PASS, REVIEW and BLOCK, the score behind them, and the four verdicts for what you are about to do with the code.
The decision page shows one of five badges. The first three are verdicts about the repository; the last two are statements about RepoGates itself — and the difference matters.
| Badge | What happened | What you should do |
|---|---|---|
| PASS | No finding reached your policy's warn or block level. The download proceeds — you normally never see a page for a PASS. | Nothing. A PASS is not a guarantee; it means none of the 22 checks fired at a level your policy acts on. |
| WARNING (REVIEW) | The repository has findings worth reading — for example a very young account, an auto-executing devcontainer, or no licence. The download was stopped and the findings are listed. | Read the findings. If you understand and accept them, click Proceed with download — recorded, and remembered for the rest of the browser session for that repository. |
| BLOCKED (BLOCK) | A finding your policy blocks on — or the repository is listed in an active malware campaign. The download was cancelled before it reached your downloads folder. | Stop and read why. If your policy allows overrides you can Override and download anyway — always recorded. Believe the block is wrong? Report it. |
| NOT CHECKED (UNCHECKED) | The repository was not assessed: your trial is used up or expired, sign-in is needed, or the account is over its device limit. Explicitly not a judgement about the repository. | Decide with your eyes open: sign in / upgrade / remove a device, or proceed knowing nothing was examined. Known malware is still blocked either way. |
| SERVICE UNREACHABLE | RepoGates could not reach its verdict service and your policy fails closed, so the download was stopped. Also not a judgement about the repository. | Retry in a moment — outage decisions are never cached. If you prefer downloads to continue during an outage, switch to fail-open in Options and accept what that means. |
Findings carry a severity chip — CRIT, HIGH, MED,
INFO — and a check name. Policy maps each fired check to an
action; by default CRIT blocks, HIGH and MED warn, INFO is logged only,
with per-check exceptions (for example hidden-unicode and
nested-bare-repo always block by default). If an AI surface
led you to the repository, a warn-grade verdict is escalated to a block
(why).
| Verdict | Meaning |
|---|---|
| PASS | No finding reached your policy's warn or block threshold. The download proceeds. |
| REVIEW | Findings worth reading. The download is stopped and shown to you; you may proceed, and that is recorded. |
| BLOCK | A finding your policy blocks on, or a listing in an active malware campaign. Stopped; override only if permitted, always recorded. |
| NOT CHECKED | The repository was not assessed — trial used up, sign-in needed, or device limit. This is not a judgement about the repository. Known malware is still blocked. |
The full table, with what to do in each case, is in the personal guide.