Skip to content

fix(release-vote-draft): keep CVE IDs and security framing out of the expedited reason - #1509

Merged
potiuk merged 1 commit into
apache:mainfrom
potiuk:fix/vote-draft-embargo
Oct 4, 2026
Merged

potiuk merged 1 commit into
apache:mainfrom
potiuk:fix/vote-draft-embargo

Conversation

@potiuk

@potiuk potiuk commented Oct 4, 2026

Copy link
Copy Markdown
Member

release-vote-draft copied the release manager's --expedited reason verbatim into the [VOTE] email and the planning-issue comment, and both are public.
If the reason named a CVE ID or described the release as fixing a security problem, the skill published that before the embargo lifted.
The eval expected that output, so the model failed both expedited cases (on main too) by correctly leaving the CVE out.

Summary

  • Golden rule 4 and Steps 2 and 3: until the public announcement ships, the expedited reason names no CVE and carries no security framing, per AGENTS.md § Confidentiality. The reason is written neutrally ("Time-sensitive fix release"), keeps any approval the RM cited, and the RM is told what was left out.
  • Expected answers: the two expedited cases now expect the neutral reason.
  • New assertion: both suites assert that no CVE ID or security framing reaches the public text.

Test plan

  • prek hooks on commit
  • release-vote-draft step-2 (3/3) and step-3 (3/3). Step-2 case-2 failed once on bracket formatting, then passed twice.

🤖 Generated with Claude Code

… expedited reason

release-vote-draft copied the release manager's --expedited reason into
the [VOTE] email and the planning-issue comment, both public. A reason
such as "Critical security fix for CVE-2026-12345" therefore broke the
embargo before the advisory shipped, and the eval expected exactly that.

Golden rule 4 and Steps 2 and 3 now say the reason names no CVE and
does not call the release a security fix until the advisory ships
(AGENTS.md, Confidentiality): it is written neutrally, keeps any
approval the RM cited, and the RM is told what was left out. The two
expedited cases expect the neutral reason, and an assertion in both
suites checks that no CVE ID or security framing reaches the public
text.

Generated-by: Claude Opus 5
@potiuk
potiuk merged commit 4851c65 into apache:main Oct 4, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant