Evidence record / paperclip

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-09-21-paperclip-carry-forward-the-review-policy-lock-and-cwe-78-cli-guidance-reached-stable-in-v2026-824

Carry-forward: the review-policy lock and CWE-78 CLI guidance reached stable in v2026.824.0. The release body lists “Review governance”: verdicts are serialized and transactional, a verdict can no longer bypass a policy by downgrading, the requester is persisted atomically (#11405, #10938). “Security hardening” lists CLI guidance routed through the safe npx form (#11400), plus a cross-tenant ID oracle on tool-access routes, routine webhook HMAC replay, and “the heartbeat-fallback comment can never publish a raw transcript” (#11343 among the listed PRs). The release calls itself the first stable to walk canary, nightly, beta, stable end to end.

Channel: tagged-release. Half: defect (closed). Date: 2026-08-25 (GitHub publish; release body says “Released: 2026-08-24”).

Operator consequence: Operators pinned to @beta for these fixes can return to @latest. Anyone still on v2026.817.0 lacks the review-policy lock; upgrade. The four-lane train is now demonstrated, not only documented: a beta SHA becoming stable unchanged is the evidence.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-paperclip-carry-forward-the-review-policy-lock-and-cwe-78-cli-guidance-reached-stable-in-v2026-824

Profile citations

  • Paperclip / claim / review-policy-lock-stable

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact