MR Sentinel

Audit log · ← dashboard

sgharlow/governance-demo-app!10

Verdict
block
Score
0.0 / 10
Rubric
v2
Commit
1fb25ad2
Scored
2026-05-19 05:11:40 UTC

Rule outcomes (15)

RuleCategoryOutcomeSeverityControlsEvidence
contract-has-spec-linkcontract_specfailwarningCDPD-§3, ISO-27001-A.14.2.1MR description is empty or only contains 'small fix'.
no-secrets-in-diffsecurityfailblockerSOC2-CC6.1, ISO-27001-A.9.4.3, OWASP-ASVS-V2`DATABASE_URL`, `JWT_SECRET`, `STRIPE_API_KEY`, `STRIPE_WEBHOOK_SECRET`, `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY` are all present in `.env.production`.
no-commented-out-codequalitypassinfoSOC2-CC8.1Comments in `.env.production` are descriptive, not commented-out code.
no-skipped-tests-introducedqualitypasserrorSOC2-CC8.1No test files in diff.
acceptance-criteria-testablecontract_specskipwarningCDPD-§5, SOC2-CC8.1No spec linked, no test diff.
auth-on-new-public-endpointssecurityskipblockerSOC2-CC6.1, OWASP-ASVS-V1No new public endpoints added.
changed-method-coveragequalityskiperrorSOC2-CC8.1, ISO-27001-A.14.2.8No code changes, only a new configuration file.
dependency-advisory-checksecurityskipblockerSOC2-CC7.1, ISO-27001-A.12.6.1, NIST-SA-11No dependencies added or upgraded.
error-budget-impact-declaredoperationalskipwarningSOC2-CC4.1The diff adds a configuration file, not code directly impacting service SLOs.
integration-boundaries-explicitcontract_specskipwarningCDPD-§6, ISO-27001-A.14.2.5The diff adds environment variables, not new API endpoints or message bus definitions that would require contract documentation in the diff.
kill-switch-pathcontract_specskipwarningCDPD-§9, SOC2-CC7.5This MR adds configuration, not user-facing behavior.
mutation-resilience-critical-pathsqualityskipwarningSOC2-CC8.1No code changes, only a new configuration file.
observability-on-new-endpointsoperationalskipwarningSOC2-CC7.2, ISO-27001-A.12.4.1No new HTTP/gRPC endpoints added.
rollback-documented-for-migrationsoperationalskiperrorSOC2-CC7.5, ISO-27001-A.14.2.2No database migration files in diff.
spec-implementation-matchcontract_specskiperrorCDPD-§7No spec linked.

Audit log (2)

WhenActorActionDetails
2026-05-19 05:11:42 UTCmr-sentinelskip_duplicate{"sha": "1fb25ad2", "reason": "already_evaluated", "rubric_version": "v2"}
2026-05-19 05:11:42 UTCmr-sentinelevaluate{"score": 0.0, "note_id": 3361770482, "verdict": "block", "tool_calls": 8, "rubric_source": "project_override", "comment_crea