Skip to content

fix(gator): surface PR-owned security regressions in reviews - #4338

Open
johntmyers wants to merge 1 commit into
mainfrom
fix/4337-gator-security-review/johntmyers
Open

johntmyers wants to merge 1 commit into
mainfrom
fix/4337-gator-security-review/johntmyers

Conversation

@johntmyers

Copy link
Copy Markdown
Collaborator

Summary

Clarify that security regressions introduced or newly exposed by an unmerged PR belong in its normal, actionable PR review. Prevent security classification alone from creating a private-triage gate or suspending operator-authorized tests.

Related Issue

Closes #4337

Changes

  • Distinguish PR-owned regressions from pre-existing vulnerabilities independent of the PR in the Gator gate skill, top-level prompt, and independent reviewer guidance.
  • Explicitly treat new reachable paths, trusted sinks, and security contracts as PR-owned even when an underlying unsafe primitive existed before the change.
  • Preserve normal evidence, severity, blocker, and test-authorization rules; private handling under SECURITY.md remains applicable to pre-existing independent vulnerabilities.
  • Require explicit operator authorization for external disclosure or reporting.
  • Update launcher guidance, add instruction-consistency regression checks, and bump the immutable payload to 12. Payload 11 is reserved by the separate large-diff fix in fix(gator): handle oversized PR diffs in review ledger #4309; this PR does not include that implementation.
  • Leave SECURITY.md and existing sandbox state unchanged. No detailed security finding is published by this change.

Testing

  • Checks appropriate to the affected code and behavior pass: all four Gator helper suites, Bash syntax, manifest YAML/version validation, and git diff --check.
  • Unit tests added/updated: regression assertions cover consistent review routing and external-disclosure authorization across the gate, prompt, and reviewer.
  • Tests validate instruction text and helper behavior, not deterministic model compliance. No live watcher was relaunched with payload 12.
  • Full Rust/SDK/E2E suites were not run; no runtime implementation changed.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
@johntmyers
johntmyers force-pushed the fix/4337-gator-security-review/johntmyers branch from ad58a25 to 2b5f32a Compare October 9, 2026 00:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: Gator routes unmerged PR security regressions into private triage

2 participants