Repository reviews and branch comparisons
Select a branch, reuse an audit profile, inspect source health, and compare reviews without losing scope or commit provenance.
An audit reviews a captured revision of a repository. A branch name can move; the recorded commit identifies the source actually assessed.
Select the source
Open the repository list in the current workspace. Select a connected repository, choose an available branch, and start an audit. Check the repository, branch, and commit shown with the run. Branch access comes from that repository's authorized provider connection.
If the branch or repository is unavailable, repair the connection before retrying. Veriom does not silently review a different branch. GitHub access explains installation selection; other repository providers describes their read-only boundaries.
Save a repeatable profile
In Audit profiles and repository health, choose a repository and create a profile. Give it a recognizable name, select its branch and review purpose, and enter repository-relative include and exclude paths.
For example, a payments profile can include services/payments and exclude services/payments/generated. Omitted paths remain outside the assessment. The profile changes the source sent into ingestion and scanning; it also leaves a scope limitation on reports and comparisons.
Save the profile and use it to start the next review. Each run captures the profile version and settings. Editing or deleting the profile later does not rewrite historical audits. An empty include list means the repository root, subject to exclusions and normal ingestion limits.
Inspect repository health
The repository health view shows recorded access checks and evidence history. Review the checked time, available branch or revision information, failure reason, and suggested next step. A historical successful check does not guarantee that a provider still grants access today.
Use the connection management link when an installation loses access. Reconnect or refresh access, then retry the intended source. Keep the failed check as part of the history rather than treating it as a clean review.
Compare audited branches
- Open Compare audited branches and choose the repository.
- Select a baseline audit and candidate audit. Both selectors identify the captured branch and commit.
- Compare the runs and inspect new, persistent, resolved, and review-required findings alongside architecture changes.
- Read the comparability explanation before interpreting a finding as resolved.
The runs must belong to the same repository and have equivalent assessed source scope and comparable analysis policy. Missing coverage, changed paths, unfinished runs, and incompatible policy can make a conclusion require review. A finding absent from a narrower review is not evidence that it was fixed.
Saved comparisons retain their source audit references. A branch comparison is an assessment of captured evidence; it is not a merge approval or proof of the deployed state.
When a run needs recovery
| Situation | Next action |
|---|---|
| Repository missing from the picker | Check the provider account and installation's selected repository access |
| Branch no longer exists | Select an available branch and start a new review with an explicit scope |
| Another audit is active | Follow the existing run or cancel it if your role permits; avoid repeated submissions |
| Scope changed between runs | Run comparable profiles or review the result as incomplete |
| Old report has no recorded revision | Keep that provenance unknown; create a new review to establish it |
Continue with finding ownership or the audit lifecycle.
Was this guide useful?
Your response stays in this browser unless you open a GitHub issue.