analysis-tools-dev/static-analysis
78.2
Strong · 28 September 2026
2.7k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is an automated cataloging and validation infrastructure for a curated list of developer tools. It uses a Rust-based CI pipeline to enforce contribution criteria, such as star counts and repository age, via pull request checks. The system generates a structured README and JSON API from YAML data files, supporting a wide range of static analysis and linting tools.
Features
Expanded tool catalog with new linters and metadata enhancements
The data/tools directory has been significantly expanded with new YAML definitions for a wide range of static analysis, linting, and formatting tools, including Meziantou.Analyzer and SonarAnalyzer.CSharp for C\#, abaplint and abapOpenChecks for ABAP, actionlint for GitHub Actions, and ast-grep for AST-based code management. Several existing tool entries have been updated or replaced, such as the addition of Biome as the successor to Rome, and the introduction of new metadata fields like 'demos' and 'reviews' for tools such as ast-grep and AST Metrics to provide users with direct access to interactive playgrounds and community feedback.
data/tools · high confidence
Introduce automated PR contribution checks and a new render crate for catalog generation
This change introduces two new CI crates. The \pr-check\ crate automatically evaluates new tool submissions against contribution criteria (minimum 20 stars, 2+ human contributors, 6-month repository age) by fetching GitHub metadata, and generates a Markdown comment to report pass/fail/skip status or request manual review. The \render\ crate generates the project's README catalog and JSON API from tool YAML files, handling tag grouping, deprecation checks via GitHub commit dates, and outputting both Markdown and JSON artifacts.
ci/crates/render · high confidence
Repository restructured with Rust-based rendering engine and AI contribution guidelines
The project has migrated from a manually maintained list to an automated system where the README is generated from YAML data files using a new Rust-based render tool (located in ci/). This change introduces a new contribution workflow: users must now edit YAML files in data/tools/ rather than the README directly, and the repository includes AGENTS.md and CLAUDE.md to provide specific instructions for AI coding assistants to enforce these rules and contribution criteria (e.g., star counts, history). The build process is now managed via a Makefile that invokes Cargo, and the project has adopted an MIT license.
(repo-wide) · high confidence
Dependencies
Modernize CI Rust workspace and update dependencies
The CI tooling has been restructured into a Rust workspace located in the /ci directory, comprising three crates: github-repo for URL parsing, pr-check for pull request validation, and render for catalog display. This migration updates the Rust edition to 2024 and the minimum supported version to 1.98.1. Several dependencies have been upgraded to their latest versions, including reqwest (0.13.5), askama (0.16.1), and serde-saphyr (1.3), while enforcing stricter Clippy lints across the workspace.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 71 → 78 (+7.3)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 99 → 100 (+1.0)
- Architecture 100 → 97 (-3.3)
- Maturity 57 → 64 (+6.5)
- Readiness 84 → 86 (+2.8)
- Security 73 → 88 (+15.8)
- Domain Modelling 100 → 100 (+0.0)
- Performance 100 (new)
Resolved (14)
- Documentation: no project overview (data/README.md)
- Documentation: no usage examples (data/api/README.md)
- Duplicated block (9 lines × 2) (ci/pr-check/src/main.rs)
- Duplicated block (9 lines × 2) (ci/render/src/lib.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- pr_check::check_tool (cognitive 20) (ci/pr-check/src/main.rs)
New (5)
- Duplicate types with near-identical structure. ApiEntry and Entry share the exact same set of properties. ApiEntry adds 'languages', 'other', and 'licenses' as PathBuf, while Entry has 'categories' and 'types' as BTreeSet. The core data model is duplicated, leading to maintenance overhead and potential inconsistency between the two types.
- Duplicate types with near-identical structure. ParsedEntry and Entry share the exact same set of properties (name, categories, tags, license, types, homepage, source, pricing, plans, description, discussion, deprecated, resources, reviews, demos, wrapper). Entry adds methods and a constructor from ParsedEntry, suggesting ParsedEntry is an intermediate state, but the duplication of the entire data model is redundant and confusing.
- High: security finding (details withheld)
- Inconsistent parameter types for similar operations. create_catalog takes a slice of Entry (&[Entry]), while create_api takes a single Entry (Entry). This suggests a potential API design flaw where create_api might be intended for a single entry but is named similarly to create_catalog which handles collections.
- Off the main sequence: github-repo
Changes since last survey
- 27 commits — 27 feature/other, 0 fixes
By area
- (root) — 10 commits
- ci/crates — 4 commits
- data/tools — 4 commits
- ci/pr-check — 3 commits
- .github/workflows — 2 commits
- ci/Cargo.lock — 1 commit
- ci/render — 1 commit
- data/api — 1 commit
- data/collections — 1 commit
Notable commits
- change: Add DepWarden (#1848)
- change: Add LintLang (#1898)
- change: Add skillsaw (#1904)
- change: Bump dtolnay/rust-toolchain (#1908)
- change: Bump reqwest from 0.13.4 to 0.13.5 in /ci (#1893)
- change: Check homepage domain age for hosted tool submissions
- change: Close tool submissions that do not meet contribution criteria (#1897)
- change: Collapse deprecated tools in README sections (#1901)
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Deprecate unavailable tools and repair moved links (#1900)
- change: Exclude automation accounts from contributor eligibility counts (#1899)
- change: Flag generated README changes in contribution checks
- change: Keep contribution guidance focused on eligibility
- …and 7 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
analysis-tools-dev/static-analysis was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 029d415efdae7b23244ef3020bb73ac9ccfed05c — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d46da229e3fd.