You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5cc75ae
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/architecture.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -100,7 +100,7 @@ The pipeline includes several verification gates and calibration layers that aug
100
100
101
101
Before rendering the final report, deterministic checks verify that all citations (file paths + line ranges) match the scanned source tree. Findings failing this check have their confidence score halved and a note added explaining the discrepancy.
102
102
103
-
Configured via `[citation_verification] enabled = false` (disabled by default).
103
+
Configured via `[citation_verification] enabled = true` (enabled by default).
Name the preset in the config instead of on the command line:
818
+
819
+
```toml
820
+
preset = "my-project"
821
+
822
+
[project]
823
+
name = "my-project"
824
+
path = "."
825
+
```
826
+
827
+
`--preset` wins when both are present, since passing it is a deliberate
828
+
override. A name that does not resolve fails the load and names the preset,
829
+
rather than quietly scanning with no preset applied.
830
+
831
+
Presets matter more than the flag suggests: they carry
832
+
`required_security_primitives` and the hook registry, which is what the
833
+
entry-point primitive check reads. A scan run without the WordPress preset
834
+
finds no missing-nonce findings, because it has no list of nonce functions to
835
+
check against.
836
+
817
837
### Fields a Preset Can Override
818
838
819
839
| Section | Key fields |
@@ -861,15 +881,22 @@ enabled = false
861
881
862
882
## Citation verification
863
883
864
-
The `[citation_verification]` section controls verification that finding citations (file + line) actually resolve in the target source, downgrading unverifiable findings.
884
+
The `[citation_verification]` section controls verification that finding citations (file + line) actually resolve in the target source.
885
+
886
+
A citation that does not resolve gets `verification_status = failed` and a note
887
+
in `verification_notes`. The finding is kept and its confidence is left alone:
888
+
confidence is the model's own estimate, and multiplying it by a constant
889
+
corrupts that estimate without saying anything about how wrong the citation is.
890
+
Whether failed findings reach the report is decided by
891
+
`[output] evidence_gate`; `include_rejected` keeps them visible when it is on.
0 commit comments