AI Software Toolkitravisingh11/ai-software-toolkit
View repository

CI evidence / change assessment

Latest PR Scorecard

A clear view of the latest published pull-request evaluation.

ORANGE

Advisory controls need attention

No enforced controls are configured, so the policy decision is not gated by any control and every result is advisory. It does not establish mergeability or release readiness.

Policy decision
ALLOW
Advisory only

Needs attention

Active controls

15/16

controls passed

1 not passed

Enforced

0/0

controls passed

No controls configured

Advisory

15/16

controls passed

1 not passed

The totals count 16 active checks. Of the 33 built-in checks listed below, 16 are active and 17 are not activated. Only active checks count toward the totals. See all checks ↓

Evidence results

Control outcomes, separated from unavailable evidence
ControlsPassedFailedBlockedUnverified
All active controls15001
Enforced0000
Advisory15001

Failed means a reported failure. Blocked means the producer reported a blocker. Unverified means no usable result was available.

Every check, visible

Individual checks

All built-in catalog checks. Select a check to see its purpose and evidence below. Not reported means no validated row in this snapshot; it does not imply disabled or passed. A dash means the check has no active mode in this snapshot. Custom controls may contribute to totals without publishing their private names.

Check results and policy modes for this snapshot
CheckResultMode
Build & quality
Repository Validation repository-validationPassedAdvisory
Documentation Validation documentation-validationPassedAdvisory
Repository Ground Truth repository-ground-truthPassedAdvisory
PR Size change-scopePassedAdvisory
PR Metadata pr-metadataPassedAdvisory
Format and Lint format-and-lintPassedAdvisory
Migration Validation migration-validationPassedAdvisory
Build buildPassedAdvisory
Unit Tests unit-testsPassedAdvisory
Changed Code Coverage changed-code-coveragePassedAdvisory
Custom Static Analysis custom-static-analysisPassedAdvisory
Static Quality static-qualityNot activated—
Security & dependencies
Secret Detection secret-detectionPassedAdvisory
Deep SAST deep-sastPassedAdvisory
Dependency Change Review dependency-change-reviewPassedAdvisory
Platform Secret Protection platform-secret-protectionPassedAdvisory
Dependency Remediation dependency-remediationNot activated—
Dependency Vulnerability dependency-vulnerabilityUnverifiedAdvisory
License Compliance license-complianceNot activated—
IaC Misconfiguration iac-misconfigurationNot activated—
AI & QA
Functional QA functional-qaNot activated—
AI Engineering Review ai-engineering-reviewNot activated—
AI QA Review ai-qa-reviewNot activated—
AI Security Review ai-security-reviewNot activated—
AI Repository Standards Review ai-repository-standards-reviewNot activated—
Release & runtime
Artifact Provenance artifact-provenanceNot activated—
Runtime Soak runtime-soakNot activated—
Container Vulnerability container-vulnerabilityNot activated—
Artifact SBOM artifact-sbomNot activated—
Artifact Vulnerability artifact-vulnerabilityNot activated—
Deployment Policy deployment-policyNot activated—
Dynamic Application Security dynamic-application-securityNot activated—
Runtime Assurance runtime-assuranceNot activated—

Check details

Checks needing attention come first. Source report links open the evaluation run containing the detailed evidence.

Dependency Vulnerability dependency-vulnerability

Unverified

Detect known vulnerabilities in resolved dependencies

Advisory

No usable evidence was available. This is not a passing result.

Assessment criteria
Assessment criteria and available detail
AssessmentResolved dependency vulnerabilities
EvaluatesKnown vulnerabilities in the resolved dependency graph
Expected resultFindings satisfy the configured severity and exception policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result is reported. Snyk Open Source counts appear when the Snyk workflow packages them; the FOSSA adapter does not export finding counts. Open the pull request's provider check or the provider project for findings by severity.

Repository Validation repository-validation

Passed

Validate repository-owned contracts and configuration

Advisory

Ran for 7s · completed

4 passed · 0 failed · 0 not run (4 contract groups)Self-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentInstalled Proof contracts
EvaluatesInstalled runtime files, Semgrep self-test fixtures, schemas, and the control catalog, profiles, providers, and policy
Expected resultEvery contract group validates; the first failure stops the run
Started (UTC)2026-10-05T03:12:37Z
Completed (UTC)2026-10-05T03:12:44Z
Execution time7s (7 seconds)
Producer conclusionsuccess
Self-reported measurements4 passed · 0 failed · 0 not run (4 contract groups)

Documentation Validation documentation-validation

Passed

Validate documentation structure, links, and declared targets

Advisory

Ran for 7s · completed

171 Markdown files · 232 local links checked · 0 broken · 0 documentation mapping failuresSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentDocumentation integrity
EvaluatesLocal Markdown links, declared documentation targets, and required documentation updates for changed files
Expected resultNo broken local links and every documentation mapping is satisfied
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:12:45Z
Execution time7s (7 seconds)
Producer conclusionsuccess
Self-reported measurements171 Markdown files · 232 local links checked · 0 broken · 0 documentation mapping failures

Repository Ground Truth repository-ground-truth

Passed

Validate declared repository architecture and engineering documents

Advisory

Ran for 5s · completed

6 of 6 declared documents found · 0 missingSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentDeclared engineering ground truth
EvaluatesDocuments declared in .proof/ground-truth-ai.yaml, such as agent instructions and architecture, testing, security, and contribution guides
Expected resultEvery declared document exists in the repository; document contents are not assessed
Started (UTC)2026-10-05T03:12:37Z
Completed (UTC)2026-10-05T03:12:42Z
Execution time5s (5 seconds)
Producer conclusionsuccess
Self-reported measurements6 of 6 declared documents found · 0 missing

PR Size change-scope

Passed

Detect oversized or unexpectedly broad changes

Advisory

Ran for 0s · completed

Assessment criteria
Assessment criteria and available detail
AssessmentChange size
EvaluatesCounted files, added lines, changed lines, and maximum additions per file
Expected resultEach measurement is within its configured limit
Started (UTC)2026-10-05T03:12:43Z
Completed (UTC)2026-10-05T03:12:43Z
Execution time0s (0 seconds)
Producer conclusionsuccess

Files & lines of code

Large PRs can overwhelm human reviewers; smaller, focused PRs make feedback more actionable.

Exceeding a limit warns only; it does not block the policy decision.

Counted changes compared with the configured limits
MeasurementCountedLimitResult
Counted files212Within limit
Added lines44300Within limit
Added + deleted lines110500Within limit
Most added lines in one file39150Within limit

Total diff
5 files · 96 added lines · 163 added + deleted lines

Excluded from limits
3 files · 52 added lines · 53 added + deleted lines

Counted changes exclude the configured path patterns. Binary files: 0 counted; 0 excluded. Binary contents have no line count. File paths are not published.

PR Metadata pr-metadata

Passed

Validate pull-request title and body requirements against mutable PR state

Advisory

Title matches the required format · 1 of 1 required section presentEvaluated by the trusted base-branch PR metadata validator. The title, description, and section names are not published.

Assessment criteria
Assessment criteria and available detail
AssessmentPR title and description
EvaluatesConfigured title pattern and required description sections; title and description text are not published
Expected resultTitle matches the configured pattern and every required section is present
Execution timeNot supplied by this source report
EvaluatedTitle matches the required format · 1 of 1 required section present

Format and Lint format-and-lint

Passed

Verify repository formatting and lint rules with the repository-owned command

Advisory

Ran for 11s · completed

Assessment criteria
Assessment criteria and available detail
AssessmentFormatting and lint rules
EvaluatesRepository-configured formatter and lint command
Expected resultConfigured command completes successfully
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:12:49Z
Execution time11s (11 seconds)
Producer conclusionsuccess
Counts not reportedOnly the command's exit status is reported. This repository supplies the command, so counts such as files checked, errors, warnings depend on its tools; open the source report for their output.

Migration Validation migration-validation

Passed

Validate repository-specific database and data migration safety

Advisory

Ran for 13s · completed

No migrations found to checkSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentMigration safety
EvaluatesRepository-specific migration checks, or declared absence of migrations
Expected resultRepository migration validator succeeds
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:12:51Z
Execution time13s (13 seconds)
Producer conclusionsuccess
Self-reported measurementsNo migrations found to check

Build build

Passed

Detect compilation, packaging, and build-time regressions

Advisory

Ran for 9s · completed

Assessment criteria
Assessment criteria and available detail
AssessmentBuild and packaging
EvaluatesRepository-configured build command
Expected resultBuild command completes successfully
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:12:47Z
Execution time9s (9 seconds)
Producer conclusionsuccess
Counts not reportedOnly the command's exit status is reported. This repository supplies the command, so counts such as artifacts produced, build errors depend on its tools; open the source report for their output.

Unit Tests unit-tests

Passed

Detect functional regressions in changed behavior

Advisory

Ran for 11m 7s · completed

805 passed · 0 failed · 0 skipped (805 tests)Self-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentAutomated unit tests
EvaluatesRepository-configured test command and selected test suites
Expected resultTest command completes successfully
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:23:45Z
Execution time11m 7s (667 seconds)
Producer conclusionsuccess
Self-reported measurements805 passed · 0 failed · 0 skipped (805 tests)

Changed Code Coverage changed-code-coverage

Passed

Measure test coverage for changed code

Advisory

Ran for 12m 29s · completed

No measurable changed lines · target 90%Self-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentCoverage of changed code
EvaluatesExecutable changed lines compared with repository coverage policy
Expected resultChanged-line coverage meets the repository-configured threshold
Started (UTC)2026-10-05T03:12:37Z
Completed (UTC)2026-10-05T03:25:06Z
Execution time12m 29s (749 seconds)
Producer conclusionsuccess
Self-reported measurementsNo measurable changed lines · target 90%

Custom Static Analysis custom-static-analysis

Passed

Run repository and organization-specific static rules

Advisory

Ran for 6m 25s · completed

No findings reportedSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentCustom static rules
EvaluatesRepository and organization-specific analysis rules
Expected resultConfigured analyzer completes without policy-blocking findings
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:19:03Z
Execution time6m 25s (385 seconds)
Producer conclusionsuccess
Self-reported measurementsNo findings reported

Secret Detection secret-detection

Passed

Detect credentials and authentication material in source history

Advisory

Ran for 9s · completed

No findings reportedSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentSecrets in source history
EvaluatesCredential patterns in the configured scan scope
Expected resultScanner reports no policy-blocking secret findings
Started (UTC)2026-10-05T03:12:37Z
Completed (UTC)2026-10-05T03:12:46Z
Execution time9s (9 seconds)
Producer conclusionsuccess
Self-reported measurementsNo findings reported

Deep SAST deep-sast

Passed

Detect security vulnerabilities through semantic source analysis

Advisory

Ran for 1m 9s · completed

0 critical · 6 high · 0 medium · 0 lowSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.

Assessment criteria
Assessment criteria and available detail
AssessmentSemantic security analysis
EvaluatesData flow and security queries for configured languages
Expected resultSelected security analysis satisfies its configured policy
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:13:47Z
Execution time1m 9s (69 seconds)
Producer conclusionsuccess
Self-reported measurements0 critical · 6 high · 0 medium · 0 low

Dependency Change Review dependency-change-review

Passed

Review security and license risk introduced by dependency changes

Advisory

Ran for 7s · completed

Assessment criteria
Assessment criteria and available detail
AssessmentDependency changes
EvaluatesNew or changed dependencies and associated security/license risk
Expected resultChanges satisfy the configured dependency review policy
Started (UTC)2026-10-05T03:12:38Z
Completed (UTC)2026-10-05T03:12:45Z
Execution time7s (7 seconds)
Producer conclusionsuccess
Counts not reportedOnly the overall result is reported. GitHub Dependency Review writes changed dependencies, new vulnerabilities, and license violations to its own job summary; open the pull request's Dependency Review check for them.

Platform Secret Protection platform-secret-protection

Passed

Verify platform secret scanning and push protection

Advisory

Ran for 0s · completed

Assessment criteria
Assessment criteria and available detail
AssessmentPlatform protection settings
EvaluatesSecret scanning and push protection capability checks
Expected resultRequired platform protections are enabled and verified
Started (UTC)2026-10-05T03:12:44Z
Completed (UTC)2026-10-05T03:12:44Z
Execution time0s (0 seconds)
Producer conclusionsuccess
Counts not reportedOnly the overall result was reported. This report does not include secret scanning enabled, push protection enabled.

Checked elsewhere, not activated, or not reported (17)

Not activated checks are excluded from the active-control totals.

Static Quality static-quality

Not activated

Evaluate maintainability, reliability, and static quality gates

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentStatic quality gate
EvaluatesMaintainability, reliability, and quality rules from the selected provider
Expected resultProvider quality gate satisfies its configured policy
Execution timeNot supplied by this source report
Counts not reportedOnly the quality-gate result is reported. SonarQube keeps quality-gate conditions, bugs, code smells, and duplication on the SonarQube server; open the project there for them.

Dependency Remediation dependency-remediation

Not activated

Verify automated dependency security remediation is configured

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentRemediation configuration
EvaluatesAutomated dependency security update configuration
Expected resultRequired dependency remediation automation is configured
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include security updates enabled, configuration checks.

License Compliance license-compliance

Not activated

Evaluate dependency licenses against repository policy

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentDependency license policy
EvaluatesDetected dependency licenses and configured allow/deny rules
Expected resultLicenses satisfy the configured compliance policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result is reported. The FOSSA adapter does not yet export license counts; open the pull request's FOSSA check or the FOSSA project for them.

IaC Misconfiguration iac-misconfiguration

Not activated

Detect insecure infrastructure-as-code configuration

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentInfrastructure configuration
EvaluatesSecurity rules for infrastructure-as-code resources
Expected resultConfiguration satisfies the selected infrastructure policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include resources scanned, misconfigurations by severity.

Functional QA functional-qa

Not activated

Exercise the running application as a user to detect functional regressions in changed behavior

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentApplication behavior
EvaluatesConfigured user journeys and assertions against a running application
Expected resultExecuted QA scenarios meet the advisory scenario expectations
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include scenarios passed, failed, blocked, skipped.

AI Engineering Review ai-engineering-review

Not activated

Review correctness, architecture, maintainability, and regression risk

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentEngineering review dimensions
EvaluatesCorrectness, architecture, maintainability, and regression risk
Expected resultAdvisory review completes with a documented disposition
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.

AI QA Review ai-qa-review

Not activated

Review tests, edge cases, failure paths, and assertions

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentTest adequacy review
EvaluatesTest assertions, edge cases, failure paths, and coverage gaps
Expected resultAdvisory review completes with a documented disposition
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.

AI Security Review ai-security-review

Not activated

Review authentication, isolation, injection, secrets, and privilege risks

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentSecurity review dimensions
EvaluatesAuthentication, isolation, injection, secrets, and privilege boundaries
Expected resultAdvisory review completes with a documented disposition
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.

AI Repository Standards Review ai-repository-standards-review

Not activated

Review changes against repository-owned engineering ground truth

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentRepository standards review
EvaluatesChanges compared with repository-owned engineering requirements
Expected resultAdvisory review completes with a documented disposition
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.

Artifact Provenance artifact-provenance

Not activated

Attest where and how a release artifact was built

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentBuild provenance
EvaluatesAttestation tying a release artifact to its build source
Expected resultArtifact provenance satisfies the release policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include artifacts attested, verification failures.

Runtime Soak runtime-soak

Not activated

Detect runtime degradation, leaks, and performance drift over time

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentSustained runtime behavior
EvaluatesDegradation, resource leaks, errors, and performance drift over time
Expected resultObserved runtime stays within configured environment limits
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include test duration, error rate, latency, resource growth.

Container Vulnerability container-vulnerability

Not activated

Detect vulnerabilities in container images

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentContainer image security
EvaluatesVulnerabilities in the selected container image
Expected resultImage findings satisfy the configured vulnerability policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include images scanned, vulnerabilities by severity.

Artifact SBOM artifact-sbom

Not activated

Record the software components contained in an artifact

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentSoftware component inventory
EvaluatesSoftware components recorded in an artifact SBOM
Expected resultSBOM satisfies artifact inventory requirements
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include components recorded, missing metadata.

Artifact Vulnerability artifact-vulnerability

Not activated

Detect vulnerabilities in a built release artifact

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentRelease artifact security
EvaluatesVulnerabilities in a built release artifact
Expected resultArtifact findings satisfy the configured vulnerability policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include artifacts scanned, vulnerabilities by severity.

Deployment Policy deployment-policy

Not activated

Verify deployment approval and environment policy

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentDeployment authorization
EvaluatesApproval and environment-policy evidence
Expected resultDeployment satisfies required environment policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include approvals verified, policy violations.

Dynamic Application Security dynamic-application-security

Not activated

Detect vulnerabilities in a running application

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentRunning application security
EvaluatesSecurity checks against a deployed application
Expected resultRuntime security findings satisfy configured scan policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include endpoints scanned, vulnerabilities by severity.

Runtime Assurance runtime-assurance

Not activated

Verify runtime security and operational safeguards

Not activated for this evaluation. Excluded from active-control totals.

Assessment criteria
Assessment criteria and available detail
AssessmentOperational safeguards
EvaluatesRuntime security and operational control evidence
Expected resultSafeguards satisfy the configured environment policy
Execution timeNot supplied by this source report
Counts not reportedOnly the overall result was reported. This report does not include safeguards verified, policy violations.

Trace it to the evidence

Open the source CI run for the full scorecard, individual controls, and supporting results.

View source CI run
Source run
#37258502858 · attempt 1
Source created
Published
Operation
change
Verification details

Subject digestsha256:8eecd14c9fc2fcd69adf1e69d661e7792a567845cac246adcffe621f97eb2c87