◆ NFRGate / Rule Reference
πŸ›‘οΈ Code verification for the AI era

Every rule your merges are held to.

NFRGate catches missing logs, metrics, traces, and reliability gaps — static analysis plus LLM judgment, gating CI/CD before they ever reach production.

0Rules enforced
0NFR categories
0Languages
Python Java Go

How it builds trust

The same loop SonarQube popularized for code quality — applied to non-functional requirements.

πŸ”

Static analysis

Rule-based checks for logging, metrics, tracing, and reliability on every changed Python, Java, or Go file.

πŸ€–

LLM semantic assessment

Ticket text and diff context judged against the rubric for what no static rule can catch alone.

🚦

Confidence-based routing

High-confidence failures on critical rules auto-block; everything else is flagged for human review, never dropped.

πŸ’¬

CI/CD gating

One continuously-updated PR/MR comment, with a direct link to every rule's own documentation page.

See what your team sees

One comment per PR/MR, updated on every push — not a wall of separate bot comments.

Pull Request #482 · payments-service Example
🤖 nfrgate-bot commented

NFR Gate — Static Analysis

2 fail (2 blocking) · 6 pass · 1 unclear across 4 changed files.

CRITICALR1payments/client.py:88outbound call has no timeout configured
HIGHT1payments/client.py:88call not wrapped in a trace span
PASSL2payments/client.py:102structured error log present

Drops into the CI you already run

Complete, runnable job definitions — not just the invocation line. Both read the diff, post the comment, and fail the job on a blocking violation.

GitHub Actions

name: NFRGate

on:
  pull_request:
    types: [opened, synchronize, reopened]

permissions:
  contents: read
  pull-requests: write   # needed to post/update the PR comment

jobs:
  nfrgate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0   # full history -- pr_gate.py diffs base...head, a shallow clone can't resolve an arbitrary base SHA

      - uses: actions/setup-python@v5
        with:
          python-version: "3.12"

      - run: pip install nfrgate

      - name: Run NFRGate
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
        run: python -m nfr_gate.ci.pr_gate

GitLab CI

nfrgate:
  stage: test
  image: python:3.12-slim
  rules:
    - if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
  variables:
    GIT_DEPTH: 0   # full history, same reason as the GitHub Actions example
  script:
    - pip install nfrgate
    - python -m nfr_gate.ci.mr_gate

Rule Reference

Every rubric criterion this platform checks: what it checks, why, and (where a static evaluator exists) exactly how, per language.

πŸ“ logs
L1highNo swallowed exceptions Go Java Python
L2mediumStructured error logs Go Java Python
L3mediumSeverity matches reality Go Java Python
L4mediumCorrelatable with traces Go Java Python
πŸ“Š metrics
M1highLatency is measurable Go Java Python
M2highOutcome is measurable Go Java Python
M3highCardinality is bounded Go Java Python
πŸ›‘οΈ reliability
R1criticalTimeouts are explicit Go Java Python
R2criticalRetries back off Go Java Python
R3highDegradation is defined Go Java Python
πŸ” traces
T1highSpans on external calls Go Java Python
T2mediumSpans carry useful attributes Go Java Python
T3highContext propagates Go Java Python
T4mediumErrors marked on the span Go Java Python

No rules match that filter.