Tier-1 screening for R packages under a two-tier validation strategy: this tool screens everything, Tier 2 (full validation) receives only what fails or is business-critical.
The overall risk score (0 = low risk, 1 = high risk) is
{riskmetric}'s weighted mean of 17 per-metric scores,
computed in an isolated R subprocess. For transparency the report also
discloses category subscores — each the equal-weighted mean of its member
metrics — with the rubric's strategy weights (config v1.1.0,
sha256 4ae212e568b1…):
| Category | Strategy weight | Member metrics |
|---|---|---|
| code | 0.5 | 4 metrics (dependencies, exported_namespace, remote_checks, size_codebase) |
| documentation | 0.15 | 7 metrics (export_help, has_examples, has_news, has_vignettes, has_website, license, news_current) |
| maintenance | 0.2 | 4 metrics (bugs_status, has_bug_reports_url, has_maintainer, has_source_control) |
| popularity | 0.15 | 2 metrics (downloads_1yr, reverse_dependencies) |
Category subscores are display-only disclosure; the overall score and the tier thresholds are the decision inputs.
| Tier | Meaning | GO band (overall risk) | NO-GO threshold |
|---|---|---|---|
exploratory | research / non-GxP work | GO below 0.3 | NO-GO at/above 0.6 |
gxp-support | output feeds GxP workflows but is not itself the record of truth | GO below 0.2 | NO-GO at/above 0.4 |
gxp-critical | on the critical path of a regulated decision — GO is unreachable by design (human gate) | GO below — | NO-GO at/above 0.3 |
On top of the score bands, 8 per-metric rules
(3 critical severity) attach conditions or force escalation — e.g.
unresolved bug trackers, missing source control, non-standard licenses,
low community usage. Any non-GO outcome in
gxp-critical additionally carries the mandatory human-gate
conditions (independent verification, double programming).
gxp-critical requires two
distinct signers (dual approval).Vendor offerings such as Atorus OpenVal, Appsilon Axon.R and Jumping Rivers Litmus sell per-package validation: deep, service-delivered qualification of individual packages, priced per engagement. They answer "is this package validated?" one package at a time.
This gateway answers the portfolio question continuously and in-house: every package in the platform inventory gets the same evidence-bound screen, a tamper-evident audit trail, and a governed path into the approved repository. That changes the economics and the inspection posture:
This tool never signs off and does not replace Tier-2 full validation; it makes that effort targeted, repeatable and auditable. Classification and sign-off stay with human QA.