47 posts went live on verdicts that said the post needed work. A failed blog cron was traced to a publish gate that treated a missing verdict as approval, with an allowlist bug underneath it that had published 47 posts.
The allowlist bug underneath
The allowlist bug had published 47 posts on verdicts that said the post needed work.
Four live posts to correct
I corrected four live posts. One of them was teaching a backwards git rule.
I also hardened the scrub, the model-egress path and the landed drops, and centralized the model pricing figures, which had drifted into five files.
Residual gaps are still open and tracked in their own ticket.
Three states, not two
A publish gate needs three states: approved, rejected and unknown. Unknown has to block. If your check is written as “fail when a bad verdict is present,” it approves by absence.
AI Skills
Use this lesson with the AI assistant you already use
A failed blog cron led to a publish gate that treated a missing verdict as approval. Tracing it showed 47 posts had gone live even though their verdicts said the post needed work.
Paste the prompt, share only the context needed to answer it, and treat the result as a draft for your review. Do not include confidential information or let an AI assistant make changes without your approval.
Optional: for a visual report and saved memory, run /dxdev first.
Don’t have it? Get it at dxdev.com/skills/dxdev. The prompt works without it.
dxdev LESSON · paste into your AI coding agent
LESSON: A Publish Gate Must Block On Unknown Verdicts, Not Only On Bad Ones
SOURCE: dxdev.com/blog/2026-09-08_publish-gate-missing-verdict-approval
WHAT HAPPENED: Chasing a failed blog cron through a 41-hour session led to a publish gate with a bad default: a post with no verdict was treated as approved. Fixing that was not the whole problem. An allowlist bug underneath the gate had let through the 47 posts that did have verdicts on file saying they needed work. So the gate had two separate ways to ship something a reviewer had held back, one by absence and one by an explicit needs-work verdict. Four live posts had to be corrected, and one of them taught a backwards git rule. The same pass hardened the scrub, the model-egress path and the landed drops, and centralized model pricing figures that had drifted into five files.
THE RULE: A publish gate needs three states, approved, rejected and unknown, and unknown must block. Write the check as requiring positive approval rather than failing only when a bad verdict is present.
CHECK MY CODE, then report PASS or FAIL with file:line for each:
1. Confirm that a post with no verdict on file is blocked from publishing rather than treated as approved.
2. Confirm that a post whose verdict says it needs work is blocked, including when it passes through any allowlist or exemption path.
3. Periodically count what was published against the verdicts on file and flag any published post whose verdict is missing or not an approval.
THEN PRINT: a table (check, PASS/FAIL, evidence, fix) + a verdict (applies / partially / OUT_OF_SCOPE / no) + the single most important next action.