Skip to content

Findings: lint outcomes from packages[].rules, inspect-evals-lint 0.9.0, IESC001 - #14

Merged
MattFisher merged 2 commits into
feat/findingsfrom
fix/lint-rule-outcomes
Sep 30, 2026
Merged

MattFisher merged 2 commits into
feat/findingsfrom
fix/lint-rule-outcomes

Conversation

@MattFisher

Copy link
Copy Markdown

Independent of the milestone-1 slices; small change on dev.

Bug. inspect-evals-lint writes outcomes only for rules that passed or skipped. A rule with diagnostics appears only under packages[].rules. The adapter read outcomes, so a failing rule never had an Outcome: runs_df always reported outcomes_fail = 0 for lint, rule-level coverage never named the failing rule, and a package whose remaining rules all skipped read as a skipped run and made the sweep exit 1. Verified on 0.9.0 against SciCode: rules 19 pass / 8 skip / 1 warn, outcomes 19 pass / 8 skip.

Fix. Outcomes come from rules when present, one per rule that ran at its worst status (warn and fail map to fail, as before) with a "N diagnostics" message; documents without rules fall back to outcomes unchanged. Findings are unchanged.

Also. The pin moves from 0.7.0 to 0.9.0. Its new IESC001 (sandbox_privileges: privileged mode, host mounts, extra capabilities in a compose file) is classified environment/major instead of the harness/minor default.

Tests: real 0.9.0 output for SciCode as a fixture; a failing rule gets an outcome and outcomes_fail counts it; a run with only failing and skipped rules is not a skip; the 0.7.0 fixture still parses via outcomes. Trial on SciCode with the new pin: IEBP007 | fail | 2 diagnostics, outcomes_fail = 1, run not skipped. Gate: pre-commit clean, basedpyright 0, 108 findings tests.

🤖 Generated with Claude Code

MattFisher and others added 2 commits September 30, 2026 14:12
…t-evals-lint 0.9.0; classify IESC001

Lint writes `outcomes` only for rules that passed or skipped, so a rule
with diagnostics never had an Outcome: runs_df always showed
outcomes_fail = 0 for lint, rule coverage never named the failing rule,
and a run whose other rules all skipped read as a skipped run and made
the sweep exit 1. Outcomes now come from `rules` (one per rule that ran,
at its worst status, with the diagnostic count) when present, falling
back to `outcomes` for documents written before 0.9.

The pin moves to 0.9.0. Its new IESC001 sandbox_privileges rule maps to
environment/major rather than the harness/minor default.

Fixture: real 0.9.0 output for scicode, root path redacted.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@MattFisher
MattFisher changed the base branch from dev/integrated-audits to feat/findings September 30, 2026 04:24
@MattFisher
MattFisher merged commit edd71e3 into feat/findings Sep 30, 2026
2 checks passed
@MattFisher
MattFisher deleted the fix/lint-rule-outcomes branch September 30, 2026 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant