A clear view of the latest published pull-request evaluation.
ORANGE
Advisory controls need attention
No enforced controls are configured, so the policy decision is not gated by any control and every result is advisory. It does not establish mergeability or release readiness.
The totals count 16 active checks. Of the 33 built-in checks listed below, 16 are active and 17 are not activated. Only active checks count toward the totals. See all checks ↓
Evidence results
Control outcomes, separated from unavailable evidence
Controls
Passed
Failed
Blocked
Unverified
All active controls
15
0
0
1
Enforced
0
0
0
0
Advisory
15
0
0
1
Failed means a reported failure. Blocked means the producer reported a blocker. Unverified means no usable result was available.
Every check, visible
Individual checks
All built-in catalog checks. Select a check to see its purpose and evidence below. Not reported means no validated row in this snapshot; it does not imply disabled or passed. A dash means the check has no active mode in this snapshot. Custom controls may contribute to totals without publishing their private names.
Checks needing attention come first. Source report links open the evaluation run containing the detailed evidence.
Dependency Vulnerability dependency-vulnerability
Unverified
Detect known vulnerabilities in resolved dependencies
Advisory
No usable evidence was available. This is not a passing result.
Assessment criteria
Assessment criteria and available detail
Assessment
Resolved dependency vulnerabilities
Evaluates
Known vulnerabilities in the resolved dependency graph
Expected result
Findings satisfy the configured severity and exception policy
Execution time
Not supplied by this source report
Counts not reported
Only the overall result is reported. Snyk Open Source counts appear when the Snyk workflow packages them; the FOSSA adapter does not export finding counts. Open the pull request's provider check or the provider project for findings by severity.
Validate repository-owned contracts and configuration
Advisory
Ran for 7s · completed
4 passed · 0 failed · 0 not run (4 contract groups)Self-reported by the pull request's own workflow run; not independently verified and never used for the result.
Assessment criteria
Assessment criteria and available detail
Assessment
Installed Proof contracts
Evaluates
Installed runtime files, Semgrep self-test fixtures, schemas, and the control catalog, profiles, providers, and policy
Expected result
Every contract group validates; the first failure stops the run
Started (UTC)
2026-10-05T03:12:37Z
Completed (UTC)
2026-10-05T03:12:44Z
Execution time
7s (7 seconds)
Producer conclusion
success
Self-reported measurements
4 passed · 0 failed · 0 not run (4 contract groups)
Validate documentation structure, links, and declared targets
Advisory
Ran for 7s · completed
171 Markdown files · 232 local links checked · 0 broken · 0 documentation mapping failuresSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.
Assessment criteria
Assessment criteria and available detail
Assessment
Documentation integrity
Evaluates
Local Markdown links, declared documentation targets, and required documentation updates for changed files
Expected result
No broken local links and every documentation mapping is satisfied
Validate declared repository architecture and engineering documents
Advisory
Ran for 5s · completed
6 of 6 declared documents found · 0 missingSelf-reported by the pull request's own workflow run; not independently verified and never used for the result.
Assessment criteria
Assessment criteria and available detail
Assessment
Declared engineering ground truth
Evaluates
Documents declared in .proof/ground-truth-ai.yaml, such as agent instructions and architecture, testing, security, and contribution guides
Expected result
Every declared document exists in the repository; document contents are not assessed
Counted changes exclude the configured path patterns. Binary files: 0 counted; 0 excluded. Binary contents have no line count. File paths are not published.
Validate pull-request title and body requirements against mutable PR state
Advisory
Title matches the required format · 1 of 1 required section presentEvaluated by the trusted base-branch PR metadata validator. The title, description, and section names are not published.
Assessment criteria
Assessment criteria and available detail
Assessment
PR title and description
Evaluates
Configured title pattern and required description sections; title and description text are not published
Expected result
Title matches the configured pattern and every required section is present
Execution time
Not supplied by this source report
Evaluated
Title matches the required format · 1 of 1 required section present
Verify repository formatting and lint rules with the repository-owned command
Advisory
Ran for 11s · completed
Assessment criteria
Assessment criteria and available detail
Assessment
Formatting and lint rules
Evaluates
Repository-configured formatter and lint command
Expected result
Configured command completes successfully
Started (UTC)
2026-10-05T03:12:38Z
Completed (UTC)
2026-10-05T03:12:49Z
Execution time
11s (11 seconds)
Producer conclusion
success
Counts not reported
Only the command's exit status is reported. This repository supplies the command, so counts such as files checked, errors, warnings depend on its tools; open the source report for their output.
Detect compilation, packaging, and build-time regressions
Advisory
Ran for 9s · completed
Assessment criteria
Assessment criteria and available detail
Assessment
Build and packaging
Evaluates
Repository-configured build command
Expected result
Build command completes successfully
Started (UTC)
2026-10-05T03:12:38Z
Completed (UTC)
2026-10-05T03:12:47Z
Execution time
9s (9 seconds)
Producer conclusion
success
Counts not reported
Only the command's exit status is reported. This repository supplies the command, so counts such as artifacts produced, build errors depend on its tools; open the source report for their output.
805 passed · 0 failed · 0 skipped (805 tests)Self-reported by the pull request's own workflow run; not independently verified and never used for the result.
Assessment criteria
Assessment criteria and available detail
Assessment
Automated unit tests
Evaluates
Repository-configured test command and selected test suites
No measurable changed lines · target 90%Self-reported by the pull request's own workflow run; not independently verified and never used for the result.
Assessment criteria
Assessment criteria and available detail
Assessment
Coverage of changed code
Evaluates
Executable changed lines compared with repository coverage policy
Expected result
Changed-line coverage meets the repository-configured threshold
Review security and license risk introduced by dependency changes
Advisory
Ran for 7s · completed
Assessment criteria
Assessment criteria and available detail
Assessment
Dependency changes
Evaluates
New or changed dependencies and associated security/license risk
Expected result
Changes satisfy the configured dependency review policy
Started (UTC)
2026-10-05T03:12:38Z
Completed (UTC)
2026-10-05T03:12:45Z
Execution time
7s (7 seconds)
Producer conclusion
success
Counts not reported
Only the overall result is reported. GitHub Dependency Review writes changed dependencies, new vulnerabilities, and license violations to its own job summary; open the pull request's Dependency Review check for them.
Checked elsewhere, not activated, or not reported (17)
Not activated checks are excluded from the active-control totals.
Static Quality static-quality
Not activated
Evaluate maintainability, reliability, and static quality gates
Not activated for this evaluation. Excluded from active-control totals.
Assessment criteria
Assessment criteria and available detail
Assessment
Static quality gate
Evaluates
Maintainability, reliability, and quality rules from the selected provider
Expected result
Provider quality gate satisfies its configured policy
Execution time
Not supplied by this source report
Counts not reported
Only the quality-gate result is reported. SonarQube keeps quality-gate conditions, bugs, code smells, and duplication on the SonarQube server; open the project there for them.
Evaluate dependency licenses against repository policy
Not activated for this evaluation. Excluded from active-control totals.
Assessment criteria
Assessment criteria and available detail
Assessment
Dependency license policy
Evaluates
Detected dependency licenses and configured allow/deny rules
Expected result
Licenses satisfy the configured compliance policy
Execution time
Not supplied by this source report
Counts not reported
Only the overall result is reported. The FOSSA adapter does not yet export license counts; open the pull request's FOSSA check or the FOSSA project for them.
Review correctness, architecture, maintainability, and regression risk
Not activated for this evaluation. Excluded from active-control totals.
Assessment criteria
Assessment criteria and available detail
Assessment
Engineering review dimensions
Evaluates
Correctness, architecture, maintainability, and regression risk
Expected result
Advisory review completes with a documented disposition
Execution time
Not supplied by this source report
Counts not reported
Only the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.
Review tests, edge cases, failure paths, and assertions
Not activated for this evaluation. Excluded from active-control totals.
Assessment criteria
Assessment criteria and available detail
Assessment
Test adequacy review
Evaluates
Test assertions, edge cases, failure paths, and coverage gaps
Expected result
Advisory review completes with a documented disposition
Execution time
Not supplied by this source report
Counts not reported
Only the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.
Review authentication, isolation, injection, secrets, and privilege risks
Not activated for this evaluation. Excluded from active-control totals.
Assessment criteria
Assessment criteria and available detail
Assessment
Security review dimensions
Evaluates
Authentication, isolation, injection, secrets, and privilege boundaries
Expected result
Advisory review completes with a documented disposition
Execution time
Not supplied by this source report
Counts not reported
Only the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.
AI Repository Standards Review ai-repository-standards-review
Not activated
Review changes against repository-owned engineering ground truth
Not activated for this evaluation. Excluded from active-control totals.
Assessment criteria
Assessment criteria and available detail
Assessment
Repository standards review
Evaluates
Changes compared with repository-owned engineering requirements
Expected result
Advisory review completes with a documented disposition
Execution time
Not supplied by this source report
Counts not reported
Only the overall result was reported. Finding counts appear only when an AI PR Review adapter packages its result file for this run; a native GitHub review posts findings as review comments instead. Open the source report for the review output.