Public Kiota methodology sample; historical agent-authored squash merges in the committed study dataset. Microsoft is not a customer.
microsoft/kiota · 77 selected record(s).
Public Kiota methodology sample. Microsoft is not a customer; no customer relationship or endorsement is implied.
75VERIFIED
2NOT_PROVEN
0FAIL
77 verdict(s) recorded; 0 unresolvable record(s), excluded from verdict counts. Counts are per record, not per finding.
NOT_PROVEN != bad code. NOT_PROVEN means missing evidence under implemented checks, not defective code. VERIFIED means those checks found no blocking evidence gap; it is not proof of correctness. FAIL means the verifier could not safely establish a result.
Recommendation
Inspect the flagged records and any existing validation of the combined state. If evidence is insufficient for the risk, validate that state and repeat the assessment. Start with the small flagged set rather than changing every merge workflow.
Do nothing is an option. If the recorded limitation is acceptable for this scope, document that decision and leave the workflow unchanged. Accepting a gap does not change a NOT_PROVEN, FAIL or unresolvable record into VERIFIED. No action is executed by this report.
BASE_DRIFT_UNVERIFIED The base advanced by 2 commit(s), with 1 overlapping file(s). This flags a possible evidence gap for the combined state. CI results were not inspected.
PROTECTED_BOUNDARY The candidate changed policy. The implemented path checks request closer validation of this boundary; they do not establish that code is defective or that existing CI failed.
This report renders recorded study/collect.js output; it does not fetch current repository or CI state. The collector examines selected agent-authored squash merges, using the squash commit first parent as base-at-merge and the fetched PR head as candidate. The source format does not record collection time or merge timestamps, so no date window is inferred. Sampling is purposive and bounded, not representative of all merges. See STUDY.md for methodology.
Implemented blocking checks: BASE_DRIFT_UNVERIFIED (overlapping base drift) and PROTECTED_BOUNDARY (sensitive path categories). Stale-base and CI/deploy path advisories do not affect verdict counts. The source JSON retains detailed metrics, exclusions and advisories; collector rows retain finding IDs rather than full file-level explanations.
Not checked
CI_RAN_ON_FINAL_HEAD: merge-proof does not read CI results; it cannot tell which commit was tested.
HUMAN_APPROVAL_PRESENT: merge-proof does not read reviews or approvals.
CANDIDATE_DURABLE_ON_REMOTE: merge-proof inspects local git state only; it does not query a remote for durability.
SCOPE_CREEP_VS_DECLARED_SCOPE: merge-proof has no declared-scope input to compare the diff against.
This report cannot establish whether CI ran on the exact state that landed. It is not a code review, bug detector, security scan, correctness proof or replacement for CI.
Evidence register
All selected records; full refs for notable records appear above. Abbreviated refs below are locators, not additional validation. The input JSON preserves full available evidence.