KORTHEXDocumentation

Docs / ANALYSIS ENGINES

ANALYSIS ENGINES

Policy Engine

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

The Policy Engine decides which findings should block a CI/CD pipeline, which should warn , and which to ignore - based on a federated baseline plus your organization's overrides. It outputs proper CI exit codes and standard-format reports.

Verdicts

Each verdict carries a citation to the rule or standard that produced it (e.g. "NIST SP 800-131A § 8.2") so reviewers can verify the decision.

VerdictMeaningCI behavior
BLOCKThis finding violates a hard rule.CI fails (exit 1).
WARNFinding noted, but not blocking.CI passes with annotation.
ALLOWFinding falls within the policy.CI passes silently.
AUDITFinding noted for periodic review.CI passes; appears in audit summary.

Built-in Profiles

Profiles are a property of the policy file, not a CLI setting. There is no command to switch or print the active profile - the CLI exposes exactly two policy subcommands, enforce and evaluate . Select a profile by editing the policy file and passing it with --policy .

ProfileUse case
strictAnything below recommended status raises BLOCK. For greenfield projects + regulated industries.
balancedDefault. Deprecated raises BLOCK; acceptable raises WARN; exemptions allowed.
legacyOnly disallowed primitives BLOCK; deprecated WARN; for brownfield migrations.

Scan Modes

# Evaluate a report against the policy, machine-readable korthex policy evaluate --report report.krx --format sarif # Enforce it: exit 1 when the policy is violated korthex policy enforce --report report.krx --fail-on-violation policy enforce takes a report via --report , not a directory, and it has no mode selector: --mode , --base-ref and --baseline do not exist on it. The three scopes above are properties of the policy evaluation, not flags you pass here. To gate a PR on changed files only, use korthex check . --since-ref origin/main ; to gate on new findings only, use korthex check . --baseline <file> . Policy commands require an Enterprise license. Exit codes: 0 clean, 1 violations, 31 report unreadable, 32 no policy loaded, 41 policy file unusable. --threshold is declared but not honoured - set ci_fail_on in the policy file instead.

ModeEffect
fullEvaluate every finding in the report against policy.
changedOnly findings touched by the current diff (best for PR gates).
baselineOnly findings new since the saved baseline (best for incremental migration).

CI Output Formats

Policy enforcement emits in formats CI platforms consume natively:

FormatIntegration
SARIFGitHub Code Scanning, Azure DevOps, GitLab. Findings show up inline on the PR diff.
JUnit XMLGeneric CI runners. Each violation becomes a failed test case.
JSONCustom integrations and bot workflows.
TEXTHuman-readable summary for terminals + Slack notifications.