Scoring
KAEV scores summarize static-analysis findings; they are not SAP-certified scores or security guarantees.
Formula
Section titled “Formula”Scores start at 100. Each finding applies a severity weight multiplied by confidence:
| Severity | Weight |
|---|---|
| Info | 0 |
| Low | 1 |
| Medium | 4 |
| High | 12 |
| Critical | 30 |
| Confidence | Multiplier |
|---|---|
| Low | 0.25 |
| Medium | 0.75 |
| High | 1 |
Modernization findings apply 25% of their normal weighted penalty, with their combined penalty capped at 10. The final result is rounded and clamped to 0–100. Duplicate and lower-priority findings at the same source location are removed before scoring.
Score meanings
Section titled “Score meanings”- Project Health uses all active evaluated findings.
- Security Posture uses only active security findings and is
nullwhen security was not analyzed. - Unidentified projects receive
nullscores. - Category-only analysis, skipped/unavailable checks, and relevant discovery diagnostics mark coverage as partial.
A partial score of 100 means no weighted findings were found in the analyzed subset; it does not mean the whole application was proven healthy or secure.
Filters, baselines, and quality gates
Section titled “Filters, baselines, and quality gates”--severity changes only displayed findings. It does not change scores or the process exit code.
Baselines and active suppressions remove matching findings before scoring and --fail-on evaluation. Suppressed counts remain visible in rule status. --fail-on none disables the finding threshold but does not turn analysis failures into success.