Skip to content

Security Decision Record

One defensible security decision for every release.

See what changed, what was tested, which policies were triggered, and why the release received its decision.

Security decision record

Illustrative example — fictional data, not a customer record.
Release
payments-api
Version
2.14.0
Commit
9f3c1ab
Decided
Policy
.fendix.yaml v1, blocks at CRITICAL

Release decision

INCOMPLETE

Highest finding status

WARN

Decision reasons

  1. HIGH findings warn under this illustrative policy, which blocks at CRITICAL. Severity alone is not the release recommendation.
  2. Dependency scan did not complete, so part of the release is undecided.
  3. 1 accepted risk expires in 11 days and has no fix in progress.

Tests and scanners

  • Static analysiscompleted
  • Secret scanningcompleted
  • API probingcompleted
  • Dependency scanfailed
  • Infrastructure confignot configured

Coverage gaps

  • Dependency scan failed — lockfile could not be resolved. Re-run before relying on this decision. Affects coverage.
  • Infrastructure config scanning is not configured for this repository. Not required by this policy.

Since previous release

  • 2 new
  • 1 fixed
  • 11 persisting

Accepted risks

Wildcard CORS origin on /public/status

Accepted by Security Lead, expires 2026-08-04

Assigned owners

  • SQL injection in refund handler

    @payments-team, due 2026-07-29

  • Missing rate limit on /api/v2/login

    @platform-security, due 2026-08-07

Fix verification

  • 1 verified resolved
  • 1 still present
  • 1 queued

Human accountability

The release recommendation is not human approval. Review the evidence and coverage gaps, record risk acceptance and ownership, and request fix verification in your release process.

Audit trail
4 recorded events: policy evaluated, decision recorded, risk accepted, owner assigned.
  • BLOCK
  • WARN
  • INFO