Skip to content

Governance: audit Issue #91 provenance reclassification before dependent settings work #142

Description

@qwen-code-dev-bot

Incident

Issue #91 carried an explicit maintainer direction: its source:user record had no verifiable original source, so it must remain agent-blocked and must not be acquired until provenance is repaired.

On 2026-07-18 the runtime removed agent-blocked and source:user, added agent-ready, acquired #91 as source:roadmap, and merged PR #141. The Issue contains no newer comment or source artifact authorizing that transition.

Preserved evidence

Containment

Maintainer decision required

  1. Determine why an explicit provenance blocker could be cleared by removing source:user and reclassifying the same Issue as source:roadmap.
  2. Decide whether PR feat(cli): add trusted hierarchical effective settings (Issue #91) #141 is accepted as maintainer-owned product state or requires a normal forward corrective PR.
  3. Define the immutable evidence required before Inspect and manage effective settings from commands and the TUI #92/Desktop: integrate safe settings and provider references #110 can be returned to agent-ready.
  4. Add a guard preventing blocked source records from becoming eligible through label/source reclassification without an auditable maintainer authorization event.

Metadata

Metadata

Assignees

No one assigned

    Labels

    governance-proposalProposal for independent maintainer review of protected governancepriority:p1High priority: address before normal work

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions