Security decision record
Illustrative example — fictional data, not a customer record.- Release
- payments-api
- Version
- 2.14.0
- Commit
- 9f3c1ab
- Decided
- Policy
- .fendix.yaml v1, blocks at CRITICAL
Release decision
Highest finding status
Decision reasons
- HIGH findings warn under this illustrative policy, which blocks at CRITICAL. Severity alone is not the release recommendation.
- Dependency scan did not complete, so part of the release is undecided.
- 1 accepted risk expires in 11 days and has no fix in progress.
Tests and scanners
- Static analysiscompleted
- Secret scanningcompleted
- API probingcompleted
- Dependency scanfailed
- Infrastructure confignot configured
Coverage gaps
- Dependency scan failed — lockfile could not be resolved. Re-run before relying on this decision. Affects coverage.
- Infrastructure config scanning is not configured for this repository. Not required by this policy.
Since previous release
- 2 new
- 1 fixed
- 11 persisting
Accepted risks
Wildcard CORS origin on /public/status
Accepted by Security Lead, expires 2026-08-04
Assigned owners
SQL injection in refund handler
@payments-team, due 2026-07-29
Missing rate limit on /api/v2/login
@platform-security, due 2026-08-07
Fix verification
- 1 verified resolved
- 1 still present
- 1 queued

