witan-batch-1787098861529-336882

Date
Run
unknown @ 946812bdec8faf6598fed154a8d611ead612b6fd
Rubric
witan-rubric-v17-2026-07-24
2.4/4.0 overall

At risk

Code 2.0 · Process 2.8

code 2/5 · process 4/6 measured · low confidence

Criterion profile

Measured scores are plotted on a 0–4 scale. Unknown and not-applicable dimensions remain explicit.

6 measured 1 no data 4 N/A

Code trust

A1Test integrity and regression signal
1.8
A2Data-layer isolation and secrets posture
N/A
A3Production readiness
N/A
A4Dependency hygiene
No data
A5Claim-vs-reality reconciliation
2.2

Process trust

B1Internal process dimension
N/A
B2PR outcome traceability
4.0
B3CI and QA discipline
0.6
B4Audit trail and report-up completeness
2.5
B5Internal process dimension
N/A
B6Privileged-operation human gating
4.0

Code trust

A1

Test integrity and regression signal

dimension band: warning
1.8
  • Test-to-source file ratio53 ratio (capped; 163 raw)
  • Static coverage percentage0/100 percent
  • Verification script ratio0/4 ratio
  • Non-hollow test share77/78 ratio
  • Detected test file rack-protection/spec/lib/rack/protection/authenticity_token_spec.rb:1 · sha256:eee1d74a3ff0
  • Detected test file rack-protection/spec/lib/rack/protection/base_spec.rb:1 · sha256:0f86f660571f
  • Detected test file rack-protection/spec/lib/rack/protection/content_security_policy_spec.rb:1 · sha256:a6836f158b55
  • Detected test file rack-protection/spec/lib/rack/protection/cookie_tossing_spec.rb:1 · sha256:27c39fd3a46f
  • Detected test file rack-protection/spec/lib/rack/protection/escaped_params_spec.rb:1 · sha256:ee75320b93ad
  • Detected test file rack-protection/spec/lib/rack/protection/form_token_spec.rb:1 · sha256:b89f75a7d0c1
  • Detected test file rack-protection/spec/lib/rack/protection/frame_options_spec.rb:1 · sha256:55698f06865a
  • Detected test file rack-protection/spec/lib/rack/protection/host_authorization_spec.rb:1 · sha256:3aea586a6342
  • finding severity warning: A1 dimension band is warning at 1.8/4.0. Lowest contributing measurements: Static coverage percentage 0/100 percent; Verification script ratio 0/4 ratio. To improve: configure coverage and publish a measured threshold or report; add explicit test, lint, and typecheck verification commands. (Detected test file rack-protection/spec/lib/rack/protection/authenticity_token_spec.rb:1 · sha256:eee1d74a3ff0)
A4

Dependency hygiene

dimension band: insufficient_data
No data
  • No measured depth metrics supplied.
  • No concrete evidence supplied.
A5

Claim-vs-reality reconciliation

dimension band: warning
2.2
  • Claim match rate12/13 ratio
  • Claim source depth1/4 docs
  • Reconciliation artifact depth0/3 artifacts
  • Repository claim source README.md:1 · sha256:7c8cdf9819db
  • Code presence for claim reconciliation lib/sinatra.rb:1 · sha256:7c3157fd3ea7
  • finding severity warning: Claim source and implementation files are present, but no dedicated claim-reality report artifact was supplied. (Repository claim source README.md:1 · sha256:7c8cdf9819db)

Not applicable to this repository

  • A2 Data-layer isolation and secrets posture — No data layer (DB/ORM/migrations) or ratable secrets surface detected — A2 not applicable to this repo archetype. A ratable surface requires .env* files, .gitignore .env rule, committed/history .env path, or detected signing/HMAC/secret-comparison code; bare env reads (process.env / os.environ / std::env::) do not qualify.
  • A3 Production readiness — No deployable-service surface detected — production-readiness not applicable to this library/CLI archetype. Signals checked: production server entrypoint (HTTP/RPC port binding in main/server/app files, outside examples/tests/demo dirs), deploy config (vercel.json, render.yaml, fly.toml, Procfile, app.yaml, serverless.yml, docker-compose, k8s/helm manifests), CI deploy job (fly deploy, kubectl apply, helm install/upgrade, docker push). A Dockerfile without an explicit runtime start/service command is ambiguous and does not qualify.

Process trust

B2

PR outcome traceability

dimension band: verified
4.0
  • PR trace basic checks2 signals (capped; 3 raw)
  • Recent PR merge ratio1/1 ratio
  • Pull-request CI workflow .github/workflows/release.yml:1 · sha256:cc493a1c4dc2
  • Pull-request CI workflow .github/workflows/test.yml:1 · sha256:99756d90f358
  • Review gate configuration .github/workflows/CODEOWNERS:1 · sha256:682a996b6856
B3

CI and QA discipline

dimension band: warning
0.6
  • CI verification depth0/4 signals
  • PR-gate CI workflow count1/4 workflows
  • CI workflow .github/workflows/release.yml:1 · sha256:cc493a1c4dc2
  • finding severity warning: B3 dimension band is warning at 0.6/4.0. Lowest contributing measurements: CI verification depth 0/4 signals; PR-gate CI workflow count 1/4 workflows. To improve: run the repository verification commands in CI; run CI on the default branch and pull requests. (CI workflow .github/workflows/release.yml:1 · sha256:cc493a1c4dc2)
B4

Audit trail and report-up completeness

dimension band: verified
2.5
  • Audit artifact depth2/3 files
  • Audit freshness depth1/2 ratio
  • Audit or changelog artifact CHANGELOG.md:1 · sha256:21e2a2928d51
  • Audit or changelog artifact SECURITY.md:1 · sha256:0a317e90d1c1
B6

Privileged-operation human gating

dimension band: verified
4.0
  • Privilege-escalation cleanliness1/1 clean
  • Protected-path review gate1/1 present
  • CODEOWNERS/required-review gate on protected paths .github/workflows/CODEOWNERS:1 · sha256:682a996b6856

Not applicable to this repository

  • B1 Internal process dimension — Substrate-specific: an internal process dimension is not applicable to external code.
  • B5 Internal process dimension — Substrate-specific: an internal process dimension is not applicable to external code.

Verified evidence

  • B2 - PR outcome traceabilityPull-request CI workflow .github/workflows/release.yml:1 · sha256:cc493a1c4dc2
  • B2 - PR outcome traceabilityPull-request CI workflow .github/workflows/test.yml:1 · sha256:99756d90f358
  • B2 - PR outcome traceabilityReview gate configuration .github/workflows/CODEOWNERS:1 · sha256:682a996b6856
  • B4 - Audit trail and report-up completenessAudit or changelog artifact CHANGELOG.md:1 · sha256:21e2a2928d51
  • B4 - Audit trail and report-up completenessAudit or changelog artifact SECURITY.md:1 · sha256:0a317e90d1c1
  • B6 - Privileged-operation human gatingCODEOWNERS/required-review gate on protected paths .github/workflows/CODEOWNERS:1 · sha256:682a996b6856

Open / unverified

  • A1 - Test integrity and regression signalfinding severity warning: A1 dimension band is warning at 1.8/4.0. Lowest contributing measurements: Static coverage percentage 0/100 percent; Verification script ratio 0/4 ratio. To improve: configure coverage and publish a measured threshold or report; add explicit test, lint, and typecheck verification commands. (Detected test file rack-protection/spec/lib/rack/protection/authenticity_token_spec.rb:1 · sha256:eee1d74a3ff0)
  • A4 - Dependency hygieneInsufficient data — no measurable signal; excluded from composite.
  • A5 - Claim-vs-reality reconciliationfinding severity warning: Claim source and implementation files are present, but no dedicated claim-reality report artifact was supplied. (Repository claim source README.md:1 · sha256:7c8cdf9819db)
  • B3 - CI and QA disciplinefinding severity warning: B3 dimension band is warning at 0.6/4.0. Lowest contributing measurements: CI verification depth 0/4 signals; PR-gate CI workflow count 1/4 workflows. To improve: run the repository verification commands in CI; run CI on the default branch and pull requests. (CI workflow .github/workflows/release.yml:1 · sha256:cc493a1c4dc2)