The v1 slice (GitHub collector + predefined checks) is an R1 issue; this item keeps the
input-shape research and the multi-forge questions (GitLab, org/enterprise scope). Recommendation:
a keyed bag of GitHub REST API responses with field names validated against GitHub's published
OpenAPI — not the raw JSON of an existing repo-scoring scanner, which was evaluated and
rejected (feature-gated, schema drift against its own code, shipped field-name typos, repository
scope only). Adopt a 404-fallback convention so "branch not protected" is expressible with existing
conditions.
The v1 slice (GitHub collector + predefined checks) is an R1 issue; this item keeps the
input-shape research and the multi-forge questions (GitLab, org/enterprise scope). Recommendation:
a keyed bag of GitHub REST API responses with field names validated against GitHub's published
OpenAPI — not the raw JSON of an existing repo-scoring scanner, which was evaluated and
rejected (feature-gated, schema drift against its own code, shipped field-name typos, repository
scope only). Adopt a 404-fallback convention so "branch not protected" is expressible with existing
conditions.