docs: add gauge-repo best-practices audit report - #110
Merged
Merged
Conversation
Adds the ai-sdlc gauge-repo engineering best-practices audit to docs/, scored under the current item-credit-v1 rubric: adjusted compliance = (Met + 0.5 x Partial) / (49 - justified N/A), target 100%, with critical gates reported separately as a binary GREEN/RED safety floor. Result: critical gates RED, adjusted compliance 43.9%. Documentation only — no code changes. Ref: SRE-3549 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
🟡 Changes recommended
The new report contains a broken internal reference and a couple of accuracy/consistency issues that should be corrected to keep the audit documentation reliable.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds a new documentation artifact capturing a gauge-repo engineering best-practices audit report for the muffin_man repository, intended to summarize current compliance status, evidence, and prioritized remediation actions.
Changes:
- Adds
docs/engineering-best-practices-audit.mdcontaining the repo profile, scorecard, per-item verdicts (with evidence), and prioritized recommendations. - Documents critical-gate status and an adjusted compliance calculation under the
item-credit-v1rubric.
File summaries
| File | Description |
|---|---|
| docs/engineering-best-practices-audit.md | New audit report documenting engineering best-practices compliance, evidence, and recommendations. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 3
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+3
to
+7
| | | | | ||
| |---|---| | ||
| | **Audit date** | 2026-09-08 | | ||
| | **Auditor** | Claude — gauge-repo skill | | ||
| | **Rubric version** | `item-credit-v1` — 2026-09-04 (`references/best-practices.md`) | |
|
|
||
| **Test suite is the standout.** 42 RSpec files under `spec/`, supported by **102 recorded JSON response fixtures** and `webmock` (`webmock/rspec` in `spec_helper.rb`, `webmock ~> 2.1` as a development dependency) — so SP-API interactions are exercised against recorded responses rather than live calls. | ||
|
|
||
| **CI actually enforces things.** `.github/workflows/ci.yml` triggers on both `push` and `pull_request` to `master`, runs a matrix across three Ruby versions with `bundler-cache: true`, and executes **`bundle exec rspec` and `bundle exec rubocop`** — the only repository in this batch whose CI runs both a test suite and a linter. |
| | 18 | License compliance scanning | **Gap** | No automated license checking, though the gem itself correctly declares MIT and ships `LICENSE.txt` | Low priority. | | ||
| | 19 | Secret scanning | **Met** | Inherited Pattern Wiz org-wide secret scanning (owner verified as `patterninc`). No credential material is committed — SP-API credentials are supplied by consuming applications at runtime, and the 102 recorded fixtures are responses rather than requests | Met — inherited Pattern Wiz policy. Worth noting that recorded HTTP fixtures are a common place for tokens to leak, and these do not appear to carry any. | | ||
| | 20 | SAST / static analysis gates | **Met** | Inherited Pattern Wiz org-wide SAST and blocking policy (owner verified as `patterninc`), plus repo-local RuboCop running on every pull request | Met — inherited policy reinforced by a real local check. | | ||
| | 21 | Max complexity limits | **Partial** | `.rubocop.yml` is present and RuboCop's `Metrics` department (method length, ABC size, cyclomatic complexity) is enabled by default unless explicitly disabled — so complexity limits are likely enforced through the CI step in item 10. What cannot be confirmed from the repository layout alone is whether those cops have been switched off in the configuration | Verify the `Metrics` cops are enabled rather than excluded; if they are on, this is Met. | |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
docs/engineering-best-practices-audit.md— thegauge-repoengineering best-practices audit for this repository.Result: Critical gates RED · Adjusted compliance 43.9%
Rubric:
item-credit-v1(2026-09-04). Every applicable item counts equally; adjusted compliance is(Met + 0.5 × Partial) / (49 − justified N/A)with a target of 100%, and critical gates are reported separately as a binary GREEN/RED safety floor. Items marked N/A carry a written, profile-backed rationale and are collected in a Declined practices section so the exclusions can be argued with.The report contains the repo profile that justifies each N/A, all 49 item verdicts with evidence (file paths, CI job names,
gh apiresults), prioritized recommendations sized S/M/L and ordered gates-first, and a Beyond the checklist section for strengths the list does not capture.Documentation only — no code changes.
Ref: SRE-3549