Repository navigation
fix(ci): correct the provenance claim in the remediation PR body - #3847
Merged
Merged
Conversation
The published body states that Claude authored the change. That is false since the planner took over the manifest. Pull request 3846 carries the false claim now. A security remediation must not misattribute its own authorship. The body also held `\n` inside double quotes. Bash does not read an escape there, so the text reached GitHub as one line with a literal backslash and n. Pull request 3846 shows that too. The body now comes from a quoted heredoc, so the text holds real newlines. Its lines carry the indentation of the run block, which YAML strips, so the shell receives the heredoc at column zero. The new text names the deterministic planner, states that no model authored the change, and lists the checks that ran before the publishing job received a write credential. This is the smaller half of UI-138. The per-alert table with advisory links and resolved versions is still open. Refs UI-138
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
laurakwhit
added a commit
that referenced
this pull request
Sep 9, 2026
Auto-generated version bump from 2.53.3 to 2.54.0 Bump type: minor Changes included: - [`7a5684a5`](7a5684a) Check if api has been upgraded for minimum minor bump (#3823) - [`af39e483`](af39e48) refactor(events): derive event groups on read in the grouped-event-buffer (#3790) - [`3ce42ebb`](3ce42eb) Add the developer Workflow Catalog (#3785) - [`a1234e36`](a1234e3) chore: split Catalog into a focused Temporal UI plugin (#3835) - [`060eacf7`](060eacf) Get total slots based on available plus used (#3833) - [`283d3cfc`](283d3cf) fix(timezone): use regular font weight for the timezone switcher (#3834) - [`88d61845`](88d6184) Manual on-call dependency review with constrained Claude remediation (#3816) - [`f87d239e`](f87d239) ci: validate the weekly review candidate the way the PR checks do (#3841) - [`dd80eca0`](dd80eca) feat(ci): apply the dependency remediation without a model (#3845) - [`403e5b97`](403e5b9) refactor(icons)!: replace holocene's icon registry with Io icon components (#3822) - [`d6823cc4`](d6823cc) fix(ci): correct the provenance claim in the remediation PR body (#3847) - [`f1b05e99`](f1b05e9) feat(ci): post the weekly review only when it needs a person (#3848) - [`b993c04b`](b993c04) ci: run the on-call review test only for an on-call change (#3850) - [`4307d20f`](4307d20) fix(copyable): pin the copy icon to 16px (#3855) - [`62e3014f`](62e3014) Update SAA heartbeat info (#3856) - [`3a797592`](3a79759) Headers spacing alignment and Small Standalone Activity UI fixes (#3854) - [`41687b1f`](41687b1) Add total Worker count (#3641) - [`68a3bc2f`](68a3bc2) fix(catalog): keep isolated test fixtures out of the repo root (#3859) - [`9a56d3d9`](9a56d3d) fix: don't render an empty selected-count badge in combobox (#3853) - [`4b97f35b`](4b97f35) Make only keyboard focus pin Tooltip open (#3861) - [`2fd63c0e`](2fd63c0) Add Rust SDK to worker heartbeats SDK warning (#3863) - [`4b43f7f9`](4b43f7f) Move Saved Views above Filtering (#3858) - [`cdfd92c9`](cdfd92c) Add option to maximize paginated tables (#3864) - [`ea4d3f14`](ea4d3f1) Fix ConfigurableTableHeadersDrawer for SAA nexus operations (#3867) - [`10f50c8b`](10f50c8) Fix duplicate schedule action keys (#3868) - [`9feeb756`](9feeb75) feat(DT-3944): SignalWithStart system Nexus obfuscation — decode infrastructure + UI (#3356) - [`5af59f03`](5af59f0) feat(workers): let users set the Cloud Run scale-down stabilization window (#3860) - [`bb7d6fbd`](bb7d6fb) Support secondary text on Combobox options (#3866) - [`e0925297`](e092529) Fix paginated table height and mobile scrolling (#3871) - [`6dbd9b96`](6dbd9b9) fix: categorize local activity markers as local-activity (#3872) - [`353fbbc8`](353fbbc) Wrap long filter chips instead of overflowing the filter bar (#3877) - [`f4c71240`](f4c7124) Fix workflow list timestamp formatting (#3880) - [`fa9c51e9`](fa9c51e) Open saved views in a new tab on modifier-click (#3881) - [`376af414`](376af41) feat(workers): warn about Cloud Run deployment latency when creating a version (#3879) - [`1bde3187`](1bde318) Fix extra horizontal scroll from filter bar dropdowns (#3885) - [`dd1dcd9b`](dd1dcd9) Add Next Retry Delay under Retry State (#3886) - [`66c57a40`](66c57a4) Make system saved views additive on custom saved views (#3876) - [`ffa1f2fb`](ffa1f2f) Audit fields for defaults and order (#3887) - [`9ab9c40b`](9ab9c40) fix(server): update labstack/echo/v4 to 4.15.4 (FE-493) (#3874) - [`e4449991`](e444999) Make Build ID filterable and show worker status counts (#3889) - [`0a5e01f5`](0a5e01f) SAA fields audit part 2 (#3890) - [`0d604b5a`](0d604b5) Fix payload input focus loss (FE-643) (#3891) - [`06712381`](0671238) Keep portal menus anchored when the layout shifts (#3893) Co-authored-by: laurakwhit <15069288+laurakwhit@users.noreply.github.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description & motivation 💭
The first real
applyrun published draft pull request #3846. Its body holds two faults.It misattributes authorship. The body states that Claude authored the change. #3845 moved that work to the deterministic planner, and no model touches the manifest now. A security remediation must not make a false claim about who wrote it.
The newlines are literal. The body was built as
body="...\n\n..."inside double quotes. Bash reads no escape there, so GitHub received one long line holding a backslash and an n. #3846 shows this.The change
The body now comes from a quoted heredoc, so the text holds real newlines. Its lines carry the indentation of the
runblock, which YAML strips, so the shell receives the heredoc at column zero.The new text names the deterministic planner, states that no model authored the change, and lists the checks that ran before the publishing job received a write credential.
Testing 🧪
How was this tested 👻
The workflow file parses and prettier reports no problem. 77 tests pass, unaffected.
The body was extracted from the parsed workflow and run through bash with
RUN_URLset. The output holds real line breaks, expands the run URL, and contains no literal backslash and n.Steps for others to test: 🚶🏽♂️🚶🏽♀️
After this merges, open Actions, select Weekly On-Call Review, and run it with the mode
applyand the channelC0BPXR260DA. The run updates #3846 in place, so the body should render as paragraphs.Checklists
Merge Checklist
Issue(s) closed
Part of UI-138. The per-alert table with advisory links and resolved versions is still open.
Docs
Any docs updates needed?
No.