Skip to content

feat(claude-lanes): unpark security-review caller for provisioning - #379

Merged
kyle-sexton merged 2 commits into
mainfrom
cursor/unpark-security-review-caller-63a5
Aug 13, 2026
Merged

feat(claude-lanes): unpark security-review caller for provisioning#379
kyle-sexton merged 2 commits into
mainfrom
cursor/unpark-security-review-caller-63a5

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Summary

Unparks claude-security-review-caller for private adopters (path (b) from #377), with melodic-software/provisioning as the first managed target.

  • Move cancel-in-progress: false to job-level concurrency on security-review so the caller can coexist with concurrency-policy (delegated-job-level shape).
  • Manage the component for provisioning in the sync manifest.
  • Rewrite parking docs so the remaining public/shared-shape blockers from Unparking claude-security-review-caller costs more than the runner indirection alone #377 stay recorded (cross-repo routing kind, blanket public-target test, plugins evidence/skip-actors) without filing a follow-up issue.
  • Align the claude-code-plugins locally-owned removal trigger with that same three-part bar.

Fixes #377

Related

Verification

  • node --test --test-name-pattern='claude lane|managed target of a claude|selector-routed claude' components/runner-policy/runner-policy.test.mjs — 4/4 pass
  • Standalone actionlint of materialized security caller — clean
  • bash distribution/sync-manifest.sh validate — valid
  • Clean-config apply to a provisioning stand-in materializes both lane callers

Follow-through (same session)

  • Merge sync PR into provisioning after this lands
  • Ship repo-owned .github/claude-security-paths starter in provisioning
  • Do not add security-review / security-review as a required check yet (frontier consensus: observe advisory first)
Open in Web Open in Cursor 

Move cancel-in-progress:false to job-level concurrency so the caller can
coexist with concurrency-policy, manage the component for provisioning,
and record the remaining public/shared-shape blockers from #377.

Fixes #377

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review August 13, 2026 05:25
@cursor

cursor Bot commented Aug 13, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actions github-actions Bot deleted a comment from claude Bot Aug 13, 2026
@claude

claude Bot commented Aug 13, 2026

Copy link
Copy Markdown

Claude encountered an error after 0s —— View job


I'll analyze this and get back to you.

@github-actions

Copy link
Copy Markdown

Warning

Automated review did not complete — this is an infrastructure failure, not a review verdict.

Treat any Claude comment on this PR (including a placeholder like "I'll analyze this and get back to you") as incomplete, not "no findings."

Re-run the job, or workflow_dispatch this workflow with the PR number, to retry the review. A new push re-triggers this lane only if the caller's pull_request triggers include synchronize (the canonical caller omits it).
An automatic retry may already have run — it is skipped when a partial review could duplicate comments, or when the failure class needs an operator (auth).

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2c88b251bc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread distribution/sync-manifest.yml Outdated


The claude-code-plugins note still claimed runner-indirection alone was
enough; keep it in lockstep with the three public/shared-shape blockers.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@kyle-sexton
kyle-sexton merged commit 6d46b7a into main Aug 13, 2026
46 checks passed
@kyle-sexton
kyle-sexton deleted the cursor/unpark-security-review-caller-63a5 branch August 13, 2026 05:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unparking claude-security-review-caller costs more than the runner indirection alone

2 participants