Point the shut reporting route at the file that holds its state - #207
Merged
iderex merged 1 commit intoAug 27, 2026
Merged
Conversation
SECURITY.md named the private reporting form as the destination, said in the same breath that the form does not answer, and then sent the reader to issue #57 for the moment it opens. #57 closed as completed on the alternative its own done-when offered, the parity row, rather than on the setting, so the form is still off and a reporter following the pointer met a finished piece of work and nothing telling them the door is shut. That reads as the door having been opened, which is the opposite of the two sentences around the pointer. The paragraph now names the setting rather than an issue and points at docs/parity.md, which carries that setting with the reason and is a tracked file rather than a tracker row that can close underneath it. What the file admits is unchanged: the form does not answer today, and the public issue with as little detail as the report can carry is still written down as the poor arrangement it is. The reading pasted above the paragraph was re-run at this commit and the date moved with it. Found while reading #62, whose last clause waits on the same setting and whose own done-when does not reach this file. Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com>
iderex
deleted the
security/the-pointer-for-a-shut-route-names-a-closed-issue
branch
August 27, 2026 02:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #206.
SECURITY.mdnamed the private reporting form as where a report goes, said inthe same breath that the form does not answer, and then sent the reader to issue
#57 for the moment it opens. #57 closed as completed on the second half of its
own done-when - the parity row for each setting left off - rather than on the
setting, so the form is still shut and the pointer resolves to a finished piece
of work. A reporter who follows it reads the door as opened, which is the
opposite of the two sentences around the pointer, and this is the one document in
the tree read by somebody deciding in that moment whether to report privately or
in public.
What was wrong, at
origin/mainAll three run 2026-08-27, the first against
63b4c2b.What the change does
The paragraph names the setting rather than an issue, and points at
docs/parity.md, which carries that setting with its reason and is a trackedfile rather than a tracker row that can close underneath the sentence:
No closed issue is named for the route any more:
The destination the paragraph now points at is in the tree at this commit:
The reading pasted above the paragraph was taken again at this commit rather than
carried over, which is why the date moved with it. The command and its output are
unchanged, because the setting is unchanged.
The negative disclosure is not weakened
What the file admits, it still admits and in the same words: the form does not
answer today, the paragraph says so before it says anything else, and the public
issue with as little detail as the report can carry is still written down as the
poor arrangement it is. Nothing here turns any of that into an assurance. The
only sentence that moved is the one saying where the state is held.
What this does not do
It does not turn the setting on. That is a repository setting rather than a
change to this tree, it is unmeasured by anything here, and #206 is written not
to ask for it. The row in
docs/parity.mdgoes on holding the gap.It does not touch #62, whose last clause waits on the same setting. That issue's
done-when reaches four things and none of them is this file, which is how the
defect came to be sitting in a comment with no tracker row behind it.
The means
Prose in the tracked Markdown file that already carries the rule, edited in
place. The artefact is a document a person reads, the change is one paragraph of
it, and no other means would carry the same sentence to the same reader; adding a
language, a format or a generator step for one paragraph would cost the tree
something and buy nothing.
The gate, at this commit
What no leg decides here
The
linksleg reads references inside the site the build produced. This file isrepository documentation and no page of the built site carries it, so the
reference added here is decided by no leg of the gate. I resolved it by hand with
the
git ls-treeabove, and a later edit that breaks it would be refused bynothing.
needs-networkwas not asked for. Nothing in this change reads the network, andthe two tracker readings above were taken with
ghat a terminal rather than byanything in the tree.
No second reader
This change has not been read by a second person, and merging it is not evidence
that it has: the ruleset on the branch requires no approving review, so the pull
request is merged by the account that opened it. The evidence above stands in
place of that reading, and the whole of the change is seven lines of one
paragraph in one file.