Engineering practice is published as declared figures with a guard, not as prose
Decided
/security#engineering publishes four claims about what runs before a change ships — test modules and coverage gates, the verify chain and the claim rules, the migration jobs, the Lighthouse audit. Every figure in them is declared once in lib/engineering-practice.ts and re-derived from its artifact by scripts/check-engineering-practice.mjs, which is the fifteenth check in verify and runs in prebuild.
Affects: lib/engineering-practice.ts, scripts/check-engineering-practice.mjs, app/security/page.tsx, package.json
What the alternative was. The obvious move was a sentence: "200+ automated tests, coverage thresholds enforced in CI." It would have taken two minutes and it would have been true on the day it was written. That is the whole problem. Of every figure on this site, a claim about testing discipline is the worst one to let decay, because it decays silently — nobody re-reads /security when they delete a test file — and it decays on the page a procurement reviewer opens to decide whether this team can be trusted with their data. A stale claim about rigour is worse than no claim, because it is itself evidence of the defect it denies.
Why declare-here-and-check-there rather than import. Every one of these figures is a fact about a file that is not a module. package.json scripts and workflow YAML cannot be imported into a React Server Component, and the Lighthouse JSON is forty megabytes. So the module declares and the script re-derives: test module count and coverage flags from the test:coverage command, the verify count from the chain, the claim-rule count from the RULES array, the migration count from the directory, the CI job names by substring against ci.yml, and the Lighthouse scores from the committed reports.
Min, not max, for any figure published as a single number. Accessibility, best practices and SEO are stated as one number each, so the check compares the published figure against the *lowest* observed run. Checked against the maximum, a route that regressed to 96 while four others held 100 would pass, and the page would keep saying 100. Performance is published as a range because it is one.
What it deliberately does not do. It does not run the tests and it does not run Lighthouse. A guard that re-ran everything would take twenty minutes and get skipped. This one takes milliseconds and catches the entire class of drift that matters, which is the published number and the real one parting company.
Proven able to fail. MIGRATION_COUNT was set to 6 and LIGHTHOUSE_SCORES.accessibility to 98; the check exited 1 naming both, the artifact each was derived from, and the true value. Restored, it exits 0. The same deliberate-break evidence check:links carries in D-046.
It caught its own author on the first run. ISOLATION_JOB_NAME was declared as "API — Postgres RLS policies", which is a plausible name for a job that does not exist. The real one is "API — tenant isolation against Postgres". Wiring the check into verify then invalidated VERIFY_CHECK_COUNT, which had to go from 14 to 15 — the guard failing on the act of adding itself is the clearest possible demonstration that it is measuring the thing it claims to measure.
What would make this wrong: a figure that stops being derivable from a committed artifact. If Lighthouse moved to a hosted dashboard with no committed JSON, the honest response is to delete the claim, not to keep the number and drop the check.