Skip to content

feat(daily): select targets by channel viability, and add an unreachable exit - #149

Merged
elfrost merged 2 commits into
mainfrom
feat/channel-viability-and-unreachable
Sep 18, 2026
Merged

elfrost merged 2 commits into
mainfrom
feat/channel-viability-and-unreachable

Conversation

@elfrost

@elfrost elfrost commented Sep 18, 2026

Copy link
Copy Markdown
Owner

The pipeline's bottleneck is the delivery step, and the numbers say it is structural.

Measured 2026-09-18: 14 disclosures went through an autonomous channel, 12 needed a human send. Every stoppage in the project's history came from the human-gated half — the six-report backlog (25 days, 4 scans lost) and claude-tap (33 days, 3 scans lost, blocking right now). The autonomous half has never stopped a run.

Guardrail 9 — channel viability becomes a selection criterion. Resolve delivery before committing to a candidate, tiered on queue depth: 0–2 pending → any channel; 3+ → require an autonomous one; at any depth → never a target with no channel at all. Tiered on purpose: PVR-enabled repos skew mature and commercially backed, so a standing preference would bias the series away from the small projects that most need review.

Guardrail 8 — unreachable. The only way to close an undeliverable report, requiring four proofs in the entry. Detail stays withheld — it records a failed delivery, not a licence to disclose.

Applied to claude-tap (all four criteria met, PVR re-checked on a third day). Verified zero lines of the diff add a port, endpoint or mechanism. Queue is now empty; tomorrow's run is unblocked.

Index housekeeping: undelivered replaces a misleading private, all eight outcome values get a legend, and a stray ✅ is normalised — the column now totals exactly 24.

🤖 Generated with Claude Code

elfrost and others added 2 commits September 18, 2026 09:26
Implements the 2026-09-17 coverage-manifest PRP. Scan coverage was an
`info`-severity finding buried among hundreds; it is now a first-class report
artifact — `reports/coverage.json` plus a `## Scan Coverage` section in
`security_report.md`, with an explicit `complete` flag and a banner when the
scan is incomplete. ADR-015 records the decision.

Written by the 2026-09-18 `/daily` run, which the disclosure guardrail held in
status-only and which spent the time on planned work rather than inventing a
scan. It was finished and passing but never committed. Split into its own
commit rather than riding along in an unrelated change.

Verified end to end on a real self-scan: `coverage.json` is written and the
`## Scan Coverage` section renders.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…able` exit

The pipeline's bottleneck is the delivery step, and it is structural rather than
incidental. Measured across the series on 2026-09-18: 14 disclosures went through
an autonomous channel (GitHub private vulnerability reporting, or a public issue)
and 12 needed a human to send an email or a DM. Every stoppage the project has
had came from the human-gated half — the six-report backlog (25 days, 4 scans
lost) and claude-tap (33 days, 3 scans lost). The autonomous half has never
stopped a run.

Two changes: one stops the queue forming, the other stops the residue deadlocking.

- **Guardrail 9 / Phase 2**: resolve how a finding would actually reach the
  maintainer *before* committing to a candidate, tiered on current queue depth.
  0-2 pending: any channel. 3+: require an autonomous channel. At any depth:
  never pick a target with no channel at all (PVR off AND no email anywhere AND
  a SECURITY.md forbidding public issues) — that exact combination produced the
  only permanent deadlock in the series.
  Tiered on purpose, never absolute: PVR-enabled repos skew mature and
  commercially backed, so a standing preference would bias the series away from
  the small projects that most need the review.

- **Guardrail 8**: `unreachable` is the only way to close an undeliverable
  report, requiring four proofs in the entry — PVR disabled on two separate
  days, no email in any of six locations, a public issue forbidden or
  self-disclosing, and any remaining contact on a platform the operator has
  *said* they do not use. The detail stays withheld: a High with no fix and no
  maintainer aware of it serves an attacker before a user. It records a failed
  delivery, not a licence to disclose.

Applied to claude-tap, which met all four: re-keyed to `unreachable_disclosure_*`
and the public post now says plainly that the reported channel was unavailable
and why. Nothing about the finding was added — zero lines of this diff contain a
port, endpoint or mechanism. The manual queue is empty and tomorrow's run is
unblocked.

Public index, since the outcome vocabulary grew: the claude-tap row reads
`undelivered` rather than `private` (which implied a delivery that never
happened), a legend documents all eight values in use, and one stray checkmark is
normalised to `**fixed**` — the column now totals exactly 24, matching the record.

ROADMAP carries both this work and the roadmap line for the coverage manifest
that landed the same day.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@elfrost
elfrost force-pushed the feat/channel-viability-and-unreachable branch from fa994de to 39786b6 Compare September 18, 2026 13:26
@elfrost
elfrost merged commit 59c48f2 into main Sep 18, 2026
2 checks passed
@elfrost
elfrost deleted the feat/channel-viability-and-unreachable branch September 18, 2026 13:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant