binghe001/BingheGuide
37.0
Weak · 4 August 2026
381
lines of production code
Python
primary language
6
measurements over time
What this system is
This system is a documentation site generator built on VuePress 2 and Vite, serving as a technical guide or wiki. It provides an automated CI/CD pipeline for building and deploying the site, while enforcing strict Git commit and branch naming conventions through pre-commit and pre-push hooks.
Features
Added CI configuration and build scripts for VuePress 2 migration
The repository now includes a \.codechina-ci.yml\ file to automate the build and deployment process for the site, ensuring consistent builds in the CI/CD pipeline. A new Python script, \generate\_config.py\, has been added to assist in the migration from VuePress 1 to VuePress 2 by converting the existing configuration. Additionally, the \run.sh\ script has been updated to include \npm install\ and \npm run build\ steps before starting the development server, ensuring all dependencies are present. The \.gitignore\ file was also updated to exclude generated build artifacts and new scripts.
(repo-wide) · high confidence
Behavioural changes
Enforced commit message and branch naming conventions via Git hooks
New Git hooks (commit-msg, pre-commit, pre-push) are introduced to enforce structured commit messages and branch naming conventions. The commit-msg hook validates that commit messages follow a specific format (e.g., 'feature:', 'fix:') and optionally include task/bug IDs. The pre-commit and pre-push hooks validate that branch names conform to a defined pattern (e.g., 'feature/abc-xyz-0', 'hotfix/abc-xyz-0'), preventing non-conforming branches from being committed or pushed.
githook · high confidence
Dependencies
Upgrade to VuePress 2 and migrate to Vite bundler
The project has been upgraded from VuePress 1.8.2 to the VuePress 2.0.0-rc.28 release candidate, which utilizes the new Vite-based bundler (@vuepress/bundler-vite) instead of the previous Webpack-based setup. This migration replaces several legacy plugins (such as vuepress-plugin-seo, vuepress-plugin-sitemap, and vuepress-plugin-tags) with updated equivalents or built-in features, while also introducing Vue 3 and Sass support. Additionally, the project name has been changed from 'CodeGuide' to 'BingheGuide'.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 45 → 37 (-7.7)
- Rubric changed (rubric-2026.08.15 → rubric-2026.08.19) — scores are not directly comparable.
Lenses
- Maturity 66 → 52 (-14.6)
- Readiness 23 → 29 (+5.3)
- Security 55 → 60 (+5.0)
- Accessibility 37 (new)
Resolved (289)
- ADR not followed: 使用rarcrack暴力破解RAR,ZIP,7Z压缩包 (docs/md/hack/crack/2022-05-02-001-使用rarcrack暴力破解RAR-ZIP-7Z压缩包.md)
- ADR not followed: 各种一句话木马大全 (docs/md/hack/horse/2022-05-02-001-各种一句话木马大全.md)
- ADR not followed: 数据库提权 (docs/md/hack/raising/2022-05-02-001-数据库提权.md)
- Classify ADR enforcement: Metasploit渗透php-utility-belt程序 (docs/md/hack/tools/2022-04-17-026-Metasploit渗透php-utility-belt程序.md)
- Consequences/trade-offs (e.g. operational cost, latency, complexity) are absent despite strong context and explicit coding-goal focus (docs/md/project/ai/one/coding/2026-01-31-chapter02.md)
- Consequences/trade-offs (e.g. stack depth limits, module-state loss on popm) are absent despite strong context and a concrete example (docs/md/hack/tools/2022-05-02-020-Metasploit之pushm和popm命令.md)
- Consequences/trade-offs are absent despite a strong problem statement and fix (docs/md/middleware/rpc/2023-02-28-《RPC手撸专栏》第fix-04章-修复基于SpringBoot启动服务消费者Netty Group多次连接的问题.md)
- Context/problem (e.g. why these commands matter and what they do when Meterpreter loads) is absent (docs/md/hack/tools/2022-05-02-015-Metasploit基本后渗透命令.md)
- Context/problem and consequences sections are absent (the body reads like a chapter description with no decision or trade-offs) (docs/md/core/spring/ioc/2022-04-04-030-自定义组件如何注入Spring底层的组件.md)
- Context/problem and consequences sections are absent (the body reads like a source-code dump with no problem statement or trade-offs) (docs/md/core/spring/ioc/2022-04-04-021-BeanPostProcessor在Spring底层是如何使用的.md)
- Context/problem and consequences/trade-offs are absent (only author links and install steps present) (docs/md/core/nginx/2023-08-07-《Nginx核心技术》第16章-实现Nginx的高可用负载均衡.md)
- Context/problem and consequences/trade-offs are absent (only exploit command-line steps and results appear) (docs/md/hack/tools/2022-05-02-024-使用Metasploit获取目标的控制权限.md)
- Context/problem and consequences/trade-offs are absent (only project-structure description and dependency setup appear) (docs/md/microservices/springcloudalibaba/2022-04-18-SA实战-开撸-完成通用模块的开发.md)
- Context/problem and consequences/trade-offs are absent (only source-code annotation and inheritance diagram shown) (docs/md/core/spring/ioc/2022-04-04-041-AnnotationAwareAspectJAutoProxyCreator类的调用流程是啥.md)
- Context/problem and consequences/trade-offs are absent; only attack setup (Kali/XP target, Easy File Sharing Web Server 7.2, Metasploit pattern_create.rb used to generate payload) is present (docs/md/hack/tools/2022-05-02-014-使用Metasploit实现基于SEH的缓冲区溢出攻击.md)
- Context/problem and consequences/trade-offs are absent; the body is a bare code example with no rationale or impact discussion (docs/md/hack/sql/2022-05-02-006-SQLServer启动-关闭xp_cmdshell.md)
- Context/problem and consequences/trade-offs are absent; the body is a list of Metasploit commands with no rationale for why each one matters or what it does (docs/md/hack/tools/2022-05-02-016-Metasploit高级后渗透模块.md)
- Context/problem and consequences/trade-offs are absent; the body is a one-line title repeated verbatim with no problem statement or decision (docs/md/hack/client/2022-05-02-006-使用Metasploit实现对Linux客户端的渗透.md)
- Context/problem and consequences/trade-offs are absent; the body is a procedural walkthrough of Metasploit payload selection and bypassuac exploit with no rationale for why this targeting path was chosen or its risks (docs/md/hack/raising/2022-05-02-005-Metasploit-Win10提权.md)
- Context/problem and consequences/trade-offs are absent; the body is a single script with no problem statement or decision (docs/md/hack/tools/2022-05-02-035-Armitage使用Cortana实现后渗透攻击.md)
- …and 269 more
New (8)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Workflow token permissions not restricted
- complexity unreadable for .py — churn × complexity hotspots could not be measured
- single-maintainer — knowledge-concentration (bus factor) risk
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
binghe001/BingheGuide was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 4 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 65eb59bf70b66ad1c020ddd0d92b7fa27e7fb9ec — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.