From 935d0a553209e5feaf0f4be5f372999d93c161a3 Mon Sep 17 00:00:00 2001 From: REPPL <77722411+REPPL@users.noreply.github.com> Date: Fri, 9 Oct 2026 08:04:05 +0100 Subject: [PATCH 1/2] chore: capture the post-release postmortem and the drain's blind spot for advisories Two records the product thinker asked for after the v0.13.3 cut: nothing checks after a release that every problem a run's logs record was captured, and the drain never sees security advisories submitted through the forge's private reporting, which cannot be copied into the public ledger as they are. Refs: iss-2610090703513626, iss-2610090703514921 Assisted-by: Claude:claude-opus-5-5 --- ...elease-nothing-checks-that-every-problem-an.md | 15 +++++++++++++++ ...nly-the-issue-ledger-so-security-advisories.md | 15 +++++++++++++++ 2 files changed, 30 insertions(+) create mode 100644 .abcd/work/issues/open/iss-2610090703513626-after-a-release-nothing-checks-that-every-problem-an.md create mode 100644 .abcd/work/issues/open/iss-2610090703514921-a-drain-reads-only-the-issue-ledger-so-security-advisories.md diff --git a/.abcd/work/issues/open/iss-2610090703513626-after-a-release-nothing-checks-that-every-problem-an.md b/.abcd/work/issues/open/iss-2610090703513626-after-a-release-nothing-checks-that-every-problem-an.md new file mode 100644 index 000000000..67a09db03 --- /dev/null +++ b/.abcd/work/issues/open/iss-2610090703513626-after-a-release-nothing-checks-that-every-problem-an.md @@ -0,0 +1,15 @@ +--- +schema_version: 1 +id: "iss-2610090703513626" +slug: "after-a-release-nothing-checks-that-every-problem-an" +severity: "minor" +category: "process" +source: "user-observation" +found_during: "2026-10-09 product thinker request after the v0.13.3 cut" +origin: researcher-authored +production_mode: hand-written +found_at: "commands/reflect.md" +remedy: "Add an automatic post-release postmortem: once a tag is cut, read the run logs written since the previous tag, extract each stop, slip, observation and autonomy-gap line, match it against the ledger as capture's filing-time match does, and list the unmatched ones for capture (or capture them with 'none (filed automatically)' for a person's remedy), so reflect or the release flow ends with nothing unrecorded." +--- + +After a release, nothing checks that every problem an autonomous run met was captured. The run logs under .abcd/.work.local/logs/ (for example the 2026-10-07 cleanup-and-bugfix-cut log) record each stop, slip, observation and autonomy gap, but turning them into issues was a manual pass the product thinker had to ask for after v0.13.3, and it found ten defects and five records owed new evidence. diff --git a/.abcd/work/issues/open/iss-2610090703514921-a-drain-reads-only-the-issue-ledger-so-security-advisories.md b/.abcd/work/issues/open/iss-2610090703514921-a-drain-reads-only-the-issue-ledger-so-security-advisories.md new file mode 100644 index 000000000..400bbbe8d --- /dev/null +++ b/.abcd/work/issues/open/iss-2610090703514921-a-drain-reads-only-the-issue-ledger-so-security-advisories.md @@ -0,0 +1,15 @@ +--- +schema_version: 1 +id: "iss-2610090703514921" +slug: "a-drain-reads-only-the-issue-ledger-so-security-advisories" +severity: "minor" +category: "security" +source: "user-observation" +found_during: "2026-10-09 product thinker request after the v0.13.3 cut" +origin: researcher-authored +production_mode: hand-written +found_at: "commands/drain.md" +remedy: "Waits on the product thinker's ruling on how private advisories enter the drain's view: list them in the drain's plan from the forge without their content and always hand them back; keep a private mirror outside the public ledger that the drain reads; or file a content-free placeholder issue per advisory that the drain can route." +--- + +A drain reads only the issue ledger, so security advisories that others submit through the forge's private vulnerability reporting never reach it. Unpublished advisories are not named by any record, so nothing in abcd shows whether they were triaged. They cannot simply be copied into the ledger as issues, because the ledger is public and an advisory stays private until it is fixed; and even a ledger issue in the security category is handed back by the drain under its default rule. From d068101548b5310dc405d52a1536c289c0b83cc0 Mon Sep 17 00:00:00 2001 From: REPPL <77722411+REPPL@users.noreply.github.com> Date: Fri, 9 Oct 2026 08:40:18 +0100 Subject: [PATCH 2/2] chore: capture that ideate should keep verdicts private until published The product thinker treats every idea put through ideate as secret, but ideate record writes its verdict straight into the committed research notes and decision log. Refs: iss-2610090740139804 Assisted-by: Claude:claude-opus-5-5 --- ...cord-writes-every-verdict-straight-into-the.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 .abcd/work/issues/open/iss-2610090740139804-abcd-ideate-record-writes-every-verdict-straight-into-the.md diff --git a/.abcd/work/issues/open/iss-2610090740139804-abcd-ideate-record-writes-every-verdict-straight-into-the.md b/.abcd/work/issues/open/iss-2610090740139804-abcd-ideate-record-writes-every-verdict-straight-into-the.md new file mode 100644 index 000000000..18c614327 --- /dev/null +++ b/.abcd/work/issues/open/iss-2610090740139804-abcd-ideate-record-writes-every-verdict-straight-into-the.md @@ -0,0 +1,15 @@ +--- +schema_version: 1 +id: "iss-2610090740139804" +slug: "abcd-ideate-record-writes-every-verdict-straight-into-the" +severity: "minor" +category: "ux" +source: "user-observation" +found_during: "2026-10-09 product thinker capture" +origin: researcher-authored +production_mode: hand-written +found_at: "commands/ideate.md" +remedy: "Make ideate record write the verdict to the person's home store first, ~/.abcd.noindex/ideas//-ideate-.md (owner-only, keyed on the repository's root commit like the history and transcript stores), with no DECISIONS.md line; add an explicit publish step (for example 'abcd ideate publish ') that moves a chosen verdict into the research notes and writes the decision-log pointer, and say in commands/ideate.md that nothing reaches the repository until then." +--- + +abcd ideate record writes every verdict straight into the repository: a research note under .abcd/development/research/notes/ and a pointer line in .abcd/work/DECISIONS.md, both committed and public once pushed. The product thinker treats every idea put through ideate as secret: an idea and the sources it came from are kept private first and enter the repository only when the person decides it should.