Repository navigation
Rebalance verdicts: PASS for healthy PRs, QUARANTINE for risk, BLOCK for major signals only - #20
Merged
Merged
Conversation
PASS should be the outcome for healthy code awaiting merge; QUARANTINE should mean genuinely risky changes; BLOCK should be reserved for major signals. Three rules moved to match: - Pending required checks no longer quarantine — they are a review note, so PRs analyzed before CI finishes still pass when nothing else is risky. - Dependency manifests now quarantine only on newly added packages (net of removals, so version bumps and lockfile refreshes pass with a note). - Credential-like values are location-aware: production code blocks, while the same values in tests, fixtures, or docs quarantine for confirmation instead of hard-blocking (diffly's own #17 was blocked by its fake fixture credential). Failed checks and production secrets still block. Policy text in the report and README updated; six new/updated tests cover the matrix.
Diffly verdict: BLOCK#20 · 6 files · 145 lines changed · checks: PENDING Risk flags: Risk flags and reasoning
Blast-radius summary
Deterministic triage is authoritative; any optional LLM explanation cannot change the verdict. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Verdict feedback from dogfooding: healthy pull requests were routinely quarantined or blocked by signals that don't warrant a merge stop. Three rules over-fired:
postgresql://admin:hunter2@…test string.New policy
Net-new dependency detection now subtracts removed packages from added ones (
_dependency_base_namestrips version constraints), sorequests==2.31→2.32passes while addingleft-padstill quarantines.Surface area
src/diffly_cli/triage.py:verdict_for()rebalanced;_removed_dependency_names()added; flag codes/severity/JSON schema unchanged (only verdict routing and reasoning text moved).cli.pyreport policy footer + README "The verdict policy" table updated to match.Changedbullets under Unreleased.Validation
tests/→ QUARANTINE; same string in production path → BLOCKQUARANTINEwith the confirm-it's-fake reasoning.demo/intentionally left untouched (captured outputs).