SecurityGate evaluates one entry with an ordered set of scanners and turns
their findings into a verdict. It is created by Runner from the configured
scanners, score aggregator, threshold, fail-fast setting, and scanner-error
policy.
Findings and scores
A scanner emits a ScanOutcome: risk score, rationale, and optional match
spans. The gate adds the scanner ID, display name, severity, and action to make
a Finding.
Only findings with action BLOCK contribute to the aggregate. Their input to
the configured score aggregator is:
weighted score = finding.risk_score × finding.severity.weight
The entry is safe when there are no blocking findings or when the aggregate is
strictly below threshold. WARN and PASS findings are retained for review
but do not contribute to the aggregate.
Content-type routing
Scanners may restrict their accepted content_types. Before calling a scanner,
the gate compares the entry’s type with that restriction. A non-matching scanner
is recorded as skipped with its reason; it does not produce a finding or affect
the aggregate.
Fail-fast behavior
When fail_fast is enabled, the gate stops after the first blocking finding
whose severity-weighted score reaches the configured threshold. With it disabled,
the gate runs every compatible scanner and returns all findings.
Scanner errors
on_scanner_error determines how scanner exceptions affect the result:
| Policy | Behavior |
|---|---|
|
Re-raises the original error. |
|
Continues according to fail-fast settings and forces an unsafe verdict. |
|
Records a skipped scanner with an execution-failure reason. |
The output GateVerdict includes is_safe, aggregate score, rationale,
findings, and skipped scanners. See
Score aggregators for the available
combination strategies.