Review the change. Keep the judgment.
uses: D4NZ-jpg/diffowl@v0Every finding shows its work.
A material finding is a claim with a location, an impact, repository evidence, and an explicit verification state. No evidence, no finding.
Transient provider errors now permanently discard events instead of requeueing them.
Evidence: scoped diff
Validation: npm test failed on head
Example finding, shown as Diffowl publishes it to a review thread.
One review. Three safeguards.
Generation, challenge, and verification are separate roles, so confident language never counts as proof by itself.
{ "type": "findings", "coverage": "completed_permitted", "materialFindings": ["1 finding"], "verification": { "validationAttempts": 1 }}The same review, on your machine.
The CLI runs the engine the Action runs. Reproduce a CI review locally, inspect the full report, and get the same typed outcome.
cleanfindingspartial_coveragetimeoutabstentionconfiguration_failureDocumentation
Add base-branch policy, connect provider credentials, and install the GitHub Action in one sitting.
Open the guide →Project policyEvery field of .diffowl.json, with its security ceilings.
Automation stops. Human judgment starts.
A clean result means Diffowl found no material problems in what it was allowed to check. It is not proof the change is correct, and it is not an approval.
What Diffowl does and does not do