Skip to content

[pull] main from PaulDuvall:main#3

Merged
pull[bot] merged 1 commit into
TheTechOddBug:mainfrom
PaulDuvall:main
Dec 1, 2025
Merged

[pull] main from PaulDuvall:main#3
pull[bot] merged 1 commit into
TheTechOddBug:mainfrom
PaulDuvall:main

Conversation

@pull

@pull pull Bot commented Dec 1, 2025

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Add new experimental pattern addressing the "self-grading student" problem
where AI can weaken tests to pass buggy code.

Pattern Features:
- Immutable golden tests (tests/golden/) vs mutable generated tests
- Defense-in-depth enforcement with explicit threat model
- CI/CD git diff detection as primary enforcement
- CODEOWNERS as final human approval gate

Key Insight:
File permissions (444) alone are INSUFFICIENT - AI with bash access can
bypass using chmod. The pattern explicitly documents this limitation and
relies on CI/CD + CODEOWNERS as primary enforcement mechanisms.

Complete Implementation:
- Pattern documentation in experiments/README.md
- Working example in experiments/examples/test-promotion/
- Promotion workflow scripts with quality checklist
- CI/CD enforcement blocking golden test modifications
- AI hooks providing defense-in-depth
- CODEOWNERS requiring human approval
- THREAT-MODEL.md documenting all attack vectors

Anti-patterns:
- Mutable Baselines: Allowing AI to modify tests
- Permission-Only Protection: Relying solely on file permissions

Related Patterns: Testing Orchestration, Spec-Driven Development, Suite Health

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
@pull pull Bot locked and limited conversation to collaborators Dec 1, 2025
@pull pull Bot added the ⤵️ pull label Dec 1, 2025
@pull pull Bot merged commit f05e5df into TheTechOddBug:main Dec 1, 2025
6 of 7 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant