witan-batch-1787098859538-502150

Date
Run
unknown @ adbc8813901bba65827259daa8e22ff94ec1f30e
Rubric
witan-rubric-v17-2026-07-24
2.5/4.0 overall

Conditional

Code 2.6 · Process 2.3

code 2/5 · process 2/6 measured · low confidence

Criterion profile

Measured scores are plotted on a 0–4 scale. Unknown and not-applicable dimensions remain explicit.

4 measured 1 no data 6 N/A

Code trust

A1Test integrity and regression signal
2.0
A2Data-layer isolation and secrets posture
N/A
A3Production readiness
N/A
A4Dependency hygiene
3.2
A5Claim-vs-reality reconciliation
No data

Process trust

B1Internal process dimension
N/A
B2PR outcome traceability
4.0
B3CI and QA discipline
0.6
B4Audit trail and report-up completeness
N/A
B5Internal process dimension
N/A
B6Privileged-operation human gating
N/A

Code trust

A1

Test integrity and regression signal

dimension band: verified
2.0
  • Test-to-source file ratio1 ratio (capped; 17 raw)
  • Static coverage percentage0/100 percent
  • Verification script ratio1/4 ratio
  • Non-hollow test share16/17 ratio
  • Detected test file active_help_test.go:1 · sha256:7ae9d42bd41c
  • Detected test file args_test.go:1 · sha256:37058f718eb5
  • Detected test file bash_completionsV2_test.go:1 · sha256:3cf7c192417f
  • Detected test file bash_completions_test.go:1 · sha256:7bb8b9de6c45
  • Detected test file cobra_test.go:1 · sha256:bb9a5a989701
  • Detected test file command_test.go:1 · sha256:710a689a1512
  • Detected test file completions_test.go:1 · sha256:3f8a8aabe2d2
  • Detected test file doc/cmd_test.go:1 · sha256:c016acceee91
  • Configured test runner Makefile:1 · sha256:880eb1cbfbfd
  • finding severity info: Test suite files are present, but no coverage configuration was detected. (Detected test file active_help_test.go:1 · sha256:7ae9d42bd41c)
A4

Dependency hygiene

dimension band: verified
3.2
  • Declared version range ratio4/5 ratio
  • Lockfile coverage1/1 present
  • Dependency automation ratio1/2 ratio
  • Dependency count sanity1/1 sane
  • Dependency manifest go.mod:1 · sha256:cc6098fd1118
  • Dependency lockfile go.sum:1 · sha256:e557d41a00d6
  • Dependency update config .github/dependabot.yml:1 · sha256:fce71f1c82f8
A5

Claim-vs-reality reconciliation

dimension band: insufficient_data
No data
  • No measured depth metrics supplied.
  • No concrete evidence supplied.

Not applicable to this repository

  • A2 Data-layer isolation and secrets posture — No data layer (DB/ORM/migrations) or ratable secrets surface detected — A2 not applicable to this repo archetype. A ratable surface requires .env* files, .gitignore .env rule, committed/history .env path, or detected signing/HMAC/secret-comparison code; bare env reads (process.env / os.environ / std::env::) do not qualify.
  • A3 Production readiness — No deployable-service surface detected — production-readiness not applicable to this library/CLI archetype. Signals checked: production server entrypoint (HTTP/RPC port binding in main/server/app files, outside examples/tests/demo dirs), deploy config (vercel.json, render.yaml, fly.toml, Procfile, app.yaml, serverless.yml, docker-compose, k8s/helm manifests), CI deploy job (fly deploy, kubectl apply, helm install/upgrade, docker push). A Dockerfile without an explicit runtime start/service command is ambiguous and does not qualify.

Process trust

B2

PR outcome traceability

dimension band: verified
4.0
  • PR trace basic checks2/2 signals
  • Recent PR merge ratio1/1 ratio
  • Pull-request CI workflow .github/workflows/labeler.yml:1 · sha256:c2ec854c684d
  • Pull-request CI workflow .github/workflows/test.yml:1 · sha256:22b2338c231c
B3

CI and QA discipline

dimension band: warning
0.6
  • CI verification depth0/4 signals
  • PR-gate CI workflow count1/4 workflows
  • CI workflow .github/workflows/labeler.yml:1 · sha256:c2ec854c684d
  • finding severity warning: B3 dimension band is warning at 0.6/4.0. Lowest contributing measurements: CI verification depth 0/4 signals; PR-gate CI workflow count 1/4 workflows. To improve: run the repository verification commands in CI; run CI on the default branch and pull requests. (CI workflow .github/workflows/labeler.yml:1 · sha256:c2ec854c684d)

Not applicable to this repository

  • B1 Internal process dimension — Substrate-specific: an internal process dimension is not applicable to external code.
  • B4 Audit trail and report-up completeness — Only a static security-policy artifact (e.g. SECURITY.md) was detected — no committed CHANGELOG/CHANGES/HISTORY/NEWS/AUDIT/STATUS/release-notes/runbook/provenance file to rate for an audit trail. The project may publish release history outside the repository (e.g. GitHub Releases). B4 has no ratable surface here; it is excluded rather than scored.
  • B5 Internal process dimension — Substrate-specific: an internal process dimension is not applicable to external code.
  • B6 Privileged-operation human gating — No privileged-operation surface (prod DB admin GRANT/privilege DDL, role escalation, or documented human-gate governance) detected in this repo.

Verified evidence

  • A1 - Test integrity and regression signalDetected test file active_help_test.go:1 · sha256:7ae9d42bd41c
  • A1 - Test integrity and regression signalDetected test file args_test.go:1 · sha256:37058f718eb5
  • A1 - Test integrity and regression signalDetected test file bash_completionsV2_test.go:1 · sha256:3cf7c192417f
  • A1 - Test integrity and regression signalDetected test file bash_completions_test.go:1 · sha256:7bb8b9de6c45
  • A1 - Test integrity and regression signalDetected test file cobra_test.go:1 · sha256:bb9a5a989701
  • A1 - Test integrity and regression signalDetected test file command_test.go:1 · sha256:710a689a1512
  • A1 - Test integrity and regression signalDetected test file completions_test.go:1 · sha256:3f8a8aabe2d2
  • A1 - Test integrity and regression signalDetected test file doc/cmd_test.go:1 · sha256:c016acceee91
  • A1 - Test integrity and regression signalConfigured test runner Makefile:1 · sha256:880eb1cbfbfd
  • A4 - Dependency hygieneDependency manifest go.mod:1 · sha256:cc6098fd1118
  • A4 - Dependency hygieneDependency lockfile go.sum:1 · sha256:e557d41a00d6
  • A4 - Dependency hygieneDependency update config .github/dependabot.yml:1 · sha256:fce71f1c82f8
  • B2 - PR outcome traceabilityPull-request CI workflow .github/workflows/labeler.yml:1 · sha256:c2ec854c684d
  • B2 - PR outcome traceabilityPull-request CI workflow .github/workflows/test.yml:1 · sha256:22b2338c231c

Open / unverified

  • A5 - Claim-vs-reality reconciliationInsufficient data — no measurable signal; excluded from composite.
  • B3 - CI and QA disciplinefinding severity warning: B3 dimension band is warning at 0.6/4.0. Lowest contributing measurements: CI verification depth 0/4 signals; PR-gate CI workflow count 1/4 workflows. To improve: run the repository verification commands in CI; run CI on the default branch and pull requests. (CI workflow .github/workflows/labeler.yml:1 · sha256:c2ec854c684d)