Skip to content

autonomy pipeline: no dedicated security-review pass — automated code review only #509

Description

@kyle-sexton

Gap

The autonomy pipeline runs automated code review on every PR (claude[bot] review + work-lane post-green review pass), but there is no dedicated security review anywhere in the flow. Boris's full-autonomy guidance stresses both: code reviews AND separate dedicated security reviews. We have the first, not the second.

Current state

Questions for triage

Filed from control-tower checkpoint on operator direction (2026-07-19 late-afternoon).


Reference: Boris Cherny, "Steps of AI Adoption" (Google Doc)

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: securitySecurity-relevant: vulnerability, hardening, or disclosure follow-up.needs-humanHuman-in-the-loop required; autonomous sessions must not resolve items carrying this.priority: highSignificant impact, or blocks an imminent release; staff this cycle.wayfind: designWayfind decision item: design-space or domain-model decision; human in the loop.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions