Skip to content

Support larger Security fixes and reuse private finding issues - #581

Merged
JacobStephens2 merged 4 commits into
issue-427from
issue-545
Oct 8, 2026
Merged

JacobStephens2 merged 4 commits into
issue-427from
issue-545

Conversation

@JacobStephens2

@JacobStephens2 JacobStephens2 commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

Honor the reproduction's fix-size decision and use a private finding's own issue for its fix.

reproduced finding
  public + single → new terse Ticket → Run
  public + spec   → new terse Spec + Tickets → Spec run
  private + single → finding's issue → Run
  private + spec   → Tickets beneath finding's issue → Spec run

Every new issue links the private record; publication checks every issue before dispatch. Private finding evidence stays in its original issue. The Security run inherits the dispatched Run or Spec run's ending.

Closes #545

Evidence

  • Before: cargo test --test security_run a_bigger_public_fix_publishes_tickets_and_ends_as_the_spec_run -- --exact failed because the publishing session's Spec final line was rejected. After: passes, with ordered Ticket merges and a ready Spec PR.

  • Before: cargo test --test security_run a_private_one_session_fix_reuses_the_findings_issue_and_preserves_its_evidence -- --exact failed because a publishing session was still required. After: passes with one issue, preserved evidence and one implementation session.

  • Before: cargo test --test security_run a_bigger_private_fix_adds_tickets_to_the_findings_issue -- --exact failed because the existing finding's issue was rejected as too old. After: passes with native sub-issues and the merged Spec PR.

  • Before: the Spec reviewer's exact generated-page command and the retained publishing_skills_show_security_fix_publishing_as_a_user regression failed on missing usage metadata. After: both publishing skill cards name Security fix publishing; the same command and retained regression pass.

  • Final checks passed: cargo fmt --check, cargo clippy --all-targets -- -D warnings, and the full cargo test suite. UPDATE_PROMPTS=1 cargo test prompts_page regenerated the prompts and passed all 10 page tests.

Testing Decisions

Seam: the thirdshift secure security-fix command, exercised with real Git and the existing fake GitHub and Harness executables. Observe published issues, readiness, private record preservation, Ticket PRs, Spec PRs and the command's ending. This covers publication through dispatch without mocking internal modules.

Seam: the rendered Prompts and skills page, checking the published usage metadata for both fix-publishing skills.

Merge Danger

Door: two-way

Code and prompt changes can be reverted. Issues and Tickets already published by Security runs remain on GitHub.

Blast Radius: Security

Changes fix publication, issue readiness and dispatch for reproduced Security findings when fixing is allowed.

Unaddressed findings

Standards

None. S1 (top-issue naming) and S2 (duplicated dispatch construction) are addressed and verified by the Standards reviewer.

Spec

None. SP1 (missing Security fix publishing in the two skill cards' usage metadata) was reproduced with the reviewer's exact command, fixed, and verified with the same command and a retained rendered-page regression.

Both axes read all 14 changed files, including generated files. Changed files left unread: none.

Built with codex · gpt-6.1-sol · xhigh

@JacobStephens2
JacobStephens2 merged commit 4b1cfe8 into issue-427 Oct 8, 2026
13 checks passed
@JacobStephens2
JacobStephens2 deleted the issue-545 branch October 8, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant