Repository navigation
feat(daily): select targets by channel viability, and add an unreachable exit - #149
Merged
Merged
Conversation
Implements the 2026-09-17 coverage-manifest PRP. Scan coverage was an `info`-severity finding buried among hundreds; it is now a first-class report artifact — `reports/coverage.json` plus a `## Scan Coverage` section in `security_report.md`, with an explicit `complete` flag and a banner when the scan is incomplete. ADR-015 records the decision. Written by the 2026-09-18 `/daily` run, which the disclosure guardrail held in status-only and which spent the time on planned work rather than inventing a scan. It was finished and passing but never committed. Split into its own commit rather than riding along in an unrelated change. Verified end to end on a real self-scan: `coverage.json` is written and the `## Scan Coverage` section renders. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…able` exit The pipeline's bottleneck is the delivery step, and it is structural rather than incidental. Measured across the series on 2026-09-18: 14 disclosures went through an autonomous channel (GitHub private vulnerability reporting, or a public issue) and 12 needed a human to send an email or a DM. Every stoppage the project has had came from the human-gated half — the six-report backlog (25 days, 4 scans lost) and claude-tap (33 days, 3 scans lost). The autonomous half has never stopped a run. Two changes: one stops the queue forming, the other stops the residue deadlocking. - **Guardrail 9 / Phase 2**: resolve how a finding would actually reach the maintainer *before* committing to a candidate, tiered on current queue depth. 0-2 pending: any channel. 3+: require an autonomous channel. At any depth: never pick a target with no channel at all (PVR off AND no email anywhere AND a SECURITY.md forbidding public issues) — that exact combination produced the only permanent deadlock in the series. Tiered on purpose, never absolute: PVR-enabled repos skew mature and commercially backed, so a standing preference would bias the series away from the small projects that most need the review. - **Guardrail 8**: `unreachable` is the only way to close an undeliverable report, requiring four proofs in the entry — PVR disabled on two separate days, no email in any of six locations, a public issue forbidden or self-disclosing, and any remaining contact on a platform the operator has *said* they do not use. The detail stays withheld: a High with no fix and no maintainer aware of it serves an attacker before a user. It records a failed delivery, not a licence to disclose. Applied to claude-tap, which met all four: re-keyed to `unreachable_disclosure_*` and the public post now says plainly that the reported channel was unavailable and why. Nothing about the finding was added — zero lines of this diff contain a port, endpoint or mechanism. The manual queue is empty and tomorrow's run is unblocked. Public index, since the outcome vocabulary grew: the claude-tap row reads `undelivered` rather than `private` (which implied a delivery that never happened), a legend documents all eight values in use, and one stray checkmark is normalised to `**fixed**` — the column now totals exactly 24, matching the record. ROADMAP carries both this work and the roadmap line for the coverage manifest that landed the same day. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
elfrost
force-pushed
the
feat/channel-viability-and-unreachable
branch
from
September 18, 2026 13:26
fa994de to
39786b6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The pipeline's bottleneck is the delivery step, and the numbers say it is structural.
Measured 2026-09-18: 14 disclosures went through an autonomous channel, 12 needed a human send. Every stoppage in the project's history came from the human-gated half — the six-report backlog (25 days, 4 scans lost) and claude-tap (33 days, 3 scans lost, blocking right now). The autonomous half has never stopped a run.
Guardrail 9 — channel viability becomes a selection criterion. Resolve delivery before committing to a candidate, tiered on queue depth: 0–2 pending → any channel; 3+ → require an autonomous one; at any depth → never a target with no channel at all. Tiered on purpose: PVR-enabled repos skew mature and commercially backed, so a standing preference would bias the series away from the small projects that most need review.
Guardrail 8 —
unreachable. The only way to close an undeliverable report, requiring four proofs in the entry. Detail stays withheld — it records a failed delivery, not a licence to disclose.Applied to claude-tap (all four criteria met, PVR re-checked on a third day). Verified zero lines of the diff add a port, endpoint or mechanism. Queue is now empty; tomorrow's run is unblocked.
Index housekeeping:
undeliveredreplaces a misleadingprivate, all eight outcome values get a legend, and a stray✅is normalised — the column now totals exactly 24.🤖 Generated with Claude Code