before: the Spec reviewer's exact generated-page command and the retained
publishing_skills_show_security_fix_publishing_as_a_userregression failed on missing usage metadata. After: both publishing skill cards name Security fix publishing; the same command and retained regression pass.Final checks passed:
cargo fmt --check,cargo clippy --all-targets -- -D warnings, and the fullcargo testsuite.UPDATE_PROMPTS=1 cargo test prompts_pageregenerated the prompts and passed all 10 page tests.Testing Decisions
Seam: the
thirdshift secure security-fixcommand, exercised with real Git and the existing fake GitHub and Harness executables. Observe published issues, readiness, private record preservation, Ticket PRs, Spec PRs and the command's ending. This covers publication through dispatch without mocking internal modules.Seam: the rendered Prompts and skills page, checking the published usage metadata for both fix-publishing skills.
Merge Danger
Door: two-way
Code and prompt changes can be reverted. Issues and Tickets already published by Security runs remain on GitHub.
Blast Radius: Security
Changes fix publication, issue readiness and dispatch for reproduced Security findings when fixing is allowed.
Unaddressed findings
Standards
None. S1 (top-issue naming) and S2 (duplicated dispatch construction) are addressed and verified by the Standards reviewer.
Spec
None. SP1 (missing Security fix publishing in the two skill cards' usage metadata) was reproduced with the reviewer's exact command, fixed, and verified with the same command and a retained rendered-page regression.
Both axes read all 14 changed files, including generated files. Changed files left unread: none.
Built with codex · gpt-6.1-sol · xhigh