Engineering

DevOps Change Risk

Assess repository changes before merge with deterministic findings and policy decisions.

Dependencies, SBOM and OSV deltas, Actions, secrets, containers, Terraform and OpenAPI.

Capabilities

  • Dockerfile and Compose configuration analysis
  • Image tags, runtime users and healthcheck signals
  • Source and terraform show -json plan analysis
  • Ingress, storage and resource-level findings
  • OpenAPI breaking changes, dependency, SBOM and OSV deltas
  • GitHub Actions, secrets, container and base-image risk
  • Policies, waivers and GitHub App Check Runs

Use it in your workflow

Establish a baseline or submit a bounded request, then retain the current result, source-linked evidence and any material-change delivery in the workspace that owns the decision.

Questions before you evaluate

Does AntOps run submitted code?

No. It analyzes bounded submitted text only.

Can it block CI?

Yes. Exit non-zero when the returned decision equals blocked.

Are findings durable?

Assessments, findings, policies and waivers are retained in workspace-scoped history.

Evaluation path

GitHub PR and DevOps change risk