MR Sentinel

Audit log · ← dashboard

sgharlow/governance-demo-app!13

Verdict
block
Score
1.0 / 10
Rubric
v2
Commit
b7efcfe0
Scored
2026-05-19 05:11:42 UTC

Rule outcomes (15)

RuleCategoryOutcomeSeverityControlsEvidence
dependency-advisory-checksecurityfailblockerSOC2-CC7.1, ISO-27001-A.12.6.1, NIST-SA-11The diff pins `pyyaml==5.1` which is vulnerable to CVE-2020-14343 (critical) and `requests==2.20.0` which is vulnerable to CVE-2018-18074 (high).
error-budget-impact-declaredoperationalfailwarningSOC2-CC4.1The MR description states the change is for 'compatibility with the legacy reporting service' but does not declare the expected error-budget impact for this service.
contract-has-spec-linkcontract_specpasswarningCDPD-§3, ISO-27001-A.14.2.1MR description includes 'Closes #189' linking to a spec issue.
no-commented-out-codequalitypassinfoSOC2-CC8.1No commented-out code blocks were added in the diff.
no-secrets-in-diffsecuritypassblockerSOC2-CC6.1, ISO-27001-A.9.4.3, OWASP-ASVS-V2No secret patterns were detected in the diff.
no-skipped-tests-introducedqualitypasserrorSOC2-CC8.1No test files were modified or added in the diff.
acceptance-criteria-testablecontract_specskipwarningCDPD-§5, SOC2-CC8.1This MR modifies dependency versions, not application logic with acceptance criteria.
auth-on-new-public-endpointssecurityskipblockerSOC2-CC6.1, OWASP-ASVS-V1This MR modifies dependency versions and does not introduce new public endpoints.
changed-method-coveragequalityskiperrorSOC2-CC8.1, ISO-27001-A.14.2.8The diff modifies a dependency file (requirements.txt), not source code methods.
integration-boundaries-explicitcontract_specskipwarningCDPD-§6, ISO-27001-A.14.2.5This MR modifies dependency versions and does not introduce or alter integration boundaries.
kill-switch-pathcontract_specskipwarningCDPD-§9, SOC2-CC7.5This MR pins dependency versions and does not introduce new user-facing behavior requiring a feature flag.
mutation-resilience-critical-pathsqualityskipwarningSOC2-CC8.1The diff modifies a dependency file (requirements.txt), which is not subject to mutation testing for critical paths.
observability-on-new-endpointsoperationalskipwarningSOC2-CC7.2, ISO-27001-A.12.4.1This MR modifies dependency versions and does not introduce new HTTP/gRPC endpoints.
rollback-documented-for-migrationsoperationalskiperrorSOC2-CC7.5, ISO-27001-A.14.2.2This MR modifies dependency versions and does not include database migration files.
spec-implementation-matchcontract_specskiperrorCDPD-§7This MR modifies dependency versions, not application logic that would be compared against a detailed spec.

Audit log (2)

WhenActorActionDetails
2026-05-19 05:11:44 UTCmr-sentinelskip_duplicate{"sha": "b7efcfe0", "reason": "already_evaluated", "rubric_version": "v2"}
2026-05-19 05:11:44 UTCmr-sentinelevaluate{"score": 1.0, "note_id": 3361770539, "verdict": "block", "tool_calls": 8, "rubric_source": "project_override", "comment_crea