EricCogen/GauntletCI

Behavioral Change Risk detection for pull request diffs. GauntletCI identifies logic shifts, missing validations, and hidden regressions that pass tests and code review.

C#

3

1,376 commits

updated Oct 5, 2026

See the code

README

GauntletCI

Your tests passed. Your PR was approved. Your change still broke production.

Tests confirm existing behavior. Code review confirms intent. Neither validates what your change actually does.

GauntletCI detects Behavioral Change Risk in pull request diffs: logic shifts, missing validations, and hidden regressions that compile cleanly, pass every test, and survive code review — before the commit is created.


Table of Contents


The Missing Layer

Modern pipelines answer different questions:

LayerQuestion answered
Static analysisIs this code well-formed?
Security scanningDoes this code contain known vulnerabilities?
TestsDoes this code match expected behavior?
Code reviewDoes this change match intended behavior?
GauntletCIIs the behavioral impact of this change verified?

GauntletCI doesn't replace any of these. It closes the gap none of them cover.


Quick Start

dotnet tool install -g GauntletCI

# Run against staged changes before committing
gauntletci analyze --staged

Five minutes from install to first finding. No configuration required.

→ Full install guide | CLI reference


What GauntletCI Detects

37 deterministic rules across production risk tiers:

TierCategoryExample
1Structural & Scope IntegrityVisibility changes, signature drift
2Behavioral & Correctness RiskControl flow changes, removed guard clauses
3Security & ComplianceSecrets in diffs, SQL injection exposure, PII logging
4Resource & ConcurrencyAsync deadlocks, undisposed resources, shared state
5Observability & FailureSwallowed exceptions, removed logging from error paths
6Evidence & Test CompletenessBehavior change with no corresponding test delta
7Architecture & Structural ContractsInterface violations, coupling changes
8Dependency & Integration SafetyVersion conflicts, breaking API surface changes

Detection is fully deterministic. Same diff, same findings, every time. No LLM evaluates whether a rule fires.

→ Full rule catalog


How It Compares

GauntletCICodeRabbitCopilot Code ReviewSonarQube
Deterministic findings✅❌❌✅
Behavioral change detection✅PartialPartial❌
Test coverage gap detection✅❌❌❌
Runs pre-commit (local)✅❌❌❌
Core analysis local / no data egress by default✅❌❌✅
.NET-native✅❌❌✅
AI explanations available✅ opt-in✅✅❌

LLM explanations are available as an opt-in layer. The detection logic itself never involves one.


See It Live

The GauntletCI-Demo repo contains 36 scenarios across 3 tiers — each compiling cleanly, passing all tests, and passing traditional SAST gates, while introducing behavioral risk only visible at the diff level.

→ Browse live demo PRs


GitHub Actions

Start in advisory mode. Inline comments surface findings without blocking merges:

name: GauntletCI

on:
  pull_request:

permissions:
  contents: read
  pull-requests: write

jobs:
  risk-analysis:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - uses: EricCogen/GauntletCI@main
        with:
          fail-on-findings: "false"
          inline-comments: "true"

Once signal quality is tuned for your codebase, set fail-on-findings: "true" to block risky merges.


Documentation

Documentation HubFull documentation index
CLI ReferenceComplete command-line usage
Architecture GuideHow detection works
Technical FAQCommon questions
TroubleshootingCommon problems and solutions
ContributingHow to contribute
Security PolicyVulnerability reporting

Community

Questions? Ideas? Found a false positive?


License

Elastic License 2.0 — free for personal and internal use.

code-quality
code-review
compliance
csharp
developer-tools
dev-tools
dotnet
git
github-actions
local-first
pr-analysis
pre-commit
privacy-focused
pull-request
risk-analysis
security-automation
shift-left
static-analysis

EricCogen/GauntletCI

Behavioral Change Risk detection for pull request diffs. GauntletCI identifies logic shifts, missing validations, and hidden regressions that pass tests and code review.

C#

3

1,376 commits

updated Oct 5, 2026

See the code

README

GauntletCI

Your tests passed. Your PR was approved. Your change still broke production.

Tests confirm existing behavior. Code review confirms intent. Neither validates what your change actually does.

GauntletCI detects Behavioral Change Risk in pull request diffs: logic shifts, missing validations, and hidden regressions that compile cleanly, pass every test, and survive code review — before the commit is created.


Table of Contents


The Missing Layer

Modern pipelines answer different questions:

LayerQuestion answered
Static analysisIs this code well-formed?
Security scanningDoes this code contain known vulnerabilities?
TestsDoes this code match expected behavior?
Code reviewDoes this change match intended behavior?
GauntletCIIs the behavioral impact of this change verified?

GauntletCI doesn't replace any of these. It closes the gap none of them cover.


Quick Start

dotnet tool install -g GauntletCI

# Run against staged changes before committing
gauntletci analyze --staged

Five minutes from install to first finding. No configuration required.

→ Full install guide | CLI reference


What GauntletCI Detects

37 deterministic rules across production risk tiers:

TierCategoryExample
1Structural & Scope IntegrityVisibility changes, signature drift
2Behavioral & Correctness RiskControl flow changes, removed guard clauses
3Security & ComplianceSecrets in diffs, SQL injection exposure, PII logging
4Resource & ConcurrencyAsync deadlocks, undisposed resources, shared state
5Observability & FailureSwallowed exceptions, removed logging from error paths
6Evidence & Test CompletenessBehavior change with no corresponding test delta
7Architecture & Structural ContractsInterface violations, coupling changes
8Dependency & Integration SafetyVersion conflicts, breaking API surface changes

Detection is fully deterministic. Same diff, same findings, every time. No LLM evaluates whether a rule fires.

→ Full rule catalog


How It Compares

GauntletCICodeRabbitCopilot Code ReviewSonarQube
Deterministic findings✅❌❌✅
Behavioral change detection✅PartialPartial❌
Test coverage gap detection✅❌❌❌
Runs pre-commit (local)✅❌❌❌
Core analysis local / no data egress by default✅❌❌✅
.NET-native✅❌❌✅
AI explanations available✅ opt-in✅✅❌

LLM explanations are available as an opt-in layer. The detection logic itself never involves one.


See It Live

The GauntletCI-Demo repo contains 36 scenarios across 3 tiers — each compiling cleanly, passing all tests, and passing traditional SAST gates, while introducing behavioral risk only visible at the diff level.

→ Browse live demo PRs


GitHub Actions

Start in advisory mode. Inline comments surface findings without blocking merges:

name: GauntletCI

on:
  pull_request:

permissions:
  contents: read
  pull-requests: write

jobs:
  risk-analysis:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - uses: EricCogen/GauntletCI@main
        with:
          fail-on-findings: "false"
          inline-comments: "true"

Once signal quality is tuned for your codebase, set fail-on-findings: "true" to block risky merges.


Documentation

Documentation HubFull documentation index
CLI ReferenceComplete command-line usage
Architecture GuideHow detection works
Technical FAQCommon questions
TroubleshootingCommon problems and solutions
ContributingHow to contribute
Security PolicyVulnerability reporting

Community

Questions? Ideas? Found a false positive?


License

Elastic License 2.0 — free for personal and internal use.

code-quality
code-review
compliance
csharp
developer-tools
dev-tools
dotnet
git
github-actions
local-first
pr-analysis
pre-commit
privacy-focused
pull-request
risk-analysis
security-automation
shift-left
static-analysis