Waits outlive statuses
RISK-F-0001 is fixed and still owes a publication entry; it fell out of the waiting list because that list was built from watched findings only. A closed record with an open obligation is exactly the thing that goes quiet, since nothing prompts anyone to look at it any more. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
ce8fb70afd
commit
d3aefefdc0
3 changed files with 16 additions and 3 deletions
|
|
@ -102,6 +102,16 @@ independent of the blockage. `docs/method/verification.md` bounds what this repo
|
|||
can establish itself, and every grade resting on a document rather than a probe
|
||||
says so on its face.
|
||||
|
||||
## Waits outlive statuses
|
||||
|
||||
A finding that is `fixed` can still owe something. `RISK-F-0001` was closed on
|
||||
2026-08-19 and is still waiting on `policy-nexus` for the publication entry
|
||||
that turns `disclosure: public` into an actual address.
|
||||
|
||||
So the waiting list is built from **every** finding, not from the watched ones.
|
||||
A closed record with an open obligation is precisely the thing that goes quiet,
|
||||
because nothing is prompting anyone to look at it any more.
|
||||
|
||||
## Where the waits are visible
|
||||
|
||||
`make check` reports every open wait with its age, its owner and its default
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue