Skip to main content

Repository permissions

Veridical does not request repository administration, Actions secrets, workflow write, deployments, members, or organization administration. It does not merge pull requests.

Webhook events

GitHub supplies installation and repository-selection lifecycle events for the app installation itself.

Publication safety

  • Work is bound to an immutable base and head.
  • A moved head makes the earlier result stale and prevents it from becoming the current review.
  • Comments are published only for findings that survive grounding and final verification.
  • Duplicate webhook deliveries are idempotent.
  • Maintainer commands are accepted only from GitHub-recognized repository insiders.
  • Veridical never auto-merges.
Uninstalling the app or removing a repository stops new work for that scope.
Last modified on August 29, 2026