DashboardpublishAlways require structured independent s…

Always require structured independent security reviews

Category: preference
Confidence: 0.80
ID: 01a082a3-9338-7440-8875-c4c803278811
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 1
Source session: 03hSgNx4eYWgSQny8
Created: 2026-09-08 20:09:13
Updated: 2026-09-08 20:09:13

Cross-Project Recalls

ProjectHitsLast recalled
opencode-lore 2 16h ago

Content

For sensitive workflow and release-automation changes, request a fresh, independent, read-only review of the exact current worktree before merge or handoff. Require reviewers to inspect current source lines and relevant tests across all approval, provenance, CI handoff, revocation, credential, pinning, and untrusted-context paths. Prohibit edits during review. Demand substantive findings ordered by severity using exact labels (MUST-FIX, CONCERN, PASS) with file:line citations, a compact test/evidence section, and a final unambiguous MERGE or DO-NOT-MERGE verdict. If inspection cannot be performed, require an explicit BLOCKED error and DO-NOT-MERGE.

Move to: