SYS.21 / FINDINGS
The Finding Engine
Deterministic detectors across six pillars. No model is involved at any stage, and there is deliberately no score.
Four grades, because there are four questions
A reader who cannot tell them apart will act on the wrong one.
| Axis | Answers | Values |
|---|---|---|
| category | Which pillar this belongs to | SECURITY · SUPPLY_CHAIN · ARCHITECTURE · QUALITY · TESTING · DELIVERY |
| severity | How bad it would be if true | CRITICAL · HIGH · MEDIUM · LOW · INFO |
| verdict | What the rule concluded | FAIL · WARN · PASS · UNKNOWN · NOT_SUPPORTED |
| confidence | How it was established — see Grounding | VERIFIED · INFERRED · UNKNOWN |
There is no score
"Project Health: 82/100" is the shape this refuses.
A number blending "runs as root" with "one unused dependency" is a number nobody can act on, and it hides the thing that matters most: whether the check ran at all.
What you get instead is a list of detectors with their statuses above the findings — and that order is the point. Twelve findings from four detectors with two failed is a different document from twelve findings from six that all succeeded, and only one of them is a reason to relax.
What it takes to earn a PASS
The most expensive verdict in the system. Three rules can currently earn one.
- No committed credential files
- Every path was classified and none was credential material. It states its own limit in the summary: it checked filenames and classifications, not contents.
- No circular imports
- The resolved import graph has no strongly connected component — and the graph is complete, with no parse failures and no ingestion cap.
- No known advisories
- The feed answered and reported nothing, for the versions it was able to check, at a stated timestamp, from a stated source.
Some rules can never emit a PASS by design. Proving "no export is unreferenced" needs a type checker and a module resolver, and this engine has neither — so it says so instead of implying it.
The detectors that exist
And the honest limit each one carries.
| Detector | Pillar | Its stated limit |
|---|---|---|
| Insecure configuration | SECURITY | Reports what a container or workflow file says, never what the deployment does |
| Secret exposure | SECURITY | Checks classifications, not contents — a credential pasted into a source file is invisible to it |
| Dependency hygiene | SUPPLY_CHAIN | npm fully, Python for name-only rules; other ecosystems are NOT_SUPPORTED rather than partially analysed |
| Known vulnerabilities | SUPPLY_CHAIN | Exact versions only; an unreachable feed is UNKNOWN, never silence |
| Import cycles | ARCHITECTURE | JS/TS only. Type-only imports are excluded — they create no runtime cycle |
| Dead exports | QUALITY | TypeScript only, and only above a parse-coverage floor. Never emits a PASS |
Why the noisy rules are graded low
The three rules that would make this tool ignorable if they were wrong.
Potential unused dependencyis a warning, inferred, at the lowest severity. Six ordinary patterns defeat static import analysis — plugins loaded by name, config-only usage, dynamic imports, peer dependencies, type-only packages, CLI tools in scripts — and the rule declines to run at all below a parse-coverage floor.Possibly unreferenced exportexcludes entry points, framework conventions, barrels, tests, package APIs and types, and declines to run below a higher floor still.Unpinned third-party actionis a warning and never a failure. A tag-pinned action is a real exposure and a completely normal thing to find; calling it a failure would put an accusation next to standard practice.
Findings over time
Where a chart is most likely to lie.
- A finding counts as resolved only when the detector that raised it ran again and succeeded without it. Anything that vanished because its detector crashed is listed separately as unaccounted for.
- A snapshot where a detector failed has fewer findings *recorded*, not fewer findings — so the trend is drawn as a break in the line with the reason beside it, never as a lower number.
- Hotspots list only files that already carry a finding, ranked with what the graph measured about them. Churn and reach are multipliers on an established risk, never a source of one.