Interactive proof walkthrough

Watch one finding become a signed fix.

You follow a real proof path on a signed benchmark artifact: a reachable auth-throttling finding becomes a bounded patch with green CI, a scanner-clean delta, branch-protection review, and a KMS/Sigstore-signed evidence packet — then an auditor accepts it in a scoped evidence room. Use the step rail, the arrow keys, or Previous and Next to move through it.

Step 1 / 7

Finding received

A reachable auth-throttling finding lands from an imported SARIF scan with severity, reachability, owner, and SLA attached.

Finding ID
SARIF auth-throttle-77e3
Rule
missing-rate-limit-before-auth
Severity
High
Reachability
Reachable — used login route, unauthenticated
Affected file
apps/web/src/app/api/login/route.ts
Owner
auth-platform team
Source
Imported SARIF (Semgrep)
SLA
7 days — due 2026-06-28

Step 1 of 7: Finding received

Do the same on your finding

Turn one of your findings into a signed fix.

Open the remediation scorecard behind this walkthrough, or start a scoped evaluation on a real finding of your own.