{"object":"pr_verdict_info","scanned":"a PUBLIC GitHub pull request (diff fetched from api.github.com)","dimensions":{"code":"application-code SAST over added lines (services/codescan, CWE Top-25)","secret":"hardcoded-secret / credential leak over the diff (services/secretscan)","ci":"CI/CD pipeline security of changed workflow files, full file at head_sha so cross-job graph rules run (services/cicdscan)","deps":"supply-chain preflight of newly added dependencies — typosquat / malware / hallucination (services/pkgpreflight; npm + PyPI manifests)"},"verdicts":["pass","caution","block"],"verdict_bands":{"block":"any critical finding OR any sub-scanner that itself blocks","caution":"a lone high/medium below the block threshold","pass":"clean or info-only"},"manifests_checked":["package.json (npm)","requirements*.txt (PyPI)","pyproject.toml (PyPI)"],"manifests_recognised_unchecked":["go.mod","Cargo.toml","Gemfile"],"limits":{"github_rate_limit":"60 req/h/IP keyless; 5000/h with an optional server GITHUB_TOKEN","large_diff":"GitHub returns HTTP 406 on very large diffs; we fall back to the paginated files API up to a cap and flag coverage.truncated=true","max_files":100,"max_patch_bytes":1000000,"max_ci_files":10,"max_dependency_checks":20,"total_fetch_budget_seconds":25.0},"boundary":"Aggregator only — it composes codescan/secretscan/cicdscan/pkgpreflight (which remain standalone routes) and owns no rules. Public repos only; the fetched code is transient (only the derived verdict + short evidence are returned).","disclaimer":"Automated merge-risk indicators aggregated from static scanners over the PR diff — security signals, not a guarantee. A pass verdict is not proof the PR is safe; coverage reflects only the files and dimensions actually scanned (see `coverage`)."}