Skip to content

Understand the result

Every finding includes a stable rule ID, severity, confidence, source location when available, evidence basis, explanation, and recommended action.

State Meaning
PASS Evaluated without a finding.
ISSUE Evaluated and produced one or more active findings.
SUPPRESSED Findings were accepted by an explicit policy or baseline.
N/A The check does not apply to the detected project context.
SKIPPED The check was deliberately excluded or disabled.
UNAVAILABLE The check could not be completed safely.

Severity describes potential impact. Confidence describes how strongly the static evidence supports the finding. A finding is evidence for review, not automatic proof of a defect or vulnerability.

  • Project Health measures the weighted condition of all analyzed categories.
  • Security Posture measures the weighted condition of security findings when security was analyzed.

A score may be marked partial when analysis is intentionally limited or incomplete. A score of 100 is not a security guarantee.

Code Meaning
0 Analysis completed and no finding reached the failure threshold.
1 Analysis completed and a finding reached the failure threshold.
2 Analysis, configuration, filesystem, or required-analyzer failure.

The default failure threshold is high:

Terminal window
kaev check --fail-on medium
kaev check --fail-on critical
kaev check --fail-on none

--severity controls visibility. --fail-on controls the quality gate.