PROJECTSKILLSCONNECTING…

SYS.21 / FINDINGS

The Finding Engine

Deterministic detectors across six pillars. No model is involved at any stage, and there is deliberately no score.

What can be trusted6 SECTIONS

Four grades, because there are four questions

A reader who cannot tell them apart will act on the wrong one.

AxisAnswersValues
categoryWhich pillar this belongs toSECURITY · SUPPLY_CHAIN · ARCHITECTURE · QUALITY · TESTING · DELIVERY
severityHow bad it would be if trueCRITICAL · HIGH · MEDIUM · LOW · INFO
verdictWhat the rule concludedFAIL · WARN · PASS · UNKNOWN · NOT_SUPPORTED
confidenceHow it was established — see GroundingVERIFIED · INFERRED · UNKNOWN

There is no score

"Project Health: 82/100" is the shape this refuses.

A number blending "runs as root" with "one unused dependency" is a number nobody can act on, and it hides the thing that matters most: whether the check ran at all.

What you get instead is a list of detectors with their statuses above the findings — and that order is the point. Twelve findings from four detectors with two failed is a different document from twelve findings from six that all succeeded, and only one of them is a reason to relax.

What it takes to earn a PASS

The most expensive verdict in the system. Three rules can currently earn one.

No committed credential files
Every path was classified and none was credential material. It states its own limit in the summary: it checked filenames and classifications, not contents.
No circular imports
The resolved import graph has no strongly connected component — and the graph is complete, with no parse failures and no ingestion cap.
No known advisories
The feed answered and reported nothing, for the versions it was able to check, at a stated timestamp, from a stated source.

Some rules can never emit a PASS by design. Proving "no export is unreferenced" needs a type checker and a module resolver, and this engine has neither — so it says so instead of implying it.

The detectors that exist

And the honest limit each one carries.

DetectorPillarIts stated limit
Insecure configurationSECURITYReports what a container or workflow file says, never what the deployment does
Secret exposureSECURITYChecks classifications, not contents — a credential pasted into a source file is invisible to it
Dependency hygieneSUPPLY_CHAINnpm fully, Python for name-only rules; other ecosystems are NOT_SUPPORTED rather than partially analysed
Known vulnerabilitiesSUPPLY_CHAINExact versions only; an unreachable feed is UNKNOWN, never silence
Import cyclesARCHITECTUREJS/TS only. Type-only imports are excluded — they create no runtime cycle
Dead exportsQUALITYTypeScript only, and only above a parse-coverage floor. Never emits a PASS

Why the noisy rules are graded low

The three rules that would make this tool ignorable if they were wrong.

  • Potential unused dependency is a warning, inferred, at the lowest severity. Six ordinary patterns defeat static import analysis — plugins loaded by name, config-only usage, dynamic imports, peer dependencies, type-only packages, CLI tools in scripts — and the rule declines to run at all below a parse-coverage floor.
  • Possibly unreferenced export excludes entry points, framework conventions, barrels, tests, package APIs and types, and declines to run below a higher floor still.
  • Unpinned third-party action is a warning and never a failure. A tag-pinned action is a real exposure and a completely normal thing to find; calling it a failure would put an accusation next to standard practice.

Findings over time

Where a chart is most likely to lie.

  • A finding counts as resolved only when the detector that raised it ran again and succeeded without it. Anything that vanished because its detector crashed is listed separately as unaccounted for.
  • A snapshot where a detector failed has fewer findings *recorded*, not fewer findings — so the trend is drawn as a break in the line with the reason beside it, never as a lower number.
  • Hotspots list only files that already carry a finding, ranked with what the graph measured about them. Churn and reach are multipliers on an established risk, never a source of one.
DOCS23 CHAPTERS