test(security-review): verify /security-review path against fix-fork-secrets#1318
test(security-review): verify /security-review path against fix-fork-secrets#1318tejaskash wants to merge 2 commits into
Conversation
|
Claude Security Review: no high-confidence findings. (run) |
|
Per the PR description, this is a throwaway smoke-test PR not intended to be reviewed or merged — skipping a substantive code review. One meta-observation since I'm here: the bundled |
|
Claude Security Review: no high-confidence findings. (run) |
|
Closing — base-branch testing strategy doesn't work for pull_request_target (workflow always reads from default branch). Will verify the fixes in #1310 on a real PR after that merges. |
Throwaway PR for testing — do not merge, do not review.
Base =
fix-fork-secrets(PR #1310's branch) so the security review workflow that runs on this PR is the new one with bundled-slash-command + honest summary + cancel-in-progress=false. Verifies the inline-comment posting path before #1310 merges.The diff adds a single file with two deliberate findings the bundled
/security-reviewskill should flag (hardcoded AWS creds + command injection viaexec).Will close once verified.