witan-batch-1787098845348-975021

Date
Run
unknown @ 916bfc57fa7431467a33a5a013cba3f8a0c1ec50
Rubric
witan-rubric-v17-2026-07-24
2.9/4.0 overall

Conditional

Code 2.2 · Process 3.6

code 4/5 · process 3/6 measured

Criterion profile

Measured scores are plotted on a 0–4 scale. Unknown and not-applicable dimensions remain explicit.

7 measured 0 no data 4 N/A

Code trust

A1Test integrity and regression signal
1.9
A2Data-layer isolation and secrets posture
N/A
A3Production readiness
1.8
A4Dependency hygiene
2.3
A5Claim-vs-reality reconciliation
2.6

Process trust

B1Internal process dimension
N/A
B2PR outcome traceability
4.0
B3CI and QA discipline
2.7
B4Audit trail and report-up completeness
N/A
B5Internal process dimension
N/A
B6Privileged-operation human gating
4.0

Code trust

A1

Test integrity and regression signal

dimension band: verified
1.9
  • Test-to-source file ratio16 ratio (capped; 271 raw)
  • Static coverage percentage0/100 percent
  • Verification script ratio1/4 ratio
  • Non-hollow test share186/270 ratio
  • Detected test file attestor/command/cli_test.go:1 · sha256:8e75726c5f60
  • Detected test file attestor/policy/attestation_policy_test.go:1 · sha256:19eaa945cbbf
  • Detected test file checker/check_request_test.go:1 · sha256:a10638fb8687
  • Detected test file checker/check_result_test.go:1 · sha256:63b3271d70f1
  • Detected test file checker/client_test.go:1 · sha256:aae06114bff9
  • Detected test file checker/detail_logger_impl_test.go:1 · sha256:241c41f2e7b1
  • Detected test file checker/raw_result_test.go:1 · sha256:5631de1e13f8
  • Detected test file checks/all_checks_test.go:1 · sha256:5f18978bddad
  • Configured test runner Makefile:1 · sha256:de7ddc3cf5c3
  • finding severity info: Test suite files are present, but no coverage configuration was detected. (Detected test file attestor/command/cli_test.go:1 · sha256:8e75726c5f60)
A3

Production readiness

dimension band: warning
1.8
  • Production-readiness basic checks2/6 checks
  • Production workflow depth6 signals (capped; 34 raw)
  • Observability depth3/4 signals
  • Rollback and migration-safety depth0/4 signals
  • CI workflow .github/workflows/codeql-analysis.yml:1 · sha256:491d592bcf1e
  • Release deploy configuration cron/k8s/auth.yaml:1 · sha256:17c8371d0cd0
  • Container build configuration Dockerfile:1 · sha256:e12b8b4c85f4
  • finding severity warning: A3 dimension band is warning at 1.8/4.0. Lowest contributing measurements: Rollback and migration-safety depth 0/4 signals; Production-readiness basic checks 2/6 checks. To improve: document and test rollback or recovery procedures; add the missing deployment-readiness controls. (CI workflow .github/workflows/codeql-analysis.yml:1 · sha256:491d592bcf1e)
A4

Dependency hygiene

dimension band: verified
2.3
  • Pinned dependency ratio0/822 ratio
  • Lockfile coverage1/1 present
  • Dependency automation ratio1/2 ratio
  • Dependency manifest tools/go.mod:1 · sha256:64cc61a2ee08
  • Dependency lockfile go.sum:1 · sha256:52c2296d72dd
  • Dependency update config .github/dependabot.yml:1 · sha256:6dedf4004d9a
A5

Claim-vs-reality reconciliation

dimension band: info
2.6
  • Claim match rate12/20 ratio
  • Claim source depth4 docs (capped; 8 raw)
  • Reconciliation artifact depth0/3 artifacts
  • Repository claim source README.md:1 · sha256:8fed8241afd3
  • Code presence for claim reconciliation cmd/internal/nuget/client.go:1 · sha256:04a66196afee
  • Documented limitations / threat model / "not covered" section docs/osps-baseline-coverage.md:1 · sha256:4a6356f1184a
  • finding severity info: Claim source and implementation files are present; no dedicated claim-reality report artifact was supplied, but the repo explicitly documents what it does NOT cover/protect against — honest scoping, not overclaiming. (Repository claim source README.md:1 · sha256:8fed8241afd3)

Not applicable to this repository

  • A2 Data-layer isolation and secrets posture — No data layer (DB/ORM/migrations) or ratable secrets surface detected — A2 not applicable to this repo archetype. A ratable surface requires .env* files, .gitignore .env rule, committed/history .env path, or detected signing/HMAC/secret-comparison code; bare env reads (process.env / os.environ / std::env::) do not qualify.

Process trust

B2

PR outcome traceability

dimension band: verified
4.0
  • PR trace basic checks2 signals (capped; 16 raw)
  • Recent PR merge ratio1/1 ratio
  • Pull-request CI workflow .github/workflows/codeql-analysis.yml:1 · sha256:491d592bcf1e
  • Pull-request CI workflow .github/workflows/depsreview.yml:1 · sha256:b5f2fd32e61b
  • Pull-request CI workflow .github/workflows/docker.yml:1 · sha256:83df290e4d6e
  • Pull request template .github/PULL_REQUEST_TEMPLATE.md:1 · sha256:97111f8601a6
  • Review gate configuration .github/CODEOWNERS:1 · sha256:32bebdd16341
B3

CI and QA discipline

dimension band: verified
2.7
  • CI verification depth1/4 signals
  • PR-gate CI workflow count4 workflows (capped; 10 raw)
  • CI workflow .github/workflows/codeql-analysis.yml:1 · sha256:491d592bcf1e
B6

Privileged-operation human gating

dimension band: verified
4.0
  • Privilege-escalation cleanliness1/1 clean
  • Protected-path review gate1/1 present
  • CODEOWNERS/required-review gate on protected paths .github/CODEOWNERS:1 · sha256:32bebdd16341

Not applicable to this repository

  • B1 Internal process dimension — Substrate-specific: an internal process dimension is not applicable to external code.
  • B4 Audit trail and report-up completeness — Only a static security-policy artifact (e.g. SECURITY.md) was detected — no committed CHANGELOG/CHANGES/HISTORY/NEWS/AUDIT/STATUS/release-notes/runbook/provenance file to rate for an audit trail. The project may publish release history outside the repository (e.g. GitHub Releases). B4 has no ratable surface here; it is excluded rather than scored.
  • B5 Internal process dimension — Substrate-specific: an internal process dimension is not applicable to external code.

Verified evidence

  • A1 - Test integrity and regression signalDetected test file attestor/command/cli_test.go:1 · sha256:8e75726c5f60
  • A1 - Test integrity and regression signalDetected test file attestor/policy/attestation_policy_test.go:1 · sha256:19eaa945cbbf
  • A1 - Test integrity and regression signalDetected test file checker/check_request_test.go:1 · sha256:a10638fb8687
  • A1 - Test integrity and regression signalDetected test file checker/check_result_test.go:1 · sha256:63b3271d70f1
  • A1 - Test integrity and regression signalDetected test file checker/client_test.go:1 · sha256:aae06114bff9
  • A1 - Test integrity and regression signalDetected test file checker/detail_logger_impl_test.go:1 · sha256:241c41f2e7b1
  • A1 - Test integrity and regression signalDetected test file checker/raw_result_test.go:1 · sha256:5631de1e13f8
  • A1 - Test integrity and regression signalDetected test file checks/all_checks_test.go:1 · sha256:5f18978bddad
  • A1 - Test integrity and regression signalConfigured test runner Makefile:1 · sha256:de7ddc3cf5c3
  • A4 - Dependency hygieneDependency manifest tools/go.mod:1 · sha256:64cc61a2ee08
  • A4 - Dependency hygieneDependency lockfile go.sum:1 · sha256:52c2296d72dd
  • A4 - Dependency hygieneDependency update config .github/dependabot.yml:1 · sha256:6dedf4004d9a
  • B2 - PR outcome traceabilityPull-request CI workflow .github/workflows/codeql-analysis.yml:1 · sha256:491d592bcf1e
  • B2 - PR outcome traceabilityPull-request CI workflow .github/workflows/depsreview.yml:1 · sha256:b5f2fd32e61b
  • B2 - PR outcome traceabilityPull-request CI workflow .github/workflows/docker.yml:1 · sha256:83df290e4d6e
  • B2 - PR outcome traceabilityPull request template .github/PULL_REQUEST_TEMPLATE.md:1 · sha256:97111f8601a6
  • B2 - PR outcome traceabilityReview gate configuration .github/CODEOWNERS:1 · sha256:32bebdd16341
  • B3 - CI and QA disciplineCI workflow .github/workflows/codeql-analysis.yml:1 · sha256:491d592bcf1e
  • B6 - Privileged-operation human gatingCODEOWNERS/required-review gate on protected paths .github/CODEOWNERS:1 · sha256:32bebdd16341

Open / unverified

  • A3 - Production readinessfinding severity warning: A3 dimension band is warning at 1.8/4.0. Lowest contributing measurements: Rollback and migration-safety depth 0/4 signals; Production-readiness basic checks 2/6 checks. To improve: document and test rollback or recovery procedures; add the missing deployment-readiness controls. (CI workflow .github/workflows/codeql-analysis.yml:1 · sha256:491d592bcf1e)
  • A5 - Claim-vs-reality reconciliationfinding severity info: Claim source and implementation files are present; no dedicated claim-reality report artifact was supplied, but the repo explicitly documents what it does NOT cover/protect against — honest scoping, not overclaiming. (Repository claim source README.md:1 · sha256:8fed8241afd3)