Release Gates
Release Gates
Release gates should block on verified, reproducible, high-impact findings.
- Define blocking thresholds
Decide which severities and risk categories block release. - Require replay
Prefer bug-level deterministic replay for P0 and P1 findings. - Keep budgets explicit
Bound tokens, cost, time, and tool execution. - Attach reports
Store report JSON and Markdown as CI artifacts.
Gate rule
Avoid noisy gates
Do not block a release on unverified narrative findings unless a human explicitly accepts that risk policy.