Repository navigation
Run guidance Security review once on Spec PRs - #593
Merged
Merged
Conversation
This was referenced Oct 9, 2026
Merged
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Enable one guidance Security review on the whole Spec branch after Spec review. Ticket Runs get none. Introduced findings, refusals and incomplete reviews hold the Spec PR's Self-merge while leaving it ready for review.
Closes #551
Evidence
cargo test --test spec_run security_review_runs_once_after_spec_review_over_the_whole_spec_branch -- --exactfailed: sessions were[21, 22, 20], missing the expected second Spec session.After: the same test passes; both Tickets, the Spec review commit and the Security fix reach the Base branch after a clean review.
cargo test --test spec_run spec_review_leaves_the_push_to_delivery_after_the_optional_security_review -- --exactfailed because the Spec review prompt instructed the agent to push early.After: the same test passes with Delivery responsible for pushing after Security review.
cargo test --test spec_run(69 passed), fullcargo test(one existing ignored test),cargo check --all-targets,cargo fmt --check,cargo clippy --all-targets -- -D warnings, andUPDATE_PROMPTS=1 cargo test prompts_page.Test seams
thirdshift <Spec Issue URL>CLI, observing Harness sessions, published branch contents, PR readiness and body, Self-merge outcomes, and failure causes through GitHub and Harness stand-ins.Unaddressed findings
Standards
None. Standards review found 0 findings.
Spec
None. Spec review found 0 findings.
Review coverage
Reviewed against
issue-427, pinned at422d954bfad171bca25c2d40e2fde846660becf8. Both axes read all nine changed files; unread changed files: none. Final reports and supporting files-read lists are saved locally in.thirdshift-review-sTHbPs/standards.mdand.thirdshift-review-sTHbPs/spec.md.Merge Danger
Door: two-way
Reverting restores the previous Spec Delivery behavior. No migration or persisted state changes.
Blast Radius: Spec
Spec runs with Security review enabled gain the review and its Self-merge hold. The Spec review session leaves pushing to Delivery.
Built with codex · gpt-6.1-sol · xhigh