Skip to content

docs(claude-security-review): align two-tier posture with disabled gate - #457

Merged
kyle-sexton merged 2 commits into
mainfrom
cursor/issue-448-two-tier-docs-728c
Aug 13, 2026
Merged

kyle-sexton merged 2 commits into
mainfrom
cursor/issue-448-two-tier-docs-728c

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Summary

Option-2 resolution for #448: keep the two-tier availability machinery unchanged (armed-and-waiting) and reword unconditional POSTURE / docs lines in .github/workflows/claude-security-review.yml so they match the existing conditional "may be REQUIRED" framing.

Fix

  • WHAT THE SECOND TIER COSTS: condition merge-during-outage cost on the check actually being required; note security-review-gate is enforcement: disabled so nothing gates on the context today (Design question: with security-review-gate disabled, is the two-tier availability ruling still the right shape? #448 / github-iac#282).
  • Merge-queue carve-out: no consumer currently requires the check; name claude-code-plugins as wired via requires-security-review.
  • NARROWING AMENDMENT: change "sole required security context" to conditional "MAY make this check the required security context — when armed".
  • Break-glass: note consumer-ruleset break-glass exists only when the gate is armed.
  • Consumer-contract concurrency note: reword to "wired to require this check (gate currently disabled)".
  • Append brief Option-2 ledger note to docs/topics/claude-review-lanes/PLAN.md.

No workflow behavior, jobs, or tests changed. No org ruleset re-arm from this repo. No single-tier simplification.

Verification

git diff is comments/docs only — all edits are # header comments in the workflow YAML and an append-only ledger paragraph in PLAN.md. No job, step, if:, input, or test logic changed.

Related

Closes #448

@cursor

cursor Bot commented Aug 12, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@claude

claude Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 2m 57s —— View job


Code review complete

  • Gather context (PR diff, changed files)
  • Check skip gate — not trivial (rewords substantive policy/factual claims about ruleset state), proceeded with review
  • Review .github/workflows/claude-security-review.yml changes
  • Review docs/topics/claude-review-lanes/PLAN.md changes
  • Post findings

Scope: this is the CODE-REVIEW lane (correctness/maintainability). No security-lane findings raised — this repo runs a dedicated security lane.

Cross-checked the PR's factual claims against the rest of PLAN.md's ledger (org ruleset version history, requires-security-review property audits, the #266/#448 amendments) — the core claims about security-review-gate being enforcement: disabled, claude-code-plugins being the sole wired consumer, and the conditional "MAY make this check required" framing all check out against that record.

1 finding posted inline on .github/workflows/claude-security-review.yml line 97: the newly added (when the gate is armed) qualifier on break-glass availability doesn't hold up against this repo's own ledger — github-iac PR #282 removed the bypass_actors entry entirely (independent of enforcement), and the one recorded instance of the gate actually being armed (2026-08-10) shows bypass_actors was empty at that time too. So arming the gate is not sufficient for break-glass to be available, which the added wording implies. Given the PR's stated goal is docs-honesty alignment, this line should either drop the break-glass claim or qualify it further. See the inline comment for the two supporting PLAN.md permalinks.

No other correctness issues found. The YAML diff is comments-only (confirmed via git diff origin/main...HEAD — only #-prefixed lines changed), so no workflow behavior is affected either way.

@claude

claude Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 1m 20s —— View job


Claude Security Review — #457

  • Gather context (PR description, diff vs origin/main, changed files)
  • Confirm diff is comments/docs only (no workflow behavior change)
  • Review workflow YAML comment changes for accuracy/security framing
  • Review PLAN.md ledger addition
  • Post final findings

Verdict: No security findings. Safe to merge from a security standpoint.

Scope confirmed: every changed line in .github/workflows/claude-security-review.yml is a # comment (diff); no on:, permissions:, jobs:, if:, run:, or with: blocks were touched. This is not a code change — nothing runs differently, no new inputs are consumed, no new secrets are referenced.

Accuracy check (why this matters for a "docs honesty" PR): I cross-referenced the new phrasing against docs/topics/claude-review-lanes/PLAN.md's own ledger of current org-ruleset state:

  • PLAN.md#L2041-2052 records security-review-gate as enforcement: disabled (confirmed live == IaC, no drift) and that claude-code-plugins — the only repo with requires-security-review == "true" — does not currently have security-review / security-review in its actual required-checks list.
  • That matches the reworded workflow comments exactly: L44 ("gate is armed — org ruleset security-review-gate is enforcement: disabled"), L77-79 ("no consumer's ruleset currently requires this check... wired via requires-security-review"), and L166-169. No overstated or stale claims found — the PR does what it says: aligns unconditional wording with the actual (disabled) gate state, without touching enforcement itself.

Non-findings worth noting (informational, not blocking):

  • The PLAN.md ledger addition at L2115-2122 is append-only prose, consistent with the rest of the file's audit-trail style.
  • No re-arming of the org ruleset occurs in this repo (as claimed) — security-review-gate enforcement is out of scope for ci-workflows and lives in github-iac.

No code review or implementation changes needed; this PR is doc/comment-only as described.
· Branch: cursor/issue-448-two-tier-docs-728c

@github-actions

github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Last security-reviewed head: aa99393b7a4dbf8b8fa8a8054082061bcc34f67f. On the next push, the relevance gate compares only the commits since this SHA; delete this comment to force a full re-review.

Comment thread .github/workflows/claude-security-review.yml Outdated
Reword POSTURE header comments so unconditional required-check claims
match the armed-and-waiting reality: security-review-gate enforcement
is disabled (ciw#448 / github-iac#282). No job, step, or test changes.

Append Option-2 ruling to claude-review-lanes PLAN.md ledger.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown

Claude has reviewed this PR 1 time. The lane skips further automatic reviews after 5; deleting this comment resets the count.

@cursor
cursor Bot force-pushed the cursor/issue-448-two-tier-docs-728c branch from 80f6c1a to aa99393 Compare August 12, 2026 23:54
@claude

claude Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Claude finished @cursor[bot]'s task in 1m 36s —— View job


Claude Security Review — #457

  • Gather context (PR description, diff vs origin/main, changed files)
  • Confirm scope: PR diff content vs origin/main is unchanged from the previously-reviewed head (80f6c1a) — this push only rebased onto an unrelated main commit (4fbb6b9, prerequisite-gate cancellation fix), it did not alter this PR's own two files
  • Re-review workflow YAML comment changes and PLAN.md ledger addition for security-relevant issues
  • Post final findings

Verdict: No security findings. Safe to merge from a security standpoint.

Scope confirmed: git diff origin/main...HEAD touches only .github/workflows/claude-security-review.yml (#-prefixed comment lines only — no on:, permissions:, jobs:, if:, run:, or with: blocks) and an append-only paragraph in docs/topics/claude-review-lanes/PLAN.md. Nothing runs differently: no new inputs, secrets, permissions, or trust-boundary changes.

Content is byte-for-byte the same PR diff already reviewed at the prior head — no new lines to assess from a security standpoint.

Non-security note (already raised in the code-review lane, not repeated as a security finding here): the (when the gate is armed) break-glass qualifier is still unaddressed — PLAN.md's own ledger records bypass_actors: [] both after github-iac#282 and at the one point the gate was actually armed (2026-08-10), so "armed" doesn't imply break-glass is available. This is a docs-accuracy question (does the comment correctly describe operator recourse), not a vulnerability, so it stays out of this lane's scope — flagging only so it isn't lost, since it hasn't been fixed since the earlier code-review pass.

No re-arming of the org ruleset occurs in this repo, and no workflow behavior changed.
· Branch: cursor/issue-448-two-tier-docs-728c

…ured

Armed alone does not restore bypass; github-iac left bypass_actors empty.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@kyle-sexton
kyle-sexton merged commit f973c6a into main Aug 13, 2026
1 check passed
@kyle-sexton
kyle-sexton deleted the cursor/issue-448-two-tier-docs-728c branch August 13, 2026 00:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Design question: with security-review-gate disabled, is the two-tier availability ruling still the right shape?

2 participants