Add evidence-bound cloud review decisions - #28
Closed
seonghobae wants to merge 1 commit into
Closed
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
review_fingerprintbeside the existing metadata fingerprintWhy
Candidates with incomplete or sensitive metadata need an explicit operator decision. The prior gate
correctly blocked every review-required candidate but had no safe way to record that the displayed
metadata had actually been inspected.
Safety impact
Approval clears only
review-required. It cannot satisfy the embedded high-confidence productiondate requirement, cannot bypass destination or path blockers, and automatically expires whenever
the candidate or displayed review evidence changes. The source deletion API remains absent.
Validation
npm run check— passed, 0 errors and 0 warningsnpm test— passed, 5 files / 18 testsgit diff --check— passedcargo check --all-targets -j1did not reach project compilation because macOS killedrustc while compiling
serde_withwith SIGKILL under memory pressure; GitHub Test/Release shouldprovide the Rust compilation result