Repository navigation
Add opt-in guidance Security reviews to Runs - #592
Merged
Merged
Conversation
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Run an opt-in guidance Security review after implementation and before Delivery pushes or enters the Repair loop. Unresolved introduced findings and incomplete or refused reviews hold Self-merge and leave the PR ready for the Day shift.
Closes #550
Spec PR review and private recording of old findings remain scoped to #551 and #552. Whole-repository Security audits retain their full audit workflow.
Evidence
security_review_words_are_accepted_on_commands_that_start_runsfailed becausesecurity-reviewwas rejected.After: the same test passes; command/config precedence, Setup persistence and Base fix propagation pass through the executable.
enabled_review_fixes_reach_origin_before_delivery_finishesfailed because the review never ran.After: the review's committed fix reaches origin.
an_unaddressed_introduced_finding_holds_self_merge_with_the_pr_readyobserved an unwanted merge, anda_security_session_cannot_claim_completion_with_killed_workaccepted an unfinished review.After: both regressions pass; refusals, malformed final lines and unfinished work hold Self-merge.
cargo test --test security_review review_regression_ -- --nocapture, failed all three supplied regressions: a held Merge run skipped CI repair, a summary-write error discarded the refusal and drafted its PR, and Continuation retained an obsolete finding.After: the same command passes all three retained regressions. Held Merge runs finish readiness work, summary-write errors preserve the Security cause and ready state, and Continuation replaces the factory's marked outcome.
Validation: the full
cargo test --no-fail-fastsuite passes (one existing ignored test).cargo check --tests,cargo clippy --all-targets -- -D warnings,cargo fmt --check, andgit diff --checkpass. Generated prompt checks pass.Test seams
Unaddressed findings
Standards
None. Addressed the review's Data Clumps judgment by passing
security::Optionsthrough Base fix and child-run interfaces. Final review: 0 outstanding findings.Spec
None. Reproduced and fixed all three behavior findings using the reviewers' written tests and exact command; all three regressions are retained. Final review: 0 outstanding findings.
Review coverage: both axes reviewed the initial 34 changed paths against
issue-427fixed atf54c0148560d202ba8ea2ec60b20813206016f23, including all 13 follow-up paths at4ca2719. Full-suite validation then exposed missing default answers to the added Setup question; three fixture answers were added, andcargo test --test muse_sessions --test opencode_sessions setup -- --nocapturepasses all three affected tests. Changed files left unread by both Standards and Spec:tests/muse_sessions.rsandtests/opencode_sessions.rs(these final fixture-only corrections). Full reports and each axis's final files-read list are saved in.thirdshift-review-UktcD0/standards.mdand.thirdshift-review-UktcD0/spec.mdin the implementation workspace.Merge Danger
Door: two-way
No migration or destructive data change; the review is off by default.
Blast Radius: Delivery
Enabled Runs add a Security session, and unresolved or incomplete reviews prevent Self-merge.
Built with codex · gpt-6.1-sol · xhigh