DOCS / EXPECTED RED

Red is a safety feature.

An untouched skeleton cannot know your owners, stack, threat model, or trusted verifier. Calling that state green would be dishonest.

Expected activation failures

No real owner

Example CODEOWNERS entries must be replaced with valid people or teams who are accountable for control-plane changes.

No detected stack

A generic starter cannot infer build, coverage, mutation, or release behavior until it is applied to an actual project.

No project fuzz harness

The full profile requires a real target and useful assertions—not a placeholder command that exits successfully.

No independent verifier

Candidate-produced evidence is diagnostic until a separately administered producer verifies the exact subject and scope.

The rule

missing | stale | malformed | skipped | inconclusive => not_evaluated not_evaluated + required_control => deny

How green is earned

  1. Bind every adapter to real project commands and machine-readable reports.
  2. Prove negative controls: a survivor, missing tool, stale report, and policy drift must fail.
  3. Move the authoritative judge outside the candidate’s write boundary.
  4. Require the resulting check identities in a protected GitHub ruleset.
  5. Re-run against the final revision and promote the same artifact by digest.