# Project findings

`findings.json` is the canonical register for concrete defects, candidates and accepted risks in this repository. Keep IDs stable after rejection, merging, deferral or verification.

Allowed statuses are `candidate`, `confirmed`, `fixed_unverified`, `verified`, `accepted_risk`, `deferred`, `rejected` and `merged`.

Each finding records impact, evidence and the decisive required check. A code edit or green unit test does not establish hosted, production, artifact or physical verification.
