Use when a cve-sync sync run (locally, the sync bumper action, or an escalation issue it opened) reports a conflict or a violation. Walks through reading the failure output, inspecting uv tree to find the real cause, deciding between a floor, an override, an exclude, or a manual pin, applying the fix in the right repo (the cve-sync repo's policy/ or the target repo itself), and re-running the gate to confirm it is actually fixed. Triggers on cve-sync conflict, cve-sync violation, a cve-sync-escalation issue, or "resolve-cve-conflict".
2026-07-15