fix(#44): harden vouch enforcement - #1377
Conversation
Functional tests are runningAuthorization passed for this commit. See the Functional Tests workflow for results. |
PR Summary by QodoHarden Vouch enforcement against database read failures
AI Description
Diagram
High-Level Assessment
Files changed (3)
|
Code Review by Qodo
1.
|
d70422d to
542ad1b
Compare
|
/fs-review |
|
🤖 Finished Review · ✅ Success · Started 10:02 PM UTC · Completed 10:16 PM UTC Commit: Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $2.23 |
ReviewFindingsMedium
Low
Previous runReviewFindingsMedium
Low
|
542ad1b to
ff5eeea
Compare
944ed90 to
4b03b7c
Compare
|
Current script tests are failing due to this: #1165 issue |
Signed-off-by: Jay Flowers <jay.flowers@gmail.com>
…pand vouch-check tests Neutralize the raw console.log sink via core.warning, drop redundant percent-encoding that double-encoded API error text under core.setFailed, and add collaborator-error and comment-error regression scenarios to vouch-check-test.sh. Signed-off-by: Jay Flowers <jay.flowers@gmail.com>
4b03b7c to
6df6b85
Compare
|
/ok-to-test |
|
/fs-review |
|
🤖 Finished Review · ✅ Success · Started 11:00 PM UTC · Completed 11:15 PM UTC Commit: Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $2.94 |
|
Risk Assessment: moderate (2/5) DetailsTier 1 is pulled up by 3 protected .github/ paths and a direct CI workflow change but offset by zero security-sensitive files, no dependency changes, and a non-first-time non-bot author; Tier 2 shows low-to-moderate churn/authorship aside from the frequently-changed Makefile; Tier 3 is low given the PR is scope-proportionate to issue #44s 4 enumerated bugs with no unresolved discussion; the weighted composite rounds to a moderate risk score of 2. |
|
🤖 Finished Retro · ✅ Success · Started 12:28 PM UTC · Completed 12:36 PM UTC Commit: Runtime: claude · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $1.02 |
|
PR #1377 (fullsend-ai/agents) fixed the 4 bugs enumerated in issue #44 (itself filed by a prior retro on PR #32) and merged cleanly after human approval. The main finding: the fullsend-ai-review agent's first pass (run 35399513333, reviewing commit 542ad1b, a 10-line diff touching Proposals filed |
Summary
Fix the four remaining defects from #44: invalid review severity guidance, insufficient Vouch Check comment permission, unsafe Vouch DB error handling, and an unnecessary stale-workflow permission.
Changes
important-severityterm withhigh-severity.issues: writeso it can post its explanatory closure comment.actions: writepermission from the stale workflow.Testing
uvx pre-commit run --all-filesmake lintmake check-bundleValidation notes
make script-testreaches the existingharness-jira-test.shassertion failure even though the expected Jira variables are present inharness/triage.yaml; this PR does not modify that test or harness.core.setFailed()and returns before the PR-close API call.Closes #44