Reading a report
What each part of a report means, and why the coverage section matters as much as the findings.
A report is laid out to be read top to bottom, and it is ordered by what deserves your attention first.
The posture, and what it means
At the top is a one-sentence read of the repository's state and a score out of 100. Treat the score as a relative indicator that helps you see movement between reviews. It is not a safety rating, and no number here means your code is free of problems.
Findings, most serious first
Each finding carries:
- Where it is — file and line, with a short excerpt so you can see what was matched.
- A severity — how serious it would be if real.
- A confidence — how sure the tooling is that it is real. Low confidence is not a quiet finding, it is an uncertain one.
- A recommended remediation — what to do about it.
- Whether it requires human review — anything the tooling could not settle is marked, and a low-confidence finding is always marked.
Findings marked new appeared for the first time in this review, judged by whether this is the first review their fingerprint has been seen in.
What was not covered
Every report has a coverage section, and it is not a footnote. It states:
- which languages were found and analysed,
- which were found and not analysed, because nothing here reads them,
- which files were skipped, and why,
- and whether any analysis tool failed or was cut short, with the reason.
If half your repository is written in a language Monterva does not analyse, the coverage section says so. A report that finds nothing in the third of your code it actually read is a very different statement from a clean bill of health, and you should be able to tell the two apart at a glance.
Explanations, where they appear
Some reports carry written explanations grouping and prioritising the findings. These are produced by a language model and are visually distinct from everything else, because they are the one part of a report not produced by a deterministic tool.
The model is given findings that already exist and asked for prose about them. It cannot create a finding, remove one, or change a severity — those come from the analysis tools and stand on their own. If explanations are unavailable, the report says so and shows the findings, which is what you came for.