MR Sentinel

Audit log · ← dashboard

sgharlow/governance-demo-app!1

Verdict
pass
Score
10.0 / 10
Rubric
v2
Commit
2b02a8d8
Scored
2026-05-31 23:15:41 UTC

Rule outcomes (15)

RuleCategoryOutcomeSeverityControlsEvidence
contract-has-spec-linkcontract_specpasswarningCDPD-§3, ISO-27001-A.14.2.1MR description states: 'The placeholder file is intentionally trivial.', implicitly opting out of a formal spec link for this minor change.
no-commented-out-codequalitypassinfoSOC2-CC8.1The diff adds a markdown file, which does not contain commented-out code in a programming language context.
no-secrets-in-diffsecuritypassblockerSOC2-CC6.1, ISO-27001-A.9.4.3, OWASP-ASVS-V2No secret patterns were detected in the content of `demo/placeholder.md`.
no-skipped-tests-introducedqualitypasserrorSOC2-CC8.1No test files or test skipping patterns (e.g., `pytest.skip`) were found in the diff.
acceptance-criteria-testablecontract_specskipwarningCDPD-§5, SOC2-CC8.1No spec linked and no test files are present in the diff.
auth-on-new-public-endpointssecurityskipblockerSOC2-CC6.1, OWASP-ASVS-V1The diff only adds a markdown file; no new public endpoints were exposed.
changed-method-coveragequalityskiperrorSOC2-CC8.1, ISO-27001-A.14.2.8The diff only adds a markdown file; no code methods were modified or added.
dependency-advisory-checksecurityskipblockerSOC2-CC7.1, ISO-27001-A.12.6.1, NIST-SA-11The diff only adds a markdown file; no dependencies were added or modified.
error-budget-impact-declaredoperationalskipwarningSOC2-CC4.1The change is a new markdown file and does not impact a service with an SLO.
integration-boundaries-explicitcontract_specskipwarningCDPD-§6, ISO-27001-A.14.2.5The diff only adds a markdown file and does not cross any integration boundaries.
kill-switch-pathcontract_specskipwarningCDPD-§9, SOC2-CC7.5Adding a markdown file does not introduce or alter user-facing behavior requiring a kill switch.
mutation-resilience-critical-pathsqualityskipwarningSOC2-CC8.1The change is a new markdown file, not a critical path code file that would require mutation testing.
observability-on-new-endpointsoperationalskipwarningSOC2-CC7.2, ISO-27001-A.12.4.1The diff only adds a markdown file; no new HTTP/gRPC endpoints were introduced.
rollback-documented-for-migrationsoperationalskiperrorSOC2-CC7.5, ISO-27001-A.14.2.2The diff only adds a markdown file; no database migration files were added.
spec-implementation-matchcontract_specskiperrorCDPD-§7No spec is linked in the MR description to compare against the implementation.

Audit log (3)

WhenActorActionDetails
2026-06-01 00:10:00 UTCmr-sentinelskip_duplicate{"sha": "2b02a8d8", "reason": "already_evaluated", "rubric_version": "v2"}
2026-05-31 23:15:43 UTCmr-sentinelskip_duplicate{"sha": "2b02a8d8", "reason": "already_evaluated", "rubric_version": "v2"}
2026-05-31 23:15:42 UTCmr-sentinelevaluate{"score": 10.0, "note_id": 3403828717, "verdict": "pass", "tool_calls": 6, "rubric_source": "project_override", "comment_crea