Our summary
Different code changes deserve different review. check-risk starts with a project's written policy about sensitive files and consequences. Exact checks look for changed paths, new dependencies, large changes, and missing test edits before Jev is asked any questions about behaviour.
Jev examines limited before-and-after source excerpts. Ordinary code combines the named rules, applies minimum risk levels, and gathers required checks and reviewers. The report keeps the evidence and marks the assessment incomplete when the model is unavailable or has not been used.
The risk number represents policy weights, not the chance of an incident. Changed tests do not prove useful coverage, and default finance-related examples need replacing for another project. Source may leave the computer, while exclusions do not guarantee secrets are removed. Live Jev testing was still pending.
Key takeaways
- Write project-specific rules for sensitive changes.
- Report missing analysis rather than silently approving release.
- Do not read a policy score as a probability of failure.