Repository navigation
feat: fix confirmed findings during scans with native agents #1365
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
yoni-at-strix
wants to merge
41
commits into
main
Choose a base branch
from
devin/1790308365-verified-fix-preparation
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from 1 commit
Commits
Show all changes
41 commits
Select commit
Hold shift + click to select a range
f23afb4
Add verified fix preparation engine
yoni-at-strix 49eca20
Harden fix preparation against review findings
yoni-at-strix 2b413da
Keep prepared candidates and staleness consistent across revisions
yoni-at-strix be1c2e4
Withhold automatic fixes when repairs exceed the recorded draft
yoni-at-strix 9d525ad
Add bounded fix verification feedback loop
yoni-at-strix d02b74c
Preserve explicit blocked repair outcomes
yoni-at-strix a41000d
Retry unchanged repairs when verification changes
yoni-at-strix c510f58
fix: retry transient verifier inconclusive results
yoni-at-strix df313c1
refactor fix preparation gates
yoni-at-strix 00fcb4c
fix: classify distinct check failures correctly
yoni-at-strix f213a7d
Require functional fix evidence and preserve partial preparation work
198a254
Make preparation history factory explicit for strict type checking
791ef91
fix: let independent evidence resolve repair timeout
yoni-at-strix 85b3030
Preserve partial fixes and require consistent execution evidence
f03fd72
Simplify fix preparation around native tests and independent review
0faa7b7
Make fix handoffs actionable and require customer unit tests
43391eb
Let repair and review agents own the fix workflow
d184142
Let fix reviewer own validation and completion
348fbf2
Support native fix-agent assignments and final reviewed patches
5badb2d
Remove retired fix execution and proof machinery
d35197b
Move complete fix workflow into OSS and add strix fix CLI
acf262f
Keep fix outputs private and outside the source checkout
1c1a899
Focus fix agents and preserve completion evidence
77bd5da
Require an explicit fix handoff for source-backed findings
yoni-at-strix 868ba53
Scope fix validation and warn on repeated commands
yoni-at-strix e4f1fe6
Merge remote-tracking branch 'origin/main' into devin/1790308365-veri…
yoni-at-strix ba6bbaf
Include repair follow-ups in the readable review
yoni-at-strix 1789400
Keep an approved fix when only the PR text changes
yoni-at-strix 8317665
Run confirmed finding fixes as native agents in the scan sandbox
yoni-at-strix b71ed13
Use native child delegation for finding fixes and strengthen completi…
yoni-at-strix 1f8295c
Launch native fixes after persistence and bound completion failures
yoni-at-strix f75fb5f
fix: harden fix dispatch and verification (STR-815)
yoni-at-strix bba4aa2
fix: require reviewed current patches and enforce fix network isolation
60d4ce1
feat: allow scans to skip automatic fixes
yoni-at-strix 3763a67
fix: finalize cancelled fix agents
yoni-at-strix 1fa7d21
feat: publish verified fixes as local branches
yoni-at-strix f144685
fix: complete interactive autofix scans before cleanup
yoni-at-strix 098fa36
fix: guard resumed assessments and ignore withdrawn fix records
yoni-at-strix 9edb2ae
fix: disable automatic fix agents for PR review scans
yoni-at-strix 8bd7f4c
refactor: use one auto-fix setting and infer fix delivery
yoni-at-strix 818d583
Accept stray characters in validation status and hide auto-fix guidan…
yoni-at-strix File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Harden fix preparation against review findings
- Resolve edit/anchor/manifest paths and require workspace containment so committed symlinks cannot redirect reads or writes outside the checkout. - Treat unreadable or non-UTF-8 anchor targets as missing instead of raising, and never let candidate anchoring block report persistence. - Enforce the declared command policy: subprocess env is an allowlist plus credentials_allowed, and commands run in a network namespace (unshare) when network_allowed is false, or are rejected when isolation is unavailable. - Require a clean worktree in addition to a matching HEAD commit so pre-existing uncommitted changes are not attributed to the fix. - Expand untracked directories into per-file manifest entries. - Surface failed optional checks as gaps instead of silent readiness. - SARIF fixes emit only the verified candidate (digest must match the recorded fix_candidate), not the stale draft locations.
- Loading branch information
commit 49eca20a1a4fab4633d916cd6654ee089d3479cb
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.