Repository navigation
Report Security reproduction failures separately from completed audits - #604
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Preserve the completed Security audit when a later reproduction fails, and identify the failed reproduction in the Run notification.
Other reproduction failures report their number as
failed; safeguard refusals retain the safe cause and Session log and Command log pointers. Genuine audit failures and successful Security runs retain their existing reporting.Closes #603
Evidence
cargo test --test security_run refused_security_reproductions_keep_the_record_and_stop_before_the_next_finding -- --exactfailed on the originalaudit failedsubject.After: The same regression passes for Claude Code and Codex, on public and private repositories, with fixing allowed: all private records survive, no next reproduction or fix starts, and private diagnostics stay out of the notification.
cargo test: 1662 passed, 0 failed, 1 ignored across 41 test binaries.cargo test --test security_run: 83 passed.cargo check --all-targets,cargo clippy --all-targets -- -D warnings, andcargo fmt --check: passed.Test seams
The existing Security run scenario harness: command exit status and progress, captured Run notifications, and private records exposed by the GitHub stand-in. Fake Harness CLIs and Resend are external adapters.
Review
Standards: 0 findings. Spec: 0 findings. Both reviewers read all four changed files; no changed files were left unread.
Security: 0 introduced findings. Guidance-mode review covered
7f13fc162a1b1ad47c5fe862ddb01cb1f36b3617...7d3b03865d4d87e28253337e0c9cc5d9f97b2bc1, all four changed files and supporting failure, reproduction, private-record and notification code. Relevant attack-class guidance and ADR 0015 were read. Sandboxed offline validation passed: 83 Security run tests and 47 unit tests acrossnotification,run_endingandsecurity.Unaddressed findings
Security review outcome
No unaddressed introduced findings.
Merge Danger
Door: two-way
Reporting changes only; no migration or changes to reproduction or fix dispatch rules.
Blast Radius: notifications
Built with codex · gpt-6.1-sol · high