Skip to content

docs(review): require bilingual scrutinize evidence in PRs#120

Merged
xenodeve merged 3 commits into
masterfrom
feat/scrutinize-pr-evidence-118
Jul 23, 2026
Merged

docs(review): require bilingual scrutinize evidence in PRs#120
xenodeve merged 3 commits into
masterfrom
feat/scrutinize-pr-evidence-118

Conversation

@xenodeve

@xenodeve xenodeve commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

Closes #118

English

The core #118 changes are already on master because a concurrent Wave 3 process committed the staged review files and PR #119 merged that commit. Master now contains:

  • mandatory full English and Thai scrutinize reports as PR comments;
  • reviewed base/head and commit identity plus comment URL evidence;
  • stale-review invalidation when HEAD changes;
  • security-review invocation for trust-boundary diffs;
  • the bilingual PR-comment template and durable knowledge note.

This PR carries the remaining consistency fix found while scrutinizing the actual merge diff: add external requests to the CLAUDE.md security-risk examples so the canonical hard gate matches the scrutinize and security-review skills.

Verification

Contract check passes 10 of 10 assertions. The actual merge diff is one documentation file and git diff --check is clean.

Security classification

Security-review is not required for this diff. It changes process documentation only and does not alter runtime authentication, authorization, RLS, secrets, privileged writes, external requests, uploads, webhooks, untrusted input, or privileged clients.

ไทย

การเปลี่ยนแปลงหลักของ #118 อยู่บน master แล้ว เพราะ process Wave 3 ที่ทำงานพร้อมกัน commit ไฟล์ review ที่ stage ไว้ และ PR #119 merge commit นั้นเข้า master ปัจจุบัน master จึงมี:

  • การบังคับรายงาน scrutinize ภาษาอังกฤษและภาษาไทยฉบับเต็มเป็น comment ใน PR;
  • หลักฐาน base/head, commit ที่ review และ URL ของ comment;
  • การทำให้หลักฐานเดิม stale เมื่อ HEAD เปลี่ยน;
  • การเรียก security-review เมื่อ diff แตะ trust boundary;
  • template comment สองภาษาและ knowledge note ถาวร

PR นี้เหลือ consistency fix ที่พบระหว่าง scrutinize actual merge diff: เพิ่ม external requests ในตัวอย่าง security risk ของ CLAUDE.md เพื่อให้ canonical hard gate ตรงกับ scrutinize และ security-review skills

การยืนยันผล

Contract check ผ่าน 10 จาก 10 ข้อ Actual merge diff มีเอกสารเพียงหนึ่งไฟล์ และ git diff --check ผ่าน

การจัดประเภท Security

ไม่ต้องทำ security-review สำหรับ diff นี้ เพราะแก้เฉพาะเอกสารกระบวนการ และไม่เปลี่ยน runtime authentication, authorization, RLS, secret, privileged write, external request, upload, webhook, untrusted input หรือ privileged client

Copilot AI review requested due to automatic review settings July 22, 2026 23:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@vercel

vercel Bot commented Jul 22, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
t4-fastwork-nestjs Canceled Canceled Jul 22, 2026 11:32pm
t4-fastwork-nextjs Canceled Canceled Jul 22, 2026 11:32pm

@xenodeve

Copy link
Copy Markdown
Collaborator Author

Scrutinize review evidence

PR: #120
Base: master@0c0c210d18ad105c785e483904417d13ea06db44
Head/reviewed commit: feat/scrutinize-pr-evidence-118@74dc6f9ff69e23dbc4f0861d3e800313b769a427
Merge base: 0c0c210

English

  • Intent and simpler alternative: The current merge diff aligns the canonical pre-merge security classifier with the scrutinize and security-review skills by adding external requests to the explicit risk examples. Doing nothing would leave two authoritative instructions classifying the same diff differently. A three-line documentation edit is the smallest sufficient fix; no automation or runtime layer is needed.
  • Traced paths: Repository task starts at CLAUDE.md → pre-merge gate classifies the actual merge diff → an external-request change now invokes security-review → security findings or residual risks are included in the same bilingual PR evidence. The canonical scrutinize skill already on master separately requires the PR comment, reviewed SHA, stale-evidence handling, and EN/TH mirror.
  • Findings and suggested changes: No remaining findings in the reviewed merge diff. The earlier inconsistency between the skill and CLAUDE.md is exactly what this one-file diff fixes.
  • Verification: Reviewed git diff origin/master...HEAD and unchanged code around the gate. The actual merge diff contains only CLAUDE.md. git diff --check passes. The contract check passes 10/10: PR comment evidence, full EN/TH report, reviewed commit identity, comment URL, security trigger, external-request parity, stale-review invalidation, bilingual template, canonical reinforcement, and knowledge-note reachability.
  • Security review: Not required for this diff. It changes process documentation only; no runtime authentication, authorization/RLS, admin or privileged write, secret, upload, webhook, untrusted input, external request implementation, network policy, or privileged client is changed. Residual risk: enforcement remains procedural rather than hook-enforced, but stale-SHA and comment-URL evidence make skipped or stale review visible.
  • Verdict: Ship from the scrutinize perspective. The separate code-review gate still applies before merge.

ไทย

  • เป้าหมายและทางเลือกที่ง่ายกว่า: Actual merge diff ปัจจุบันทำให้ security classifier ในกฎ pre-merge หลักตรงกับ scrutinize และ security-review skills โดยเพิ่ม external requests ลงในตัวอย่างความเสี่ยงอย่างชัดเจน หากไม่แก้ เอกสาร authoritative สองแห่งจะจัดประเภท diff เดียวกันไม่ตรงกัน การแก้เอกสารสามบรรทัดเป็นวิธีที่เล็กและเพียงพอที่สุด ไม่ต้องเพิ่ม automation หรือ runtime layer
  • เส้นทางที่ตรวจ: งานใน repo เริ่มจาก CLAUDE.md → pre-merge gate จัดประเภท actual merge diff → งานที่แตะ external request จะเรียก security-review → findings หรือ residual risks ถูกใส่ในหลักฐาน PR สองภาษาเดียวกัน ส่วน canonical scrutinize skill ที่อยู่บน master แล้วบังคับ PR comment, reviewed SHA, การ invalid หลักฐาน stale และรายงาน EN/TH ฉบับเต็ม
  • Findings และข้อเสนอแก้ไข: ไม่พบ finding ที่เหลืออยู่ใน merge diff ที่ตรวจ ความไม่ตรงกันเดิมระหว่าง skill กับ CLAUDE.md คือสิ่งที่ diff หนึ่งไฟล์นี้แก้โดยตรง
  • การยืนยันผล: ตรวจ git diff origin/master...HEAD และโค้ดรอบกฎที่ไม่เปลี่ยน Actual merge diff มีเพียง CLAUDE.md, git diff --check ผ่าน และ contract check ผ่าน 10/10 ได้แก่ หลักฐาน PR comment, รายงาน EN/TH ครบ, reviewed commit identity, comment URL, security trigger, external-request parity, stale-review invalidation, bilingual template, canonical reinforcement และ knowledge-note reachability
  • Security review: ไม่จำเป็นสำหรับ diff นี้ เพราะแก้เฉพาะเอกสารกระบวนการ ไม่เปลี่ยน runtime authentication, authorization/RLS, admin หรือ privileged write, secret, upload, webhook, untrusted input, implementation ของ external request, network policy หรือ privileged client ความเสี่ยงคงเหลือคือ gate ยังบังคับด้วยวินัย ไม่ใช่ hook แต่หลักฐาน SHA และ comment URL ทำให้การข้าม review หรือใช้ review เก่ามองเห็นได้
  • Verdict: ผ่านในมุม scrutinize และพร้อมส่งต่อ โดยยังต้องผ่าน code-review ซึ่งเป็น gate แยกก่อน merge

@xenodeve

Copy link
Copy Markdown
Collaborator Author

Scrutinize — docs-only leftover for #118

Intent

Align CLAUDE.md security-risk examples with scrutinize/security-review (external requests). Core #118 already on master via #119.

Verdict

ship — documentation-only; no runtime path.


Scrutinize (TH)

เอกสารอย่างเดียว — ship

Security-review: not required (process docs only; stated in PR body).

@xenodeve
xenodeve merged commit e9cb16c into master Jul 23, 2026
4 checks passed
@xenodeve
xenodeve deleted the feat/scrutinize-pr-evidence-118 branch July 23, 2026 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(review): require bilingual scrutinize evidence in PRs

2 participants