How the gateway works

Tier-1 screening for R packages under a two-tier validation strategy: this tool screens everything, Tier 2 (full validation) receives only what fails or is business-critical.

The assessment pipeline
1
Ingest
CRAN name, GitHub URL or uploaded source tarball; versions resolve against the pinned CRAN snapshot and every tarball is sha256-fingerprinted.
2
Score
An R subprocess runs {riskmetric} 0.2.7 (17 risk metrics). Two-process pattern: the gateway never executes assessed package code — coverage and R CMD check metrics are deliberately excluded.
3
Evidence
Every collected value — CRAN metadata, community signals, scores — is bound to an evidence ID. Network source failures degrade explicitly, never silently.
4
Decide
A versioned, sha256-recorded rule config maps the overall score to GO / GO-WITH-CONDITIONS / NO-GO per intended-use tier, plus per-metric rules that attach conditions. Every rule, fired or not, is shown in the report.
5
Report
Evidence-linked HTML + PDF: no statement without an evidence ID; sections lacking evidence render suppressed instead of fabricated.
6
Audit
Every assessment, signature, publish and remediation joins an append-only, hash-chained audit log; the dashboard verifies the chain on every view.
How the score is built

The overall risk score (0 = low risk, 1 = high risk) is {riskmetric}'s weighted mean of 17 per-metric scores, computed in an isolated R subprocess. For transparency the report also discloses category subscores — each the equal-weighted mean of its member metrics — with the rubric's strategy weights (config v1.1.0, sha256 4ae212e568b1…):

CategoryStrategy weightMember metrics
code0.54 metrics (dependencies, exported_namespace, remote_checks, size_codebase)
documentation0.157 metrics (export_help, has_examples, has_news, has_vignettes, has_website, license, news_current)
maintenance0.24 metrics (bugs_status, has_bug_reports_url, has_maintainer, has_source_control)
popularity0.152 metrics (downloads_1yr, reverse_dependencies)

Category subscores are display-only disclosure; the overall score and the tier thresholds are the decision inputs.

Decisions are tier-relative, never black-box
TierMeaningGO band (overall risk)NO-GO threshold
exploratoryresearch / non-GxP workGO below 0.3NO-GO at/above 0.6
gxp-supportoutput feeds GxP workflows but is not itself the record of truthGO below 0.2NO-GO at/above 0.4
gxp-criticalon the critical path of a regulated decision — GO is unreachable by design (human gate)GO below —NO-GO at/above 0.3

On top of the score bands, 8 per-metric rules (3 critical severity) attach conditions or force escalation — e.g. unresolved bug trackers, missing source control, non-standard licenses, low community usage. Any non-GO outcome in gxp-critical additionally carries the mandatory human-gate conditions (independent verification, double programming).

Governance muscle (GxP)
Why this helps the team — and how it compares to vendor validation

Vendor offerings such as Atorus OpenVal, Appsilon Axon.R and Jumping Rivers Litmus sell per-package validation: deep, service-delivered qualification of individual packages, priced per engagement. They answer "is this package validated?" one package at a time.

This gateway answers the portfolio question continuously and in-house: every package in the platform inventory gets the same evidence-bound screen, a tamper-evident audit trail, and a governed path into the approved repository. That changes the economics and the inspection posture:

This tool never signs off and does not replace Tier-2 full validation; it makes that effort targeted, repeatable and auditable. Classification and sign-off stay with human QA.