What an Assessment Contains
Each assessed component version carries:- A band — how urgent the situation is, shown as a badge, never as a raw numeric score or weight.
- An action — for example, replace or upgrade, with a plain-language summary.
- Signals — the individual facts behind the action, ordered blocking, then concern, then info, each with a link to its evidence.
- Confidence, with the reasons behind it.
- An assessment date and source.
Where It Appears
The Review Workspace
A Remediation group appears on the component evidence card, after Lifecycle, on both the finding rail and the component rail. The component list also shows the band on each row, so you can see which components are most urgent before opening any of them. See Triaging Findings.Pull-Request Comments and Self-Checks
Earnie decides remediation advice with one chain, shared by inline pull-request comments, the summary comment, Self-checks, and an agent’searnie_review_code call. Where a remediation assessment exists, it comes first in that chain, ahead of a bare fixed_versions value or a generic suggestion, so the same finding gets the same advice wherever a developer or agent looks. When there’s no assessment, Earnie falls back to the next best evidence it has, such as an explicit fixed version or a policy parameter.
For dotted numeric releases, fixed-version advice picks the lowest reported fix above the installed version. If every reported numeric fix is equal to or below it, Earnie uses the next available advice instead of recommending a downgrade. Versions with suffixes or other formats keep the upstream version strings, because Earnie doesn’t infer their package-specific ordering.
MCP
earnie_get_finding includes the full assessment, and earnie_search_findings rows carry a remediation priority and band, so an agent can triage by urgency without opening every finding. See Using Earnie Through MCP.