Skip to content

fix(ci): correct the provenance claim in the remediation PR body - #3847

Merged
rossnelson merged 1 commit into
mainfrom
fix-remediation-pr-body
Aug 20, 2026
Merged

rossnelson merged 1 commit into
mainfrom
fix-remediation-pr-body

Conversation

@rossnelson

Copy link
Copy Markdown
Collaborator

Description & motivation 💭

The first real apply run published draft pull request #3846. Its body holds two faults.

It misattributes authorship. The body states that Claude authored the change. #3845 moved that work to the deterministic planner, and no model touches the manifest now. A security remediation must not make a false claim about who wrote it.

The newlines are literal. The body was built as body="...\n\n..." inside double quotes. Bash reads no escape there, so GitHub received one long line holding a backslash and an n. #3846 shows this.

The change

The body now comes from a quoted heredoc, so the text holds real newlines. Its lines carry the indentation of the run block, which YAML strips, so the shell receives the heredoc at column zero.

The new text names the deterministic planner, states that no model authored the change, and lists the checks that ran before the publishing job received a write credential.

Testing 🧪

How was this tested 👻

  • Manual testing
  • E2E tests added
  • Unit tests added

The workflow file parses and prettier reports no problem. 77 tests pass, unaffected.

The body was extracted from the parsed workflow and run through bash with RUN_URL set. The output holds real line breaks, expands the run URL, and contains no literal backslash and n.

Steps for others to test: 🚶🏽‍♂️🚶🏽‍♀️

After this merges, open Actions, select Weekly On-Call Review, and run it with the mode apply and the channel C0BPXR260DA. The run updates #3846 in place, so the body should render as paragraphs.

Checklists

Merge Checklist

Issue(s) closed

Part of UI-138. The per-alert table with advisory links and resolved versions is still open.

Docs

Any docs updates needed?

No.

The published body states that Claude authored the change. That is false since
the planner took over the manifest. Pull request 3846 carries the false claim
now. A security remediation must not misattribute its own authorship.

The body also held `\n` inside double quotes. Bash does not read an escape
there, so the text reached GitHub as one line with a literal backslash and n.
Pull request 3846 shows that too.

The body now comes from a quoted heredoc, so the text holds real newlines. Its
lines carry the indentation of the run block, which YAML strips, so the shell
receives the heredoc at column zero.

The new text names the deterministic planner, states that no model authored the
change, and lists the checks that ran before the publishing job received a write
credential.

This is the smaller half of UI-138. The per-alert table with advisory links and
resolved versions is still open.

Refs UI-138
@rossnelson
rossnelson requested a review from a team as a code owner August 20, 2026 13:56
@vercel

vercel Bot commented Aug 20, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
holocene Ready Ready Preview Aug 20, 2026 1:57pm

Request Review

@rossnelson
rossnelson merged commit d6823cc into main Aug 20, 2026
26 checks passed
@rossnelson
rossnelson deleted the fix-remediation-pr-body branch August 20, 2026 16:29
laurakwhit added a commit that referenced this pull request Sep 9, 2026
Auto-generated version bump from 2.53.3 to 2.54.0

Bump type: minor

Changes included:
- [`7a5684a5`](7a5684a) Check if api has been upgraded for minimum minor bump (#3823)
- [`af39e483`](af39e48) refactor(events): derive event groups on read in the grouped-event-buffer (#3790)
- [`3ce42ebb`](3ce42eb) Add the developer Workflow Catalog (#3785)
- [`a1234e36`](a1234e3) chore: split Catalog into a focused Temporal UI plugin (#3835)
- [`060eacf7`](060eacf) Get total slots based on available plus used (#3833)
- [`283d3cfc`](283d3cf) fix(timezone): use regular font weight for the timezone switcher (#3834)
- [`88d61845`](88d6184) Manual on-call dependency review with constrained Claude remediation (#3816)
- [`f87d239e`](f87d239) ci: validate the weekly review candidate the way the PR checks do (#3841)
- [`dd80eca0`](dd80eca) feat(ci): apply the dependency remediation without a model (#3845)
- [`403e5b97`](403e5b9) refactor(icons)!: replace holocene's icon registry with Io icon components (#3822)
- [`d6823cc4`](d6823cc) fix(ci): correct the provenance claim in the remediation PR body (#3847)
- [`f1b05e99`](f1b05e9) feat(ci): post the weekly review only when it needs a person (#3848)
- [`b993c04b`](b993c04) ci: run the on-call review test only for an on-call change (#3850)
- [`4307d20f`](4307d20) fix(copyable): pin the copy icon to 16px (#3855)
- [`62e3014f`](62e3014) Update SAA heartbeat info (#3856)
- [`3a797592`](3a79759)  Headers spacing alignment and Small Standalone Activity UI fixes  (#3854)
- [`41687b1f`](41687b1) Add total Worker count (#3641)
- [`68a3bc2f`](68a3bc2) fix(catalog): keep isolated test fixtures out of the repo root (#3859)
- [`9a56d3d9`](9a56d3d) fix: don't render an empty selected-count badge in combobox (#3853)
- [`4b97f35b`](4b97f35) Make only keyboard focus pin Tooltip open (#3861)
- [`2fd63c0e`](2fd63c0) Add Rust SDK to worker heartbeats SDK warning (#3863)
- [`4b43f7f9`](4b43f7f) Move Saved Views above Filtering (#3858)
- [`cdfd92c9`](cdfd92c) Add option to maximize paginated tables (#3864)
- [`ea4d3f14`](ea4d3f1) Fix ConfigurableTableHeadersDrawer for SAA nexus operations (#3867)
- [`10f50c8b`](10f50c8) Fix duplicate schedule action keys (#3868)
- [`9feeb756`](9feeb75) feat(DT-3944): SignalWithStart system Nexus obfuscation — decode infrastructure + UI (#3356)
- [`5af59f03`](5af59f0) feat(workers): let users set the Cloud Run scale-down stabilization window (#3860)
- [`bb7d6fbd`](bb7d6fb) Support secondary text on Combobox options (#3866)
- [`e0925297`](e092529) Fix paginated table height and mobile scrolling (#3871)
- [`6dbd9b96`](6dbd9b9) fix: categorize local activity markers as local-activity (#3872)
- [`353fbbc8`](353fbbc)  Wrap long filter chips instead of overflowing the filter bar (#3877)
- [`f4c71240`](f4c7124) Fix workflow list timestamp formatting (#3880)
- [`fa9c51e9`](fa9c51e) Open saved views in a new tab on modifier-click (#3881)
- [`376af414`](376af41) feat(workers): warn about Cloud Run deployment latency when creating a version (#3879)
- [`1bde3187`](1bde318) Fix extra horizontal scroll from filter bar dropdowns (#3885)
- [`dd1dcd9b`](dd1dcd9) Add Next Retry Delay under Retry State (#3886)
- [`66c57a40`](66c57a4)  Make system saved views additive on custom saved views (#3876)
- [`ffa1f2fb`](ffa1f2f) Audit fields for defaults and order (#3887)
- [`9ab9c40b`](9ab9c40) fix(server): update labstack/echo/v4 to 4.15.4 (FE-493) (#3874)
- [`e4449991`](e444999) Make Build ID filterable and show worker status counts (#3889)
- [`0a5e01f5`](0a5e01f) SAA fields audit part 2 (#3890)
- [`0d604b5a`](0d604b5) Fix payload input focus loss (FE-643) (#3891)
- [`06712381`](0671238) Keep portal menus anchored when the layout shifts (#3893)

Co-authored-by: laurakwhit <15069288+laurakwhit@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
Preview — 0cc24586 Deployed Aug 20, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant