From 80f4f0b92113adea94ef2c07d33ac786f410a420 Mon Sep 17 00:00:00 2001 From: Jarek Potiuk Date: Mon, 5 Oct 2026 00:28:26 +0200 Subject: [PATCH] fix(release-vote-draft): keep CVE IDs and security framing out of the expedited reason release-vote-draft copied the release manager's --expedited reason into the [VOTE] email and the planning-issue comment, both public. A reason such as "Critical security fix for CVE-2026-12345" therefore broke the embargo before the advisory shipped, and the eval expected exactly that. Golden rule 4 and Steps 2 and 3 now say the reason names no CVE and does not call the release a security fix until the advisory ships (AGENTS.md, Confidentiality): it is written neutrally, keeps any approval the RM cited, and the RM is told what was left out. The two expedited cases expect the neutral reason, and an assertion in both suites checks that no CVE ID or security framing reaches the public text. Generated-by: Claude Opus 5 --- .../skills/vote-draft/SKILL.md | 15 +++++++++++++-- .../step-2-vote-draft/fixtures/assertions.json | 7 +++++++ .../fixtures/case-2-expedited-vote/expected.json | 2 +- .../fixtures/assertions.json | 9 +++++++++ .../fixtures/case-2-expedited-note/expected.json | 2 +- 5 files changed, 31 insertions(+), 4 deletions(-) create mode 100644 tools/skill-evals/evals/release-vote-draft/step-3-planning-comment/fixtures/assertions.json diff --git a/plugins/magpie-release-management/skills/vote-draft/SKILL.md b/plugins/magpie-release-management/skills/vote-draft/SKILL.md index 2af1c7465..5eb3232c3 100644 --- a/plugins/magpie-release-management/skills/vote-draft/SKILL.md +++ b/plugins/magpie-release-management/skills/vote-draft/SKILL.md @@ -25,7 +25,7 @@ argument-hint: "-rcN [--skip-verify-check ]" capability: capability:resolve surface_hash: sha256:6d70a52ead840ca2 license: Apache-2.0 -measured_tokens: 6661 +measured_tokens: 6842 ---