AWS Evidence
Delivery repository evidence
Optional evidence about how changes reach an environment. Collected only when a repository is supplied, and deliberately not scored.
What it is
Evidence gathered from a source repository when one is explicitly supplied: workflow presence, branch protection on the default branch, merged pull requests, and recent commit activity.
Why it is not scored
Assessing how changes reach an environment properly requires read access to the source control that produces them. The AWS-only authorization used by this engagement does not grant that.
How GovIntel applies it
It is collected as context. It is excluded from the offered domains and from the published weights, and every pack states that delivery governance is out of scope.
It makes no AWS call and requires no AWS permission.
What it does not mean
Its absence is not a gap in the environment. It is a gap in scope, which is a different statement, and the pack keeps the two apart.
