Skip to content

docs: fix stale "active PR #80" references in automation-threat-model.md - #553

Draft
seonghobae wants to merge 7 commits into
mainfrom
docs/fix-stale-pr80-references
Draft

docs: fix stale "active PR #80" references in automation-threat-model.md#553
seonghobae wants to merge 7 commits into
mainfrom
docs/fix-stale-pr80-references

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Causal documentation repair

Closed PR #80 is historical lineage only. Protected Noema already carries the T-A07/T-A08 atomic publisher controls: expected-absence creation lease, exact-proposal-head deletion lease, cryptographic publication marker, exact head/base matching, unique PR recovery, numeric PR identity and conditional cleanup. RED 2814e5ee... → documentation repair 107a973f... prevents the threat model from describing those protected controls as unimplemented.

After #552 merged, ordinary two-parent/non-force restack 722fa1202a51cc774cc71af1c0a0e34429c81bdd preserved the two-file threat-model delta and adopted protected main@5b8e620dbb01a794c1a38535bbcc32e41a80d0df. No workflow/runtime behavior, permissions, provider/model routing, security/quarantine/outbound authority or foreign domain truth changed.

Current exact authority

  • protected Noema base: main@5b8e620dbb01a794c1a38535bbcc32e41a80d0df;
  • exact PR head: 722fa1202a51cc774cc71af1c0a0e34429c81bdd;
  • lifecycle: open / Draft / mergeable;
  • fresh exact-head Security Scan 34020964838, ci 34020964810, reviewer-ci 34020964819, patch-validator-image 34020964861 are queued. Historical GREEN does not transfer.

Keep Draft until unchanged-head gates are terminal GREEN and current review state is clear. Do not weaken publisher race controls, self-approve, rewrite history, or source-churn for runner allocation.

PR #80 (fix/atomic-product-publisher-lease) closed unmerged on 2026-08-15,
but three references here still described its proposed T-A07/T-A08 controls
as active/current and said doctoring should be integrated "after that PR
lands" — it never will, since it's closed. Corrected the tense/status in
place; the underlying threat/control content is otherwise unchanged, since
no current successor implements these specific controls yet.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KPmJErfkcHer4UVEgrQxUX
@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants