
Six Roads to a False PASS (All One Root Cause)
A valid credential is not proof of what it was about. Learn how six false PASS paths exposed one weak observation boundary.
Every post starts with a problem you already have (a green check you couldn't trace, an AI grading its own work) before it gets anywhere near Ranex.
The mechanism itself: what the kernel enforces, and what a gate looks like before and after a fix.
The same belief applied to a team's process: who is allowed to approve what.
The same belief applied to one incident at a time, told straight and cited to the repository record.

A valid credential is not proof of what it was about. Learn how six false PASS paths exposed one weak observation boundary.

Week 1 roundup: five verified highlights, five plain corrections, and what we left out, every restated fact re-checked against primary sources.

Five observable GitHub signals (response times, external-PR merges, release cadence) that tell you more than any good first issue label.

Why a Ranex verdict uses only gate, evidence, subject, and approver so the same proof always gets the same result.

14 dependency bumps hit your inbox overnight. Three of them are decisions, not routine maintenance. Here’s how to tell the difference.

A practical six-check method for examining a newly discovered GitHub repository before your team commits engineering time to it.

Compare three verified open-source Notion alternatives on license, export, and self-host cost, with a checklist you can apply to any candidate.

A signature can prove who made a record, not whether the policy deciding it came from a trusted committed state.

Your AI assistant cited source code, but which exact version? A practical way to check AI source code provenance with primary, verifiable evidence.

A failure sentence cannot reliably carry its category. Keep the cause as structured data, render the prose from it, and block unknown values.

Exit code zero can conceal skipped or missing tests. Freeze outcomes and judge them against a manifest instead.

A GIT_* variable redirected Ranex checks to the wrong repository. Learn the boundary a git flag cannot enforce and the fix that closed it.

Mutation testing exposed 59 refusal paths no test executed. Learn how to measure the safety net instead of trusting a green suite.

A single run cannot prove a change helped. Freeze the comparison, set the rules first, and keep observations separate from grades.

Learn why a stable-looking test report is not evidence, and how rerunning checks against disk exposed a 12% flaky suite.

A SHA-256 hash identifies approved dependency bytes. It cannot prove that imported code will report your test result honestly.

A citation can be fabricated from memory. Fetch and record the source bytes before you let a design claim borrow their authority.

Ranex gates Ranex. Here are the real failures that came out of pointing a verification kernel at its own test suite, including the ones that had already passed human review.

Better models don’t remove the need to bound an agent’s authority: they increase it. The case for treating AI as delegated labour that needs an accountability apparatus outside itself.

Ranex judges AI-written work by evidence and executable checks, never by model confidence. Here is the whole mechanism: three ports, one kernel, and only one of them produces a verdict.