Skip to content

security-ownership-map: fix five history and community defects #531

Description

@mtu-soft-matter

The curated security-ownership-map skill has five related correctness defects:

  1. community_maintainers.py implements --half-life-days as exp(-age / half_life), so an event one half-life old has weight e^-1 instead of 0.5.
  2. Author-exclusion options inspect the selected attribution identity. With committer attribution, bot-authored commits committed by a human are retained despite the documented author exclusion.
  3. community_maintainers.py --include-merges can silently use a default commits.jsonl cache that already omitted merges. The minimal fix bypasses the cache only when --include-merges is requested and preserves cache precedence otherwise.
  4. Included merge commits need --diff-merges=first-parent; otherwise their changed-file lists are empty or unsuitable for ownership attribution.
  5. When any co-change edge survives, eligible files without surviving edges are omitted from communities and graph JSON instead of receiving singleton communities.

A tested patch is available at mtu-soft-matter@c625c9b. The upstream repository currently disables pull requests.

Validation:

  • 11 standard-library regression tests cover all five defects
  • python3 -m unittest discover -s skills/.curated/security-ownership-map/tests -v
  • both modified scripts pass python3 -m py_compile
  • git diff --check passes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions