Documentation

What a check does

Provide a provider contract change and the repositories in scope. Octans normalizes the OpenAPI difference, applies static detectors to contracts and source, records relationships with evidence and confidence, identifies affected callsites, estimates blast radius, and recommends a provider-compatible or coordinated-consumer strategy.

Octans does not execute the analyzed repository, build, install, or tests. External CI and tests are human verification evidence supplied or consulted after the static analysis; they are not automatically run by Octans.

Measured limitations

On the independently authored 14-scenario evaluation set, blast-radius recall was 0.5 and precision was 0.636; strategy recommendation accuracy was 4/10. These are measurements of that evaluation set, not a guarantee for a new repository or release.

How to read results

Evidence is bounded to a redacted callsite excerpt, detector, confidence, and file location. A result is a review aid, not a production guarantee. The current release retains bounded excerpts; the planned --no-evidence-excerpt option is not implemented yet.

Safety boundary

Octans is check-only by default. It does not auto-merge or autonomously repair production code. Optional repair output is a proposal for a human reviewer. Credentials, whole source files, prompts, and repository checkouts are not persisted; runs use an operator-controlled temporary workspace.

Request a supported scan

For a design-partner compatibility scan, contact [email protected] with a repository owner, proposed contract change, and verification command. Do not send credentials, private source, customer data, or prompts through this public surface.