SpecGate
A repository gate that maps diffs to team-approved data and control policies, surfaces sensitive-data candidates and proposes the smallest reviewable blocking-test set.
Regulated engineering teams need to decide which tests and reviews should block a code change. Labeling a diff as AI-generated does not establish its risk, while scanning for personal or health data can produce false positives and miss runtime behavior. SpecGate evaluates every diff against a team-owned policy and proposes evidence-backed blocking checks for human approval.
The source confirms an early open-source compliance scanner with implemented and planned rule coverage, but no repository action, sensitive-data detector or blocking-test selector. Its copyleft license creates a mandatory legal and architectural gate: use requires compliance, a commercial license or an independently implemented alternative.
Diff, component mapping, data-flow candidate, policy finding, test proposal, code-owner approval, test execution, review disposition, merge, deployment and runtime outcome remain separate. A passing scan or test suite never proves privacy, security, legal compliance or production safety.
An engineering-platform, security, privacy or compliance leader at a regulated software team that needs explainable repository gates.
Engineering-platform and governance owners in regulated teams are clearly identifiable.
A new scanner and practitioner demand make risk-based test selection timely.
The source records three cross-references and no inbound or direct connections.
The input names a regulated engineering buyer, confirms an early scanner and identifies a concrete missing workflow: explaining which existing tests and reviews should block a given diff.
The source project's license constrains reuse, regulatory rules are partly planned, sensitive-data detection is fallible, AI authorship is not reliably observable, no structural incumbent cost is shown and policy onboarding adds human work.
Discussion
No comments yet — be the first to weigh in.
