From design to implementation
Design review identifies security requirements and checks that generated rules are supported by your specification.
The pre-write verifier evaluates supported proposed code against applicable rules before the write reaches disk.
Dependency checks assess supported package installs and npm lockfile changes.
The CI gate checks submitted changed-file content at the pull request, using project policy and GitHub's required checks.
Evidence you can follow
The review dashboard links requirements with findings, subsequent corrections and missing evidence. Hook calls bound to a design review appear under that review. CI runs are recorded at project level and do not inherit a local design-review binding.
Understand the scope
A passing check means no violation was found in the rules and context evaluated. It does not prove the whole app secure. A requirement can remain not established when the relevant behavior is outside the available code.