Repository navigation
FAQ
Because unverified is not verified. A rule the runner cannot conclusively check returns INCONCLUSIVE, and the gate treats it as FAIL. Install the scanner and rerun: the report keeps Could not assess separate from the fix queue precisely so you can tell environment problems from surface problems.
Read the environment block at the top of the report. A missing headless browser or scanner converts proofs into INCONCLUSIVE, which lowers the score without anything about the site changing.
No. The score is level-relative, a ratio over the rules in scope at the declared level, and it is environment-sensitive. Compare medals: the medal is the claim.
That is UNSCANNABLE, by design, with the transport cause and exit code 3. A surface that cannot be fetched produces no verdict at all, so an unreachable host can never look like a merely imperfect one. Treat exit 3 in CI as an infrastructure alert.
Declare what the surface actually is. An L0 declaration on a page that carries analytics produces a permanently red gate describing decisions you already made. See Choosing a profile and level.
No. AG-GOV-01, without exception. Waivers only ever suppress a failing SHOULD.
Working as intended: expiry is enforced against the runner's clock and a governance violation blocks the gate. That is what makes a waiver a deadline rather than a permanent exception.
Not necessarily. The GitHub Action runs from a prebuilt image, and there is a container image at ghcr.io/fabriziosalmi/agssh. The go install path is for local use.
agssh_scan for a live URL, agssh_scan_config for an existing .airgap.yml with full CLI parity, and agssh_list_rules for the registry, which needs no network. Each scan returns a human summary and the full structured record.
Not by default. agssh_scan fetches a caller-supplied URL server-side, so it refuses loopback, private and link-local targets with an SSRF guard enforced at dial time on the resolved IP. Pass allow_private_targets when you actually mean it.
Yes, that is why it is self-hosted SVG: no web font, no external image, no third-party endpoint. Serving it from your own origin does not violate AG-NET-02.
The PDF standard carries the normative why, check, fix, tool per rule. RULES.md is the browsable index, and both, plus the runner's rule manifest, are generated from one source, so the document and the runner cannot drift.
A handful whose verification is process-specific or not yet automated in this build, such as reproducible-build comparison and deterministic-output diffing, are registered INCONCLUSIVE with the approach to wire in. They block until proven, and each is a single Checker in internal/rules if you want to contribute one.
In this wiki
Reference
Project