# Latest PR Scorecard

![ORANGE 15/16](proof-badge.svg)

| Field | Value |
| --- | --- |
| Repository | ravisingh11/ai-software-toolkit |
| Operation | change |
| Status | ORANGE |
| Active controls | 15/16 passed |
| Enforced | 0/0 passed |
| Advisory | 15/16 passed |
| Source run | [37258502858 attempt 1](https://github.com/ravisingh11/ai-software-toolkit/actions/runs/37258502858/attempts/1) |
| Source created | 2026-10-05T03:12:35Z |
| Published | 2026-10-08T06:12:09Z |
| Subject digest | sha256:8eecd14c9fc2fcd69adf1e69d661e7792a567845cac246adcffe621f97eb2c87 |

| Evidence results | Passed | Failed | Blocked | Unverified |
| --- | ---: | ---: | ---: | ---: |
| All active controls | 15 | 0 | 0 | 1 |
| Enforced | 0 | 0 | 0 | 0 |
| Advisory | 15 | 0 | 0 | 1 |

Failed means a reported failure. Blocked means the producer reported a blocker. Unverified means no usable result was available.

No enforced controls are configured, so the policy decision is not gated by any control and every result is advisory. It does not establish mergeability or release readiness.
This is a published PR snapshot. The source timestamp does not prove it matches the current PR head or current main.
Test totals, coverage, validator counts, and scanner finding counts, where shown, are self-reported by the pull request's own workflow run and are not independently verified. A scanner card without counts says where that scanner keeps its findings.

## PR Size · Files & LOC

Large PRs can overwhelm human reviewers; smaller, focused PRs make feedback more actionable.

Advisory — warns only; does not block the policy decision.

| Measurement | Counted | Limit | Result |
| --- | ---: | ---: | --- |
| Counted files | 2 | 12 | Within limit |
| Added lines | 44 | 300 | Within limit |
| Added + deleted lines | 110 | 500 | Within limit |
| Most added lines in one file | 39 | 150 | Within limit |

Total: 5 files; 96 added lines; 163 added + deleted lines.
Excluded: 3 files; 52 added lines; 53 added + deleted lines.
Binary files: 0 counted; 0 excluded. Binary contents have no line count.

## Individual checks

Every built-in catalog check is listed. Not reported means this snapshot has no validated row; it does not imply disabled or passed.

| Check | ID | Mode | Result | Purpose |
| --- | --- | --- | --- | --- |
| Repository Validation | `repository-validation` | Advisory | Passed | Validate repository-owned contracts and configuration |
| Documentation Validation | `documentation-validation` | Advisory | Passed | Validate documentation structure, links, and declared targets |
| Repository Ground Truth | `repository-ground-truth` | Advisory | Passed | Validate declared repository architecture and engineering documents |
| PR Size | `change-scope` | Advisory | Passed | Detect oversized or unexpectedly broad changes |
| PR Metadata | `pr-metadata` | Advisory | Passed | Validate pull-request title and body requirements against mutable PR state |
| Format and Lint | `format-and-lint` | Advisory | Passed | Verify repository formatting and lint rules with the repository-owned command |
| Migration Validation | `migration-validation` | Advisory | Passed | Validate repository-specific database and data migration safety |
| Build | `build` | Advisory | Passed | Detect compilation, packaging, and build-time regressions |
| Unit Tests | `unit-tests` | Advisory | Passed | Detect functional regressions in changed behavior |
| Functional QA | `functional-qa` | Not activated | Not activated | Exercise the running application as a user to detect functional regressions in changed behavior |
| Changed Code Coverage | `changed-code-coverage` | Advisory | Passed | Measure test coverage for changed code |
| Custom Static Analysis | `custom-static-analysis` | Advisory | Passed | Run repository and organization-specific static rules |
| Secret Detection | `secret-detection` | Advisory | Passed | Detect credentials and authentication material in source history |
| Deep SAST | `deep-sast` | Advisory | Passed | Detect security vulnerabilities through semantic source analysis |
| Dependency Change Review | `dependency-change-review` | Advisory | Passed | Review security and license risk introduced by dependency changes |
| Platform Secret Protection | `platform-secret-protection` | Advisory | Passed | Verify platform secret scanning and push protection |
| Dependency Remediation | `dependency-remediation` | Not activated | Not activated | Verify automated dependency security remediation is configured |
| Artifact Provenance | `artifact-provenance` | Not activated | Not activated | Attest where and how a release artifact was built |
| Static Quality | `static-quality` | Not activated | Not activated | Evaluate maintainability, reliability, and static quality gates |
| Dependency Vulnerability | `dependency-vulnerability` | Advisory | Unverified | Detect known vulnerabilities in resolved dependencies |
| License Compliance | `license-compliance` | Not activated | Not activated | Evaluate dependency licenses against repository policy |
| AI Engineering Review | `ai-engineering-review` | Not activated | Not activated | Review correctness, architecture, maintainability, and regression risk |
| AI QA Review | `ai-qa-review` | Not activated | Not activated | Review tests, edge cases, failure paths, and assertions |
| AI Security Review | `ai-security-review` | Not activated | Not activated | Review authentication, isolation, injection, secrets, and privilege risks |
| AI Repository Standards Review | `ai-repository-standards-review` | Not activated | Not activated | Review changes against repository-owned engineering ground truth |
| Runtime Soak | `runtime-soak` | Not activated | Not activated | Detect runtime degradation, leaks, and performance drift over time |
| Container Vulnerability | `container-vulnerability` | Not activated | Not activated | Detect vulnerabilities in container images |
| IaC Misconfiguration | `iac-misconfiguration` | Not activated | Not activated | Detect insecure infrastructure-as-code configuration |
| Artifact SBOM | `artifact-sbom` | Not activated | Not activated | Record the software components contained in an artifact |
| Artifact Vulnerability | `artifact-vulnerability` | Not activated | Not activated | Detect vulnerabilities in a built release artifact |
| Deployment Policy | `deployment-policy` | Not activated | Not activated | Verify deployment approval and environment policy |
| Dynamic Application Security | `dynamic-application-security` | Not activated | Not activated | Detect vulnerabilities in a running application |
| Runtime Assurance | `runtime-assurance` | Not activated | Not activated | Verify runtime security and operational safeguards |

### Self-reported measurements

Self-reported by the pull request's own workflow run; not independently verified and never used for the result.

- Repository Validation: 4 passed · 0 failed · 0 not run (4 contract groups)
- Documentation Validation: 171 Markdown files · 232 local links checked · 0 broken · 0 documentation mapping failures
- Repository Ground Truth: 6 of 6 declared documents found · 0 missing
- Migration Validation: No migrations found to check
- Unit Tests: 805 passed · 0 failed · 0 skipped (805 tests)
- Changed Code Coverage: No measurable changed lines · target 90%
- Custom Static Analysis: No findings reported
- Secret Detection: No findings reported
- Deep SAST: 0 critical · 6 high · 0 medium · 0 low

### PR metadata

Evaluated by the trusted base-branch PR metadata validator. The title, description, and section names are not published.

- PR Metadata: Title matches the required format · 1 of 1 required section present
