Repository Assessment¶
crypto-finding-assessment.json summarizes completed scanner facts for repository-level review.
It is designed for security leads and program owners who need posture and workload without loading
every function row.
Use it to review¶
- readiness status;
- total crypto-function and operation-group counts;
- high-risk and weakened cryptographic use;
- FIPS evidence posture;
- CWE and anti-pattern distribution;
- manual-review counts;
- algorithm and confidence counts;
- deterministic recommendations.
The report is calculated from selected crypto functions, operation groups, and finding statistics. It does not embed the raw function/group rows; open the primary reports for source evidence.
Decision boundary¶
Use the assessment to prioritize work, not to certify an application. FIPS status, quantum classification, and recommendations remain limited by the detected and resolved source evidence. Unknown or unresolved context should remain visible in the review plan.
The assessment is generated entirely from deterministic scanner evidence.