01 / EVIDENCE
Read the source.
Each finding identifies its location, reviewed commit, severity and explanation. Security analysis separates observed patterns, inferred exposure and proposed hardening.
EVIDENCE BEFORE ASSUMPTION
A useful review connects a changed line to evidence, context and the questions that still need your judgment.
A conceptual map of the review workflow.
01 / EVIDENCE
Each finding identifies its location, reviewed commit, severity and explanation. Security analysis separates observed patterns, inferred exposure and proposed hardening.
02 / CONTEXT
Bounded JavaScript and TypeScript context links supported imports, calls and tests. Each connection has source evidence; dynamic calls and uninspected dependencies remain unknown.
03 / DECISION
Accept an issue, explain a false positive, record a fix assessment, or accept risk. These decisions remain tied to the repository and review; they do not silently change security rules.
Missing source, omitted files, unsupported syntax and unavailable CI remain visible. A high evidence score is not permission to merge.
Inspect eligible touched-function documentation and available GitHub check results. Skipped and unavailable checks are separate from passes. The report explains the scope of each measurement.
Understand the security boundary →