Skip to content

chore(triage-security): refresh harness pin and lock - #320

Merged
mrizzi merged 1 commit into
RHEcosystemAppEng:verify-pr-fullsendfrom
mrizzi:TC-6647
Sep 30, 2026
Merged

mrizzi merged 1 commit into
RHEcosystemAppEng:verify-pr-fullsendfrom
mrizzi:TC-6647

Conversation

@mrizzi

@mrizzi mrizzi commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

The registered triage-security child still pinned a revision preceding the completed Fullsend migration. Advance it to merged upstream commit 59f9ff4b4f49646c64ed3412271ce7c017e781d4 and regenerate only its lock entry so subsequent runs load the migration, portability, and trusted issue-scope authorization fixes.

Implements TC-6647.

The selected revision is the merge commit of PR #319 on verify-pr-fullsend. Git ancestry checks confirm containment of TC-6207–TC-6212 and TC-6613–TC-6615. PR #319's commits landed with rewritten IDs; the merged revision and its final tested head 6370ceccb665f61c34fcb8a5b38ffe7b69199806 have the identical complete Git tree 403a9947fa120491fa9729984f45e5fd5cb65209, establishing inclusion of TC-6646/TC-6649/TC-6650. Both formal prerequisites, TC-6206 and TC-6646, are Closed. The latest persisted task description matches sha256-md:ee88a8bb120f783c02f5001786d1d9658905542868b10ed63226f7bf3f075edf.

Validation:

  • Downloaded exact upstream base bytes match the Git object at the selected revision; SHA256: 110fb33d880caf1add20e73c8017451378966eeef52ef34aa988e41c35fc1b02.
  • fullsend lock triage-security --fullsend-dir .fullsend --update succeeded with Fullsend v0.43.0. All 11 dependency URLs use the selected SHA; 118 directory-member hashes and all four directory tree hashes match the selected revision. No previous-revision references remain in the triage-security entry.
  • The local input mount (including optional: true) and verify-pr lock entry are byte-identical. Diff scope is exactly .fullsend/harness/triage-security.yaml and .fullsend/lock.yaml; no local scaffolding or credentials are included.
  • git diff --check passed; uvx skillsaw passed with 0 errors and 7 existing warnings; claude plugin validate plugins/sdlc-workflow passed; python3 -m pytest plugins/sdlc-workflow/scripts/ -q passed (271 tests).

This is the configuration-only scope approved in the current Jira description. Runtime and integration validation remain in downstream TC-6213. No inference run was performed.

Summary by Sourcery

Update the triage-security harness pin and lock metadata to the validated upstream revision.

Enhancements:

  • Refresh the triage-security harness to the upstream revision containing the completed Fullsend migration and related portability and authorization updates.

Chores:

  • Regenerate the triage-security Fullsend lock entry to reflect the refreshed upstream dependencies and content hashes.

Pin merged upstream revision 59f9ff4 and regenerate only triage-security dependencies. Preserve the local input mount and verify-pr lock entry.

Implements TC-6647

Assisted-by: Claude Code
@sourcery-ai

sourcery-ai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer's Guide

Refreshes triage-security from the pre-migration upstream pin to verified merge commit 59f9ff4 and regenerates only its lock data, bringing in Fullsend migration, portability, and trusted issue-scope authorization fixes while preserving local input handling and the verify-pr lock.

File-Level Changes

Change Details Files
Advance the triage-security harness to the upstream Fullsend migration revision.
  • Replace the prior upstream commit and content digest with 59f9ff4 and its verified SHA256.
  • Retain the runner-local input mount configuration while consuming the migrated upstream harness definition.
.fullsend/harness/triage-security.yaml
Regenerate the triage-security lock entry for the pinned revision.
  • Update all triage-security dependency URLs, resolved hashes, timestamps, and directory-member/tree hashes to the selected commit.
  • Record newly included migration-related scripts and tests, including test_triage_security_fullsend.py.
  • Leave the verify-pr lock entry unchanged and limit the diff to the two Fullsend configuration files.
.fullsend/lock.yaml
Validate the refreshed immutable configuration and repository integration.
  • Verify upstream bytes, Git-tree ancestry, dependency hashes, and absence of stale revision references.
  • Run formatting, skills, plugin validation, and the 271-script test suite successfully; defer runtime/integration inference validation to TC-6213.
.fullsend/harness/triage-security.yaml
.fullsend/lock.yaml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. The new pinned commit changes the external triage harness, including its security policy and scripts, so a mistaken update could produce incorrect security findings or automated ticket/PR actions. Reverting stops future runs but does not undo actions or records already created.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@mrizzi mrizzi added the ok-to-test Enable verify-pr execution on PRs from forks label Sep 30, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🤖 Finished Verify Pr · ⏭️ Skipped (TC-6647 is missing the 'ai-generated-jira' label) · Started 12:36 PM UTC · Completed 12:36 PM UTC

Commit: de3824a · View workflow run →

Effort: high

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🤖 Finished Verify Pr · ✅ Success · Started 12:41 PM UTC · Completed 12:50 PM UTC

Commit: de3824a · View workflow run →

Runtime: claude · Model: claude-opus-4-8 · Effort: high · Cost: $4.21

@fullsend-ai-review

Copy link
Copy Markdown

[sdlc-workflow/verify-pr] Re: @sourcery-ai[bot] review - Classified as suggestion - the review is an advisory risk assessment recommending human review ("Needs a human reviewer"); it proposes no concrete code change and matches no documented CONVENTIONS.md convention or established codebase pattern. No sub-task created.

@fullsend-ai-review

Copy link
Copy Markdown

Verification Report for TC-6647 (commit de3824a)

Check Result Details
Review Feedback PASS 1 review body (sourcery-ai advisory); no code change requests, no sub-tasks.
Root-Cause Investigation N/A No sub-tasks created; nothing to investigate.
Scope Containment PASS Exactly the two task-declared files changed; none extra, none missing.
Diff Size PASS ~112 lines across 2 files; lock.yaml churn is expected regeneration.
Commit Traceability PASS Sole commit de3824a references TC-6647 ("Implements TC-6647").
Sensitive Patterns PASS No secrets in added lines; only URL pins, SHA256 integrity digests, timestamps.
CI Status PASS All completed checks success/skipped; no failures or pending.
Acceptance Criteria PASS 5 of 5 criteria met (criteria 1-2 confirmed by internal consistency; no network re-download in sandbox).
Test Quality N/A No test files in diff; no eval reviews (Eval Quality: N/A).
Test Change Classification N/A No test files added/modified/deleted.
Verification Commands PASS git diff --check clean; network/tooling commands corroborated by passing CI.

Overall: PASS

All substantive checks PASS; informational checks N/A. This configuration-only PR advances the triage-security child harness pin from upstream commit 9d6e272a to the merged revision 59f9ff4b4f49646c64ed3412271ce7c017e781d4 and regenerates only the triage-security lock. Scope is confined to the two declared files (.fullsend/harness/triage-security.yaml, .fullsend/lock.yaml); the harness #sha256=110fb33d integrity fragment matches the lock's base dependency hash; no stale 9d6e272a references remain; the local input mount and the verify-pr lock entry are preserved. CI is fully green. Note: acceptance criteria 1 and 2 (remote-commit containment of TC-6646 and byte-exact SHA256 of the upstream base) were verified by internal consistency and passing CI rather than a live re-download, since the sandbox has no network egress. This report is informational - no merge or Jira transition is performed.


This comment was AI-generated by sdlc-workflow/verify-pr v0.13.9.

@mrizzi
mrizzi merged commit 255d509 into RHEcosystemAppEng:verify-pr-fullsend Sep 30, 2026
42 checks passed
@mrizzi
mrizzi deleted the TC-6647 branch September 30, 2026 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Enable verify-pr execution on PRs from forks

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant