Skip to content

docs: add resource-bounding and CI-workflow-security to review rubric#80

Open
vincent-k2026 wants to merge 2 commits into
mainfrom
krabat/docs/review-rubric-additions
Open

docs: add resource-bounding and CI-workflow-security to review rubric#80
vincent-k2026 wants to merge 2 commits into
mainfrom
krabat/docs/review-rubric-additions

Conversation

@vincent-k2026

Copy link
Copy Markdown
Contributor

Two checks the shared baseline didn't cover yet:

  • rubric.md — a "bound every queue and buffer" bullet under Correctness & safety (an unbounded channel/queue/buffer or metric label set is a memory-DoS), plus a routing entry to the new detail section.
  • rubric-detail.md — a §CI-workflow-security section (no untrusted input in run:, least-privilege token / SHA-pinning, teardown-on-failure, guarded comment/label triggers), read on demand when a diff touches workflows.

Additive only — no existing rubric text changed.

@vincent-k2026
vincent-k2026 requested a review from Troublor as a code owner July 22, 2026 11:55

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Clean

  • Reviewed additive rubric changes under Correctness & safety in rubric.md and a new §CI-workflow-security section in rubric-detail.md.
  • No new actionable findings. Additions match surrounding style, the routing sigil maps to the new header, and no existing rubric text was mutated.
  • Still open from earlier reviews: none.

Pre-mortem: no verifiable high-impact failure path found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant