CanineCC/kennel.canine.dev
81.8
Strong · 7 October 2026
897.8k
lines of production code
C#
primary language
116
measurements over time
What this system is
This system is a polyglot static analysis engine that evaluates software repositories across more than a dozen programming languages for structural quality, security vulnerabilities, and architectural integrity. It combines deep semantic scanning with infrastructure and supply-chain analysis to generate deterministic health reports, scorecards, and compliance documentation. The platform also includes an operator console for managing scans and billing, providing a comprehensive assessment of software project health.
Features
AX1 Captive Dependencies check now detects non-.NET containers and hand-rolled DI
The AX1 architecture check for captive dependencies (singletons capturing shorter-lived scoped or transient services) has been expanded beyond .NET. It now reads Spring bean lifetimes and detects hand-rolled dependency-injection containers in Python, JavaScript/TypeScript, Swift, Java, Kotlin, and Go. For languages where no container is found, the check distinguishes between 'not applicable' (e.g., Rust or BEAM ecosystems where captives are structurally impossible) and 'language reach' (containers that allow captives but are not yet modeled), providing specific reasons instead of a generic unanalyzed card.
engine/src/Scanner/ArchitectureModel · high confidence
Add kind-sweep tool for repository classification and D20 gap analysis
Introduces a new command-line tool in \engine/tools/kind-sweep\ that classifies repositories by kind using \SourceClassifier\ and optionally runs D20 engine-gap analysis when the \KINDSWEEP\_D20\ environment variable is set. This tool provides a way to audit repository types and identify specific engineering gaps for each root directory.
engine/tools/kind-sweep · high confidence
Added Erlang process-state fixture modules for cohesion analysis
The cohesion-fixture sidecar now includes a comprehensive set of Erlang modules (e.g., BareMapState, BoundRecordState, Registry, Spellings) that serve as controlled test cases for the LCOM4 metric. These modules cover various Erlang process patterns, including gen\_server and gen\_statem behaviors, state representation via records and maps, and specific coding idioms like branched init returns, shadowed variables, and pure helper functions. This allows the analysis engine to accurately measure cohesion by distinguishing between actual state touches and trivial or non-state interactions.
engine/sidecars/erlang-frontend/cohesion-fixture · high confidence
Added Go and Python test discovery and reliability analysis
The engine now discovers and runs test suites for Go and Python repositories, which were previously reported as gaps. For Go, the engine identifies modules via \go.mod\, counts test cases in \\_test.go\ files, and executes \go test\ with \-count=1\ to detect flakiness. For Python, it scans for pytest/unittest files, counts test functions, installs dependencies in a virtual environment, and runs pytest with cache clearing to reliably detect flaky tests.
engine/src/Core/Languages/Go/Testing, engine/src/Core/Languages/Python/Testing · high confidence
Added PHP domain-driven design conventions for static analysis
The engine now includes specific rules to identify PHP Value Objects, ORM Entities, Domain Events, and Aggregates. This enables accurate detection of DDD patterns in PHP codebases by recognizing Doctrine and Laravel markers, as well as structural indicators like readonly classes and encapsulated state.
engine/src/Core/Languages/Php · high confidence
Added Rust cohesion fixture for D6 analysis
Added a new Rust library (\cohesion-fixture\) containing structural type definitions (such as \Registry\, \Ledger\, \Length\, and \Framed\) designed to exercise specific code cohesion metrics (LCOM4) and Rust language features like pattern matching, pinning, and fluent builders. This fixture serves as test data for the D6 analysis engine to validate its ability to parse and analyze Rust source code facts.
engine/sidecars/rust-frontend/cohesion-fixture · high confidence
Added Swift module-route survey tool
A new Python script, \module-route-survey.py\, has been added to the Swift frontend tools to analyze how product files are routed to module names. This tool helps identify files that fall into a catch-all bucket due to ambiguous repository structures (such as flat layouts versus packages with targets), allowing developers to assess the impact of proposed routing rules before implementation.
engine/sidecars/swift-frontend/tools · high confidence
Added benchmark harness for the ingestion hot path
A new benchmark suite has been added to measure the performance of the ingestion pipeline, specifically targeting the cost of deserializing and processing large fingerprint bundles (up to 20,000 rows) and sidecar contracts. The suite includes benchmarks for parsing fingerprints, normalizing paths, and extracting public findings, with a focus on memory allocation via the MemoryDiagnoser. It also introduces a CI smoke-test mode (\--ci\) that validates the benchmarks compile and execute without asserting timing thresholds, ensuring the suite remains functional as the codebase evolves.
benchmarks · high confidence
Added entry-type-eval tool to audit changelog entry classification accuracy
A new diagnostic harness has been added to the engine/tools/entry-type-eval directory. This tool re-evaluates previously stored changelog entries by re-narrating their diffs and commit messages through the current LLM configuration, then compares the newly generated entry types and headlines against the stored values. It outputs a TSV file showing the discrepancies (e.g., BehavioralChange -\> Feature) and prints a summary of type transitions, allowing users to assess the consistency and accuracy of the changelog generation pipeline.
engine/tools/entry-type-eval · high confidence
Added noise-probe tool for deterministic A/B testing of detector families
A new command-line utility, \noise-probe\, has been added to \engine/tools/noise-probe\ to generate baseline data for A/B testing. It runs specific detector families (readiness, secrets, or compliance) over a list of repository roots and outputs findings as a TSV file. The tool is designed to be deterministic by using a parse-only approach for compliance analysis and avoiding network/LLM calls, ensuring consistent results for comparing different analysis configurations.
engine/tools/noise-probe · high confidence
Added runtime-evidence specimen generators for end-to-end testing
Engine tooling now includes two shell scripts, \make-static-specimen.sh\ and \make-booted-specimen.sh\, which generate synthetic repository fixtures to exercise the ADR-0014 and ADR-0017 runtime tiers. The static specimen creates a Storybook-shaped build to test the static render path (AXR1 + AXP1), while the booted specimen provisions an nginx stack to test the bootable path (AXR1 + AXP1 + AXH1), including real HTTP response headers. Both fixtures intentionally contain known accessibility defects and egress attempts to validate the engine's scanning and evidence collection capabilities end-to-end.
engine/tools/runtime-specimens · high confidence
Analyzer image now supports nested Docker execution for runtime evidence scans
The analyzer container now includes a new entrypoint script that conditionally starts a nested Docker daemon when the CODEHEALTH\_RUNTIME\_EVIDENCE environment variable is set. This enables the engine to boot and scan customer-declared stacks (e.g., .NET, Node.js) inside the container, with support for registry mirrors and proxy configuration for builds. The image also bundles pinned toolchains for multiple languages (Go, Rust, Swift, PHP, Ruby, TS/JS, JVM) and .NET SDKs to support deep-scan analysis across polyglot repositories.
engine/docker/analyzer · high confidence
Android application boot and companion support added to runtime detection
The engine now detects and boots Android applications using their own Gradle wrapper and runs them on an emulator, introducing a new \AndroidApp\ boot mechanism. This mechanism is treated as the weakest boot path and is consulted last unless no stronger mechanism (like Docker or Aspire) is present. Additionally, if a stronger boot mechanism is detected, any co-located Android application is identified as a companion, allowing the runtime to crawl its accessibility tree after the primary service has booted. The detection logic requires the presence of a \gradlew\ wrapper and an \AndroidManifest.xml\ to distinguish actual applications from library modules or Flutter sub-projects.
engine/src/Core/RuntimeBoot · high confidence
Automated provisioning and validation of social identity providers
A new script, deploy/keycloak/add-identity-provider.sh, allows administrators to programmatically add or update social login providers (such as Bitbucket and Microsoft) in the Keycloak realm. The script handles credential management securely via base64-encoded environment variables and includes specific validation logic: for Microsoft, it verifies that the client credentials can actually obtain a token to prevent configuration errors that only manifest after user consent, and for all providers, it confirms the social login button appears on the rendered login page.
deploy/keycloak · high confidence
Blue/green deployment and scheduled operations via systemd units
The deployment infrastructure now supports blue/green releases for the Admin, Assay, and Watchdog web applications, as well as the preprod and production scan workers, through dedicated systemd service units (e.g., \kennel-admin-blue.service\, \kennel-worker@.service\). These units manage the dual-colour application instances, handling environment configuration, port assignments, and drain timeouts to ensure safe traffic switching. Additionally, the system introduces local, clock-based scheduling for critical operations: nightly database backups (\kennel-db-backup.timer\), nightly promotions from preprod to prod (\kennel-nightly-promote.timer\), and daily verification that backups successfully reached the NAS (\nas-backup-check.timer\). A new mechanism also allows the admin console to trigger promotions by writing a request file, which is picked up by \kennel-promote.path\ and executed with proper locking and checkout synchronization.
deploy/systemd · high confidence
C2 access-control scoring now supports JavaScript/TypeScript and default-deny fallback policies
The C2 compliance card now evaluates access controls in JavaScript/TypeScript repositories (using route guards, Nest guards/decorators, auth-gate middleware, and Supabase row-level security) in addition to .NET, and introduces a default-deny fallback policy so that \[AllowAnonymous\] becomes an opt-out rather than an open surface. For .NET, the analyzer also smooths the imperative guard scoring cliff (ramping credit up to three call sites) and adds specific findings for self-hosted RPC/IPC service hosts without authorization.
engine/src/Scanner/Compliance/C2 · high confidence
C3 Audit Trail dimension now scores JavaScript/TypeScript repositories
The C3 compliance card, which evaluates whether changes to personal data are recorded, now extends its analysis beyond .NET to JavaScript and TypeScript projects. The engine reads persisted data models (such as TypeORM, Prisma, or Sequelize entities) from disk to detect personal data, and scans for structural audit mechanisms like ORM write hooks, audit-log tables, or change-history plugins. This allows the audit trail score to be calculated for JS/TS codebases, whereas previously it would abstain or report not assessed for these languages.
engine/src/Scanner/Compliance/C3 · high confidence
Cancellation propagation check now covers JavaScript and TypeScript
The X2 Cancellation propagation dimension, which previously only analyzed C\# async methods for CancellationToken usage, now also scans JavaScript and TypeScript source files. For repositories without .NET code, the engine reads .js/.ts files to identify named async functions that make cancellable requests (such as fetch, axios, ky, or ofetch) and verifies whether they accept or propagate an AbortSignal. This ensures that in-flight work can be stopped when its caller gives up, even in non-.NET projects.
engine/src/Scanner/Defects/X2 · high confidence
Changelog engine introduces graded draft confidence and dual-form rendering
The changelog reporting engine now assesses the trustworthiness of each generated draft, flagging windows as ReleaseScale (large releases), LowSignal (dominated by housekeeping or ungrounded diffs), or Insufficient (too little readable signal to describe reliably). The renderer presents these assessments with appropriate caveats and, for large releases, includes a synthesized summary. It also outputs the changelog in both Markdown and JSON formats (dual-form), grouping entries by type in a fixed severity order. Additionally, the engine splits long histories into chronological eras for the system overview, providing a high-level narrative of how the system evolved over time.
engine/src/CodeHealth.Reporting/Changelog · high confidence
D14 License Compliance now grades 16 languages and discloses ungraded ecosystems in polyglot repos
The D14 License Compliance dimension has been expanded to grade license compliance for 16 languages (C\#, F\#, VB, Ruby, Rust, Elixir, Erlang, Java, Kotlin, Scala, Python, TypeScript, Go, Dart, Swift, and PHP) by integrating specific license collectors for each ecosystem (e.g., Maven, SBT, Go deps.dev, Pub.dev, SwiftPM). For polyglot repositories where only one ecosystem's licenses are graded, the engine now explicitly discloses which other declared ecosystems were not graded, preventing a clean score from being misinterpreted as a full-license clearance.
engine/src/Scanner/Security/D14 · high confidence
D22 Internal API Consistency dimension is now independently shippable and supports non-.NET ecosystems
The D22 (Internal API Consistency) analysis dimension has been split from D23 into its own assembly and registration, allowing it to be enabled independently. The analyzer now collects the public API surface from non-.NET ecosystems (such as npm, Ruby, Python, Go, and Swift) using a neutral model collector when Roslyn projects are absent, and specifically handles build-less C\# trees (like Unity UPM packages) via a dedicated collector. This ensures that repositories without C\#/VB source files are no longer incorrectly flagged with a missing-collector gap, and the LLM-based consistency evaluation is properly scoped to the actual exposed public surface.
engine/src/Scanner/ArchitectureJudged/D22 · high confidence
D5 Coupling dimension now measures main-sequence distance and coupling across non-.NET ecosystems
The D5 architecture dimension now extends its coupling analysis and main-sequence distance calculations beyond .NET projects to include Gradle, Maven, Cargo, npm, Go, Python, SwiftPM, sbt, Composer, OTP, and Pub ecosystems. This change introduces a new ModuleGraphCoupling component that computes Martin's afferent/efferent/instability metrics and abstractness over these module graphs, ensuring that test, benchmark, and sample projects are excluded from stability judgments. The dimension also registers its own dependencies via D5CouplingRegistration and renders dependency graphs as SVGs using DotGraphRenderer, providing a unified view of architectural coupling across polyglot codebases.
engine/src/Scanner/Architecture/D5 · high confidence
D6 Cohesion (LCOM4) now supports 15 languages and abstains on unmeasurable code
The D6 Cohesion analyzer now reads LCOM4 for 15 languages (C\#, VB, Go, Scala, Swift, Dart, Java, Python, Kotlin, TypeScript, JavaScript, PHP, Ruby, Rust, Erlang, and Elixir) instead of only C\# and VB. It also abstains with a NotApplicable score when a repository's production source is in a language it cannot read, or when the code model lacks method bodies or state records, preventing false-perfect scores on unmeasurable code.
engine/src/Scanner/Architecture/D6 · high confidence
D8 Code Coverage dimension now supports Swift and Node.js test suites
The D8 Code Coverage dimension has been expanded to measure test coverage for Swift and Node.js ecosystems alongside existing .NET support. The new \CoverageAnalyzer\ implementation detects and runs Swift (\swift test\) and Node.js (\node --test\/\bun\/\deno\) test suites, ensuring that polyglot repositories are not incorrectly flagged as having unmeasured coverage for these languages. The dimension also improves accuracy by detecting test projects located outside the main solution file and handling test code guarded by build symbols, while registering the necessary collectors and dependencies via \D8CoverageRegistration\.
engine/src/Scanner/Testing/D8 · high confidence
Dependency hygiene (D12) analyzer and registration
The engine now includes the D12 dependency hygiene dimension, which assesses the currency (outdated, vulnerable, deprecated) of dependencies across multiple ecosystems including .NET (NuGet), npm, Python (PyPI), Java (Maven/Gradle), Go, Ruby, Rust, PHP, Elixir/Erlang, Swift, Unity, and Dart. This change introduces the core analyzer logic, specific handlers for edge cases (such as .NET repositories that also use npm, or trees with no declared dependencies), and the dependency injection registration for all required ecosystem collectors and registry clients.
engine/src/Scanner/Dependencies/D12 · high confidence
Deterministic changelog engine with typed, located change entries
The changelog generation engine now uses a new deterministic fusion system that groups commits into typed, located change entries. It classifies changes into specific types including Feature, BehavioralChange, Fix, Security, Architecture, Api, TestCoverage, Dependencies, and Noise, and attributes each entry to a specific location (such as a bounded context, top-level directory, or cross-cutting areas like (api-surface) or (security)). The system filters out noise, handles dependency waves, and ensures reproducible output by using structural deltas and architecture maps to ground entries in actual code changes.
engine/src/CodeHealth.Reporting/Changelog/Fusion · high confidence
Egress allowlist now supports operator-defined extensions with safe in-place updates
Operators can now extend the analyzer's egress allowlist by dropping configuration files into the operator extension directory, which are appended to the base squid configuration. To prevent disrupting in-flight scans during deployments, the egress proxy (squid) is reconfigured in-place using \squid -k reconfigure\ when only the allowlist changes, rather than being recreated. This change also introduces a weekly egress-deny-report to aggregate denied requests, helping operators identify legitimate sources that need to be added to the allowlist.
deploy/engine-runtime/egress · high confidence
Encryption at rest for scan artifacts and local OCI registry for image pinning
Scan artifacts (HTML, PDF, CSV, SARIF, SBOM) are now persisted on a dedicated LUKS2-encrypted NVMe data disk (\/mnt/wd-secure\) rather than the plain root filesystem, ensuring data protection if the drive is removed or stolen. Additionally, a local OCI registry is introduced to support rubric-image pinning; this registry runs as a systemd-managed Docker container bound to localhost:5005, storing per-rubric analyzer tags on disk to ensure they survive reboots and remain isolated from external access.
deploy/engine-runtime · high confidence
Engine relocated to engine/ with .slnx support and edition-disposition build enforcement
The CodeHealth analysis engine has been relocated to the engine/ directory, introducing a new CodeHealth.sln solution file and a comprehensive .editorconfig that enforces C\# 13 style rules and suppresses specific analyzers (e.g., CS1591, CA1031) with documented justifications. The build system now enforces edition disposition at compile time via Directory.Build.targets, requiring every dimension slice to declare its edition status (Included, WithheldCommercial, etc.) to prevent logic leakage. Additionally, the engine now supports the modern .slnx solution format through SlnxProjectReader and uses SolutionCandidateRanker to consistently select the best solution candidate based on product vs. tooling surface, ensuring stable analysis across different loading contexts.
engine · high confidence
Erlang test reliability measurement and domain conventions scaffold
The engine now measures flakiness for Erlang repositories by discovering rebar3 projects and re-running EUnit and Common Test suites, addressing the previous gap where Erlang code was excluded from reliability scoring. This includes handling rebar3's provider-chain behavior, ensuring reports are generated via Surefire-style XML, and correctly identifying property checks that cannot have their seeds pinned. Additionally, the engine introduces Erlang-specific domain conventions to correctly classify immutable records as value objects and exempt them from anemia and persistence-model checks, while stubbing out more complex OTP and event-sourcing detection rules for future refinement.
engine/src/Core/Languages/Erlang · high confidence
Expanded dependency detection for Apple, PHP, and Rust ecosystems
The engine now detects third-party package consumption on Apple platforms by checking for CocoaPods (Podfile, .podspec with dependencies) and Carthage (Cartfile) presence, preventing false-clean licence verdicts when SwiftPM is empty but other managers are used. It adds support for reading direct production dependencies from Bun lockfiles (bun.lock) and improves PHP Composer currency checks by correctly handling abandoned packages and platform-specific requirements. For Rust, the Cargo reader now correctly resolves workspace-catalogued dependencies and distinguishes between direct and transitive edges for currency grading, while also fixing version comparison logic for 0.x crates.
engine/src/Core/Dependencies · high confidence
Expanded ecosystem support for public API surface measurement
The engine now measures the public API surface for Android, Rust, Unity, and Swift ecosystems, in addition to the previously supported JVM, .NET, Python, PHP, Ruby, and Go. New collectors detect intentional publication acts—such as Android library modules with explicit Maven publication declarations, Rust crates with a defined library target, Unity UPM packages, and Swift packages with enumerated library products—and extract their exposed signatures. This change enables the D22 dimension to score API consistency across these additional platforms, while maintaining strict abstention for ecosystems where the publication act cannot be reliably determined from source text alone (e.g., Scala, Go).
engine/src/Core/Api · high confidence
Expanded markup detection for Astro and host-language builder DSLs
The engine now detects and parses markup in Astro components and a wide range of host-language builder DSLs (Kotlin, F\#, Dart, and JavaScript/TypeScript variants), ensuring that frontends written in these styles are included in accessibility and quality scoring rather than being reported as unread. Specifically, Astro components are parsed by blanking frontmatter and raw-text blocks before delegating to the JSX producer, while a new Builder DSL producer handles function-call-based markup for kotlinx.html, Giraffe/Falco, Jaspr, Feliz, Bolero, Compose HTML, kotlin-react, Sutil, Fun.Blazor, Oxpecker, fritz2, KVision, and OverReact. This change closes the remaining gaps in the accessibility family, reducing unsupported cells to zero.
engine/src/Core/Markup · high confidence
Expanded test reliability and coverage analysis for JVM, Swift, and non-C\# languages
The engine now supports test reliability (D11) and coverage (D8) analysis for Java, Kotlin, and Swift ecosystems, closing previous gaps where these repositories were skipped. A new JVM test reliability collector re-runs Maven and Gradle suites to detect flaky tests, handling specific build-tool behaviors like Gradle's incremental caching and proxy configuration. A neutral test census (CodeModelTestCensus) enables D9 and D10 to count and classify tests in non-C\# languages (e.g., Swift, Python, Go) by reading sidecar models, ensuring these languages are no longer invisible to test quality metrics. Coverage reporting now includes a detailed outcome classification (CoverageOutcome) to distinguish between environment failures, repo build errors, and missing collectors, and supports multi-ecosystem reports (e.g., .NET + Node, .NET + Swift) to provide accurate coverage figures for polyglot repositories.
engine/src/Core/TestContracts · high confidence
F\# code model provider implementation
Added the F\# provider (CodeHealth.CodeModel.FSharp) to the engine, implementing the ICodeModel interface to expose F\# types, members, and bodies to the analysis pipeline. This includes a source-only fallback (FSharpSyntaxModel) that parses untyped syntax trees to support offline or un-restorable projects, and a typed path (FSharpProvider) using FSharp.Compiler.Service for accurate control-flow and call-site analysis. The provider correctly maps F\# constructs (modules, discriminated unions, module values) to the neutral model, ensuring F\# code is analyzed with the same structural and behavioral metrics as C\# and VB.
engine/src/CodeHealth.CodeModel.FSharp · high confidence
F\# language support: source masking, domain conventions, and test discovery
The engine now supports analyzing F\# codebases. A new source masker blanks comments, preprocessor directives, and string contents while preserving offsets for accurate defect reporting. Domain conventions recognize F\# idioms, identifying aggregates as modules with fold functions, events as discriminated unions, and value objects as records or single-case unions, ensuring DDD patterns are correctly interpreted for this language. Additionally, a dedicated test project scanner discovers .fsproj files on disk, allowing the engine to locate and run F\# test suites even when the Roslyn workspace cannot load them.
engine/src/Core/Languages/FSharp · high confidence
GD1 now detects unfinished and placeholder code in JavaScript and TypeScript
The GD1 (Generation Debt) check, which previously only analyzed C\# code, now also scans JavaScript and TypeScript files for unfinished stubs (functions that only throw a "not implemented" error) and placeholder text (such as lorem ipsum or changeme strings) left in shipped code. This expansion ensures that non-.NET repositories, particularly those using Vite and React, are no longer excluded from this quality signature analysis, providing a consistent view of generated scaffolding residue across the entire codebase.
engine/src/Scanner/Incompleteness/GD1 · high confidence
Go dependency analysis now scores currency, licenses, and reachability
The engine now fully supports Go dependency analysis across three dimensions that were previously unscored or missing. Dependency currency (D12) is now measured by querying the Go module proxy for outdated or deprecated modules, while license compliance (D14) is graded by fetching SPDX identifiers from the deps.dev API. Additionally, dependency reachability (R3.1/R3.2b) is determined by lexically scanning Go source files to identify which modules are imported in production, test, or tooling contexts, allowing for precise vulnerability impact assessment.
engine/src/Core/Languages/Go/Dependencies · high confidence
Go sidecar introduces schema version 7 with new type and body metadata
The Go sidecar now emits NDJSON snapshots using schema version 7, adding four new carriers to the output: \embeddedTypes\ to track Go struct and interface embedding (which is composition, not inheritance), \underlyingType\ for defined types like strong-typed IDs, \receiverIsPointer\ on methods to indicate mutability potential, and \tags\ for struct field metadata. The body analysis now includes \Goto\ as a cognitive-only branch contributor, supports type-switches and select statements, and implements a data-literal mask to prevent false-positive clone detection on composite literal tables. Additionally, the sidecar now recovers build-constrained files by re-scanning under different GOOS and custom build tags, ensuring that platform-specific or tag-gated code is included in the analysis.
engine/sidecars/go · high confidence
IC1 incompleteness analysis now covers JavaScript and TypeScript
The IC1 incompleteness dimension, which previously analyzed only C\# code, now extends its reach to JavaScript and TypeScript repositories. This change introduces a new analyzer path that detects unfinished work in JS/TS source files by shape—identifying patterns such as functions that only throw "not implemented" errors, empty or hollow bodies, fake-async functions that never await, dead branches, skeleton classes, and disabled tests. The analysis is registered as a standalone dimension (IC1) and applies to production JavaScript/TypeScript files, ensuring that repositories without .NET code are no longer left with a language-reach gap for this specific quality metric.
engine/src/Scanner/Incompleteness/IC1 · high confidence
Improved test detection and coverage measurement accuracy
The engine now more accurately identifies and measures test coverage by detecting coverage programs already present in CI (checking for Codecov/Coveralls configs and tool invocations), excluding co-located test files from production code metrics, and identifying test files silently excluded from compilation via MSBuild. It also provides precise, ecosystem-specific advice for generating coverage reports when the engine cannot run the suite directly, and improves the Coverlet coverage collector with caching and better error handling.
engine/src/Core/Testing · high confidence
Initial repository scaffolding and CI security configuration
The repository is initialized with a DDD/ES/VSA monorepo structure, including foundational configuration files such as \.editorconfig\ for C\# and markup style, \.gitattributes\ to mark tool-emitted artifacts as linguist-generated, and \.gitleaks.toml\ and \.gitleaksignore\ to configure the secret-scanning gate. The gitleaks configuration extends default rules and explicitly allowlists specific paths containing detector rule definitions, test fixtures, and third-party specimens to prevent false positives, while fingerprinting specific historical commits to unblock preprod deploys that were blocked by false secret matches.
(repo-wide) · high confidence
Introduce Dart sidecar for code analysis
Adds the Dart frontend sidecar entry point, which parses Dart source files using the analyzer package and emits an NDJSON snapshot (schema version 19) for the engine. This enables the detection of Dart language metrics, including method parameter types, field properties, and body effects, by walking the AST and writing structured facts about types, methods, and fields.
engine/sidecars/dart-frontend/bin · high confidence
Introduce OpenAI-compatible HTTP client with queue re-queuing and timeout handling
Added the OpenAI-compatible HTTP client boundary (IOpenAiCompatibleHttpClient and its implementation) to handle chat-completion requests. The client now automatically re-queues calls refused by the proxy (503 with X-Wd-Llm-Timeout: queue) instead of failing immediately, ensuring that queued calls are never refused but rather waited for within the caller's budget. It also distinguishes between client-side timeouts (synthesized as 504 with a specific flag) and infrastructure failures, and correctly handles null content from reasoning models by preserving the finish reason.
engine/src/CodeHealth.Llm.OpenAiCompatible/Http · high confidence
Introduce strongly-typed IDs for AccessGrants aggregates
The AccessGrants domain now uses strongly-typed identity structs (AccessGrantId and AccessRequestId) instead of raw Guids. This change ensures that grant and request identifiers are type-safe at compile time, preventing accidental mixing of IDs across different aggregate types.
src/Kennel.Core · high confidence
Introduces D34 Knowledge Freshness dimension to detect orphaned code
Adds the D34 Knowledge Freshness analyzer, which identifies source files where living knowledge has faded (orphaned files) by evaluating commit history decay. This new dimension registers as a standalone service and emits a specific dimension ID, allowing users to detect entrenched silos where no current team member understands legacy modules, distinct from the existing Bus Factor (D16) analysis.
engine/src/Scanner/GitMining/D34 · high confidence
Introduces foundational DDD and event-sourcing primitives for the shared kernel
This change adds the core building blocks for the domain model and event-sourcing infrastructure within the shared kernel. It introduces base classes for Domain-Driven Design entities, including \AggregateRoot\ for managing event-sourced state transitions, \Entity\ for identity-based equality, and \ValueObject\ for value-based equality. It also defines the \IDomainEvent\ marker interface and a \Result\ type for handling expected operation failures without exceptions. On the event-sourcing side, it provides the \IEventStore\ and \IEventSourcedRepository\ abstractions for appending and reading event streams with optimistic concurrency, along with \EventEnvelope\ to distinguish between effective time (\OccurredAt\) and transaction time (\RecordedAt\). Additionally, it establishes a registry for event type mappings (\EventTypeMapping\, \IEventTypeMap\) to handle schema versioning and read-time upcasting, and introduces a family of strongly-typed IDs (e.g., \UserId\, \RepositoryId\, \ScanRunId\) with JSON converters to ensure type safety while maintaining backward-compatible wire formats.
src/Kennel.SharedKernel · high confidence
Introduction of a language-neutral code model seam
The engine now exposes a language-neutral \ICodeModel\ interface that replaces direct Roslyn access for structural and semantic analysis. This seam allows the core analyzers to operate on a unified model built by language-specific providers (such as Roslyn for C\#/VB, and sidecars for Java, Python, Go, etc.), enabling true polyglot scanning. The model includes neutral abstractions for types, members, and call sites, along with a new token stream (\CodeToken\) and duplication units (\CloneUnit\) that allow the code-duplication detector (D4) to run on a single algorithm across multiple languages. It also introduces precise resolution tracking via \CalleeResolution\ (distinguishing InRepo, External, and Unresolved calls) and \IsProducedResult\ to fix measurement gaps in coupling and data-movement analyses.
engine/src/CodeHealth.Core/CodeModel · high confidence
Java sidecar introduces schema-versioned NDJSON output and precise source-level analysis
The Java sidecar now emits a schema-versioned NDJSON snapshot (schemaVersion 1) that the .NET JvmProvider deserializes into the neutral ICodeModel. This output includes a source census to distinguish between files found and files actually parsed, preventing silent gaps in measurement. The sidecar accurately resolves in-repo symbols using Spoon's source-only mode, marking external types as name-only stubs. It correctly handles Java-specific constructs like records, sealed classes, and Lombok-generated fields, and provides precise branch analysis that avoids double-counting branches in nested types. Additionally, it identifies declared test source directories from build scripts to ensure test code is not misclassified as production code.
engine/sidecars/java-spoon · high confidence
Kotlin language support: value object detection and explicit API mode analysis
The engine now includes dedicated Kotlin language support. It can identify Kotlin value objects by recognizing immutable classes with read-only properties, excluding data classes and strongly-typed IDs. Additionally, it detects whether a Kotlin module explicitly declares its public API via the Gradle or Maven 'explicitApi' setting, ensuring that only modules intentionally exposing a stable API are marked as such.
engine/src/Core/Languages/Kotlin · high confidence
LLM proxy introduces per-upstream admission queues and model-aware routing
The engine's LLM proxy now manages upstream concurrency via per-upstream admission queues, enforcing a configurable maximum in-flight calls (default 16) and prioritizing customer requests over corpus work. It supports model-aware routing, allowing requests to be directed to specific upstream hosts (e.g., dgx1 for large models, local ollama for judges) based on the model name in the request. The proxy distinguishes between queue wait time and processing time, refusing classified calls that exceed their queue allowance with a 503 status (which the engine can re-queue) and timing out dispatched calls with a 504 status if they exceed the processing timeout. Configuration is handled via environment variables for upstream URLs, routing rules, in-flight limits, and timeouts.
engine/src/WdLlmProxy · high confidence
Launch of the Assay product host with buyer-focused UI and scan-only capabilities
The Assay application is now available as a distinct product host, providing a buyer/business interface for scanning customer software and generating decision reports. The UI features a unique 'Dal' brand identity (warm paper tones, copper accents, and serif typography) and supports static SSR with a light-default theme. Functionally, it wires shared core contexts—including Scans, Ingestion, DecisionReports, Governance, and Billing—while enforcing a 'scan-only' scope that excludes the Watchdog-specific dev-toolkit. The host also exposes system information at /api/system/info and integrates Keycloak SSO with a dedicated per-org provisioner.
src/Kennel.Assay.App · high confidence
New AC2 dimension: forms and labels accessibility analysis
The engine now includes a dedicated AC2 dimension that evaluates whether every form control and button has a programmatic label (via \<label for\>, wrapping \<label\>, or aria-label) and accessible text. This new analyzer registers as a standalone dimension, declares support for 16 languages (including C\#, TypeScript, Dart, and F\# via builder DSLs), and implements specific logic to handle framework-specific patterns such as Vue call-site label inheritance, MUI forwarded props bags, and styled-components wrappers, ensuring that assistive technologies can correctly identify and announce form fields.
engine/src/Scanner/Accessibility/AC2 · high confidence
New AC3 Page Structure accessibility dimension added
The engine now includes a dedicated AC3 dimension that evaluates page structure, including HTML lang attributes, document titles, landmark usage (such as \<main\>), heading hierarchy, zoom settings, iframe titles, and meta-refresh presence. This change introduces the PageStructureAnalyzer and its registration, enabling the tool to detect structural accessibility issues in static HTML and Razor layouts (including Blazor partials) across a wide range of supported languages and markup frameworks.
engine/src/Scanner/Accessibility/AC3 · high confidence
New AC5 ARIA correctness check for accessibility scans
The engine now includes the AC5 dimension, which validates ARIA usage in markup by enforcing valid non-abstract roles, ensuring required ARIA states are present, and preventing aria-hidden on focusable elements. This check is registered as a standalone analyzer and declares support for 16 languages (including C\#, TypeScript, Ruby, Python, Go, and others) to cover the specific view layers and builder DSLs each ecosystem uses.
engine/src/Scanner/Accessibility/AC5 · high confidence
New AC6 Visual and Motion Safety analysis for accessibility
The engine now includes a dedicated AC6 dimension that analyzes visual and motion safety, specifically checking for focus visibility, reduced-motion guards, and color contrast. This new analyzer scans inline styles, literal CSS blocks, and external stylesheets to flag issues such as removed focus outlines, animations lacking prefers-reduced-motion support, and low-contrast color pairs. It is registered as a standalone service and declares support for a wide range of languages including C\#, TypeScript, Dart, F\#, and others, ensuring comprehensive coverage across different markup ecosystems.
engine/src/Scanner/Accessibility/AC6 · high confidence
New API surface extraction for C\# codebases
The engine now includes a new syntactic API surface extractor for C\# projects that identifies HTTP routes from both Minimal APIs (MapGet/MapPost, etc.) and attribute-routed controllers without requiring a build or Roslyn semantic model. The extractor normalizes route templates (lowercasing literals, collapsing constraints, handling group prefixes) and outputs a deterministic JSON report including route details, versioning status, and counts of unresolved templates. This enables fast, reliable diffing of external API changes across codebase versions.
engine/src/Core/ApiSurface · high confidence
New Agents bounded context for automated finding remediation
The Agents bounded context is now implemented in Kennel.Watchdog.Core, introducing a full agent-remediation loop. This includes per-repository scoped agent keys (with distinct admin/maintainer keys), a findings state machine supporting claims, provisional resolutions, and disputes, and a dedicated audit trail for agent activity. The context exposes a customer-facing MCP server and REST API for agents to read findings, dispute false positives, report detector gaps, and request rescans, while maintaining backward compatibility with the previous agent interface.
src/Kennel.Watchdog.Core · high confidence
New C1 Data Protection and C5 Data-Subject Rights compliance dimensions for .NET and JavaScript/TypeScript
The engine now includes dedicated compliance dimensions C1 (Data Protection) and C5 (Data-Subject Rights) for both .NET and JavaScript/TypeScript repositories. C1 scores encryption at rest (including key vaulting, column encryption, and key derivation) and in-transit security (HTTPS enforcement or reverse-proxy topology), abstaining when no personal data is detected or when the repository uses a data-store client without a recognized persisted model. C5 scores GDPR data-subject rights (erasure, export, and consent) using corroborated evidence rather than simple keyword matching, also abstaining when no personal data is present. Both dimensions are registered as independent slices, allowing them to be enabled separately, and provide ecosystem-specific recommendations and gap explanations for JavaScript/TypeScript projects scanned via disk.
engine/src/Scanner/Compliance/C1 · high confidence
New C4 Data Retention compliance dimension for JavaScript/TypeScript repositories
The engine now assesses data retention (C4) for JavaScript/TypeScript codebases, closing a previous gap where only .NET repositories were scored. This new capability scans for personal data in persisted models (e.g., TypeORM, Prisma, Mongoose) and evaluates retention evidence through a cumulative scoring system: it awards points for the presence of expiry limits (TTLs), scheduled purge/cleanup jobs, and documented retention periods. The analysis correctly abstains when data is stored via raw SQL or hosted backends without a recognized model, and it explicitly excludes referential integrity mechanisms like cascade deletes from the retention score.
engine/src/Scanner/Compliance/Compliance.Prework · high confidence
New CI/CD readiness dimensions: P1 (Gates) and P12 (Gate Honesty)
The engine now includes two new Readiness dimensions. P1 evaluates whether CI pipelines explicitly gate merges on build and test steps, providing toolchain-specific advice (e.g., \dotnet test\, \npm test\) rather than generic multi-ecosystem lists, and correctly handling decommissioned services or non-code-facing workflows. P12 assesses the honesty of those gates by detecting issues such as coverage collection without enforced thresholds, test suites running only post-merge, CI jobs that auto-retry until green, and test suites excluded by filters without documentation.
engine/src/Scanner/Readiness/P1 · high confidence
New CLI-based LLM providers for Claude and GitHub Copilot
The engine now includes two new LLM providers that invoke local command-line tools instead of relying solely on HTTP APIs. The Claude CLI provider (ClaudeCliLlmProvider) shells out to the \claude\ binary, handling prompt size by switching between inline arguments and file redirection, stripping markdown code fences, and caching results keyed by rubric version. The GitHub Copilot CLI provider (CopilotCliLlmProvider) uses \gh models run\, classifies failures such as missing subcommands, authentication issues, or context limits, and degrades gracefully with a confidence:0 response rather than crashing. Both providers include DI registration extensions and configurable options for timeouts, retries, and model selection.
engine/src/CodeHealth.Llm.ClaudeCli, engine/src/CodeHealth.Llm.CopilotCli · high confidence
New Change Coupling dimension (D35) detects hidden file dependencies via git history
The engine now includes a new architecture dimension, D35 Change Coupling, which identifies files that are frequently modified together in git history despite having no explicit code dependencies. This analysis mines commit logs to find pairs of production source files that co-change, filtering out test files, generated code, and 'sweeping' commits (like bulk renames or formatting) to reduce noise. The dimension reports pairs where the coupling strength exceeds a defined threshold, helping users spot hidden logical dependencies that static analysis cannot see. It is registered as a standalone dimension analyzer and integrates into the Architecture lens alongside static coupling metrics.
engine/src/Scanner/GitMining/D35 · high confidence
New CodeHealth analyzer rules enforce design and reliability standards
The CodeHealth.Analyzers engine now ships six new Roslyn analyzers (CHA0001–CHA0006) that enforce specific code quality rules. CHA0001 bans Newtonsoft.Json in favor of System.Text.Json, and CHA0002 bans NotImplementedException to prevent deferred work from hiding in code. CHA0003 prohibits mocking frameworks like Moq and NSubstitute, requiring hand-written test doubles instead. CHA0004 ensures reliability by requiring all catch blocks to log via ILogger or rethrow exceptions. CHA0005 enforces strongly-typed ID value objects over raw Guids for members ending in 'Id'. Finally, CHA0006 prevents the re-implementation of source-classification path primitives, centralizing this logic to a single canonical home to avoid drift.
engine/src/CodeHealth.Analyzers · high confidence
New D11 Test Reliability dimension with multi-language support
This change introduces the D11 Test Reliability dimension, which re-runs test suites to detect flakiness. The implementation registers a new analyzer and a suite of language-specific collectors for .NET, JavaScript/TypeScript, Swift, Go, JVM (Java/Kotlin), Python, Rust, Ruby, Scala, and Erlang. It classifies test projects into tiers (unit, integration, BDD, e2e) and applies a time budget to ensure faster tiers are measured even on large suites. The dimension is registered via dependency injection and declares its dimension ID (D11) for assembly-level reflection.
engine/src/Scanner/Testing/D11 · high confidence
New D44 dimension detects end-of-life runtimes and frameworks
The engine now includes the D44 (Platform End-of-Life) dimension, which scans repositories to identify unsupported runtimes (such as Python, Java, Go, Ruby, Rust, and others) and end-of-life frameworks (including Spring Boot and Rails). This analysis reads platform declarations from files like .nvmrc, rust-toolchain, and package.json, as well as dependency manifests like pom.xml and Gemfile.lock, to flag security risks where a project relies on a platform that no longer receives security patches.
engine/src/Scanner/Dependencies/D44 · high confidence
New Domain Modelling checks for aggregate boundaries, transactional consistency, construction safety, and ambient inputs
The engine now includes four new static analysis dimensions under the Domain Modelling lens: DM1 (Aggregate Boundaries) detects when aggregates reference other aggregates by object reference instead of identity; DM10 (Aggregate Transaction) flags operations that mutate more than one aggregate root, violating the one-transaction-one-aggregate rule; DM11 (Constructible Invalid State) identifies entities with public constructors that accept raw primitives without guards or factories, allowing invalid instances; and DM12 (Ambient Inputs) finds domain types that directly read ambient sources like the wall clock or global random number generators instead of receiving them as injected seams. These checks are registered as new DI services and emit specific findings to help enforce DDD consistency boundaries and testability.
engine/src/Scanner/ModelAware · high confidence
New Edition system with explicit dimension inclusion, language gap disclosure, and build freshness checks
The engine now ships a new Edition subsystem that explicitly defines which dimensions are included in the customer-downloadable image versus withheld (commercially, due to lack of self-sufficiency, or because they have no standalone meaning). This includes a central catalog (DimensionEditions) that enforces exhaustive coverage, a mechanism to detect and report languages present in the repository that the current build cannot analyze (EditionLanguageCoverage), and a freshness check (EditionFreshness) that warns users if the image is too old to reliably report on security vulnerabilities. The edition also enforces a CI gate (EditionGate) based on included findings and produces a self-describing manifest (EditionManifest) and filtered SARIF output (EditionPublisher).
engine/src/Core/Edition · high confidence
New Elixir sidecar adds language \#8 with schema version 6
The engine now supports Elixir as its eighth language via a new sidecar that parses \.ex\ and \.exs\ files using the standard library \Code.string\_to\_quoted/2\ AST reader. The sidecar emits an NDJSON snapshot using schema version 6, which is additive to the existing Java through Ruby schemas. It provides detailed static analysis including in-repo call resolution, branch counting, and specific handling for Elixir constructs like \defstruct\, \defprotocol\, and \apply/2\ event folds. The tool is purely static, does not compile or evaluate target code, and requires a pinned Erlang/OTP and Elixir runtime.
engine/sidecars/elixir-frontend · high confidence
New Explicit Debt (D17) dimension added to the engine
The engine now includes a new Explicit Debt dimension (D17) that scans codebases for acknowledged but unfixed issues, including TODO/FIXME markers, suppressed warnings, empty catch blocks, commented-out code, obsolete members, and dead code. The analyzer scores repositories based on the density of these markers per thousand lines of code, deducting justified suppressions and inherited (vendored) debt from the final score. It also detects enforcement rungs by checking for configured analyzer diagnostic prefixes or CI debt gates that actively prevent such debt from accumulating. The dimension is registered via dependency injection and handles edge cases such as build failures or non-.NET repositories by abstaining with clear explanations rather than failing silently.
engine/src/Scanner/ExplicitDebt · high confidence
New HTML and Markdown report renderers with fixed output limits
The templating engine now supports generating self-contained HTML reports (with dark/light theme support and print-friendly styling) and Markdown reports using Scriban templates. A critical fix in the rendering engine lifts the previous 1 MiB output size cap and iteration limits, ensuring that large reports are no longer silently truncated mid-document.
engine/src/CodeHealth.Reporting.Templating · high confidence
New IL Efficiency dimension (D39) for .NET repositories
The engine now includes a new code quality dimension, D39 (IL Efficiency), which analyzes the actual Intermediate Language emitted by .NET builds. Using Mono.Cecil, it measures the size of authored methods and flags those exceeding a 250-instruction threshold, while excluding compiler-generated code. The analyzer requires a successful build, handles transient host failures with a single retry, and reports 'not-measured' for non-.NET repositories or build failures, ensuring it does not produce spurious scores for incompatible projects.
engine/src/Scanner/BuildDependent/D39 · high confidence
New IL-level code quality metrics for authored methods
The engine now includes an IL-level analysis component (IlMetricsExtractor) that reads compiled assemblies via Mono.Cecil to measure authored code complexity. This feature counts IL instructions, identifies boxing operations, and flags methods exceeding a 250-instruction threshold as 'oversized'. It specifically excludes compiler-generated and framework-emitted code (e.g., EF Core migrations, Blazor render trees) to ensure metrics reflect only user-authored logic, providing a more accurate signal for code size and optimization opportunities than source-level analysis alone.
engine/src/Scanner/BuildDependent/D39/Il · high confidence
New JVM code model provider for Java and Kotlin
The engine now includes a dedicated provider for the JVM ecosystem, enabling the analysis of Java and Kotlin repositories. This new component parses NDJSON snapshots generated by the Spoon sidecar, mapping the data into the neutral code model to support type resolution, member analysis, and body-level metrics for these languages.
engine/src/CodeHealth.CodeModel.Jvm · high confidence
New JavaScript/TypeScript lexer and JSX/Astro support
The engine now includes a dedicated, single-pass JavaScript/TypeScript lexer (JsLexer) that produces a token stream for frontend analysis, replacing previous ad-hoc scanning. This lexer handles standard JS/TS syntax, including robust regex-vs-division disambiguation, template literal nesting, and private identifiers. It also introduces full JSX/TSX support via an explicit state machine, specifically fixing a critical issue where generic arrow functions (e.g., \\<T extends string\>(...) =\> ...\) were incorrectly parsed as JSX elements, which previously caused large sections of code to be treated as unreachable. Additionally, the engine can now parse Astro component frontmatter, correctly identifying the leading \---\ fence to expose TypeScript imports for module graph analysis.
engine/src/Core/JsLexing · high confidence
New Kotlin sidecar with schema v2 NDJSON output
A new Kotlin analysis sidecar has been added to the engine, providing source-only analysis of Kotlin codebases using the K1 BindingContext. It emits a schema-version 2 NDJSON snapshot that extends the existing Java schema with Kotlin-specific carriers, including support for sealed classes (mapped to union types), data classes, properties, and nullable types. The sidecar is built as a self-contained fat jar using the bundled Kotlin compiler, ensuring it runs offline without requiring external dependency jars or build tools.
engine/sidecars/kotlin-frontend · high confidence
New LLM abstraction layer with accurate usage tracking and failure classification
The engine introduces a new set of abstractions for LLM interactions, including interfaces for providers, endpoint health, and usage recording. This change adds precise tracking of LLM calls to the \llm-calls.json\ ledger, distinguishing between successful calls, infrastructure failures, and validation errors, while also recording whether responses were served from cache. It introduces work-unit attribution to identify which specific dimension, lens, or narration task initiated each call, and adds a queue-wait metric to separate proxy wait time from actual model processing time. Additionally, it provides a live progress bar by tracking completed and expected LLM work units.
engine/src/CodeHealth.Llm.Abstractions · high confidence
New LOC sweep tool for comparing production size metrics
A new \loc-sweep\ tool has been added to the engine to analyze repositories and output a TSV report comparing current code-composition metrics against production-line counts. The tool calculates both the standard app LOC (boilerplate, straight-line, and branching) and the production LOC (non-blank lines including comments), then applies the shipped valuator to determine size labels for both. It also includes a 'before' and 'after' comparison to show how the new production-size ruling affects the final size label, accounting for unmodelled languages via a language census. This allows users to observe the impact of the new production-size measurement on billing and sizing labels without re-implementing the engine's internal thresholds.
engine/tools/loc-sweep · high confidence
New Limitations section explains scan scope, tool failures, and per-dimension blind spots
The report now includes a dedicated 'Limitations & what we did not check' section that clarifies the boundaries of the analysis. It explicitly states that the scan is repository-only and does not inspect live cloud accounts, running pipelines, or external approval rules, listing any controls that were 'not evidenced' due to this scope. The section also details specific run-time issues, such as missing external scanners, degraded git history, or LLM infrastructure failures, and provides a curated, plain-English 'blind spot' explanation for every measured dimension to help users understand what the static analysis can and cannot see.
engine/src/CodeHealth.Reporting/Limitations · high confidence
New OpenAI-compatible LLM provider with accurate token counting and endpoint quarantine
The engine now includes a new \OpenAiCompatibleLlmProvider\ that connects to any OpenAI-compatible chat-completions endpoint. This provider introduces accurate prompt token counting using the served model's own tokenizer (falling back to UTF-8 bytes or a character estimate only when a tokenizer file is unavailable), replacing the previous 2.5 chars/token heuristic to prevent context window overflows. It also implements endpoint quarantine logic that ignores transient transport failures during host restarts (using a 10-minute grace period) and prevents reasoning models from consuming the entire output budget by allowing routes to explicitly disable the 'thinking' pass. The provider integrates with the existing caching and validation layers and registers itself via dependency injection.
engine/src/CodeHealth.Llm.OpenAiCompatible · high confidence
New P12 dimension: CI test-gate honesty analysis
The engine now includes a new Readiness dimension (P12) that evaluates whether CI test gates actually execute the tests they claim to run. This analyzer detects issues such as test suites excluded by \--filter\ flags without documentation, tests marked with \Skip=\ that never reach the gate, coverage reports collected without enforced minimum thresholds, test suites that only run after a merge (failing to block PRs), and CI workflows that retry until green, masking failures. It also flags excessive use of sleep-based synchronization in tests as a flakiness precursor. This provides users with visibility into gaps between their declared test inventory and their actual CI enforcement.
engine/src/Scanner/Readiness/P12 · high confidence
New P3 readiness dimension for security and performance tooling
The engine now includes a new P3 readiness dimension that evaluates whether repositories use dedicated static analysis and security tooling. This dimension registers a new analyzer that detects SAST signals across a broad range of ecosystems—including GitHub default code scanning, CodeQL, Semgrep, SonarQube, and various language-specific tools like Clippy, Scalafix, and IaC scanners like Checkov and Trivy—ensuring that repos using these tools are correctly credited for their security posture.
engine/src/Scanner/Readiness/P3 · high confidence
New P5 Disaster Recovery and Backup dimension added to Readiness scanning
The engine now includes a new P5 dimension that evaluates a repository's disaster recovery and backup posture. This analyzer detects production data ownership by scanning for database drivers, object storage markers, and embedded stores in IaC and manifests, then checks for backup controls in both infrastructure (Terraform, compose) and application source code (create/restore symbol pairs). It specifically addresses false negatives for object storage (S3, Azure Storage, GCS) and embedded databases (RocksDB, SQLite, etc.) that were previously ignored, and correctly excludes published libraries with no deployment surface from the DR assessment.
engine/src/Scanner/Readiness/P5 · high confidence
New P9 dimension: domain vs. controller coverage balance
The engine now includes a new Production-Readiness check (P9) that compares test coverage between domain logic and web/controller layers. It identifies domain files by path markers (e.g., /domain/, /aggregates/) and web files by path or name (e.g., /controllers/, \*Controller.cs, views.py). The analyzer uses in-process coverage data when available, falling back to existing Cobertura/OpenCover/lcov reports on disk. It warns if the web layer is at least 20 percentage points more covered than the domain, or if domain coverage is below 50%, and provides actionable advice on shifting testing effort toward business rules.
engine/src/Scanner/Readiness/P9 · high confidence
New PHP frontend sidecar for multi-language scanning
A new PHP frontend sidecar has been added to the engine, enabling multi-language scanning for PHP repositories. It uses PHP-Parser v5 to extract code structure (classes, interfaces, traits, enums, attributes) and emits an NDJSON snapshot (schemaVersion 4) compatible with the existing JvmProvider. The sidecar introduces a declared-type symbol table for call-owner resolution, providing stronger type resolution than the Python sidecar while maintaining an honest boundary for untyped receivers. It also includes a layout module that correctly identifies test code based on PHPUnit and Composer declarations, ensuring test files are properly classified and excluded from the production model.
engine/sidecars/php-frontend · high confidence
New Readiness prework scans for CI, schema migrations, and operational resilience
The engine now includes a dedicated Readiness prework pass that performs a single, memoized walk of the repository to gather evidence for multiple readiness dimensions. This pass introduces three new scans: ReadinessScan collects CI workflow, deployment manifest, and PaaS text while fixing a critical bug where self-referential symlinks caused infinite recursion and out-of-memory errors; SchemaMigrationScan detects versioned migration strategies (e.g., Flyway, Alembic, Rails) and auto-create calls across multiple ecosystems by analyzing file names and content; and OperabilityScan identifies operational resilience patterns (HTTP usage, retry handlers like Polly) and database migration usage (EF Core, EnsureCreated) by walking production compilations. These changes enable the engine to provide more accurate readiness scores by consolidating file reads and preventing structural failures during analysis.
engine/src/Scanner/Readiness/Readiness.Prework · high confidence
New Roslyn-based analyzers for PII inventory and generated-code regions
The engine now includes two new Roslyn analyzers to improve the accuracy of compliance and quality reports. PiiDataMapAnalyzer builds an inventory of personal data fields by walking C\# syntax trees, classifying member names while filtering out static constants, boolean flags, and service collaborators to reduce false positives. GeneratedRegionScan identifies machine-written code at the region level by detecting \[GeneratedCode\] attributes and BEGIN/END GENERATED CODE comment fences, allowing the engine to correctly suppress size-related quality findings (like FileTooLong or ClassTooLong) for files that are predominantly generated rather than hand-written.
engine/src/Core/ComplianceRoslyn, engine/src/Core/FileQualityRoslyn · high confidence
New Ruby domain conventions for detecting active-record smells
Added RubyDomainConventions.cs to define Ruby-specific domain modeling rules, enabling the detection of fused active-record patterns (DM6) where domain behavior is incorrectly embedded in ORM entities like ActiveRecord::Base or Sequel::Model. This includes logic to identify value objects, ORM entities, and domain events based on Ruby idioms such as Data.define, Struct.new, and namespace conventions.
engine/src/Core/Languages/Ruby/Domain · high confidence
New Ruby security analysis rules and dependency vulnerability scanning
The engine now includes several new Ruby-specific security capabilities. Static analysis rules detect silent mutation of caller-owned collections (RubyArgumentMutatedScan), duplicate method definitions that create dead code (RubyDuplicateMethodDefinitionScan), and the discarding of caught exceptions in nested rescue blocks (RubyRescueDiscardsCaughtErrorScan). A recheck mechanism refutes ReDoS findings when interpolated values are properly escaped via Regexp.escape (RubyRegexEscapeRecheck). Additionally, the engine can now assess declared dependency vulnerabilities for Ruby gems by resolving versions from Gemfile declarations and querying OSV advisories (RubyGemsAdvisoryCollector), and it resolves license compliance for the runtime dependency closure against a banned-SPDX policy (RubyGemsLicenseCollector).
engine/src/Core/Languages/Ruby/Security · high confidence
New SVG reporting components for dependency graphs, matrices, and score charts
The reporting engine now includes three new SVG generators in the Svg namespace. ArchGraphSvg produces deterministic, layered node-link diagrams for project dependencies (capped at 24 nodes) and bounded-context clustered graphs, highlighting cycles and layering violations in red. DsmSvg renders a dependency-structure matrix over the namespace graph, using cell opacity to indicate dependency weight and red cells to mark cycles or layering violations above the diagonal. SvgCharts provides deterministic, theme-aware inline SVGs for score gauges, trend sparklines, multi-series trajectory line charts, and distribution bars, ensuring consistent visual representation of health scores and trends across light, dark, and print modes.
engine/src/CodeHealth.Reporting/Svg · high confidence
New Security Watch digest for tracking new and cleared security findings
A new Security Watch renderer has been added to generate a deterministic, security-scoped diff between the current scan and the most recent prior run. This feature produces both a Markdown summary and a structured JSON output that highlights newly appeared security findings (including critical issues) and those that have been cleared since the last watch, using line-insensitive fingerprints to avoid false positives from code movement. The output is scoped to security-relevant dimensions (secrets, SAST, CVEs, IaC, PII, and dependency vulnerabilities) and is designed to support daily security-watch scans and SaaS notifications by providing a clear, reproducible view of what is newly dangerous or resolved.
engine/src/CodeHealth.Reporting/Security · high confidence
New TypeScript configuration and domain-convention analysis capabilities
The engine now includes new analyzers for TypeScript projects: TsConfigJsChecking detects whether a repository's tsconfig enables checkJs to type-check JavaScript files, and TsConfigStrictness evaluates the enforcement of core strict type-checking options (noImplicitAny, strictNullChecks, noImplicitThis) to provide a more accurate measure of type safety. Additionally, TsDomainConventions introduces detection for TypeScript-specific domain-driven design patterns, including identification of domain-event unions (distinguishing them from Result/error unions) and fused active-record ORM patterns, while gating these checks to TypeScript/JavaScript types to avoid impacting other language scans.
engine/src/Core/Languages/Ts · high confidence
New UI chassis and component library
The application introduces a new UI chassis in src/Kennel.Ui, featuring a centralized SVG icon sprite (Lucide v0.525.0) and a modular script loading system via ChassisScripts.razor. This foundation supports a suite of new, reusable Blazor components including CaiLadder for score visualization, ChartTable for accessible data presentation, ListControls for search and filtering, and InfoHint for consistent tooltips. The update also standardizes navigation with DetailCrumbs, handles empty states with EmptyState, and provides in-context feedback through FeedbackWidget, establishing a unified design system for the product.
src/Kennel.Ui · high confidence
New X14 detector for bypassable IP address classification
The engine now includes a new security check (X14) that identifies hand-rolled IP address classifiers which are vulnerable to bypass via IPv4-in-IPv6 address embeddings. The analyzer detects methods that unwrap IPv4-mapped IPv6 addresses but fail to handle other embedding formats (such as IPv4-compatible, 6to4, or NAT64), leading to inconsistent classification verdicts. This check is implemented for C\# via Roslyn syntax analysis and extends to JavaScript/TypeScript, Java, Kotlin, PHP, Python, and Go through reference-free token stream parsing.
engine/src/Scanner/Defects/X14 · high confidence
New X20 check for mistyped argument guards across .NET, JVM, and Dart
The engine now detects when an argument guard throws a null-specific exception (such as \ArgumentNullException\, \NullPointerException\, or \ArgumentError.notNull\) even though the guard's condition proves the value is merely empty. This new X20 dimension applies to C\# (via Roslyn), Java, Kotlin, Scala, and Dart (via token-based scanning). It helps callers avoid swallowing empty-value errors when catching null-handling exceptions by flagging the mismatch between the guard's logic and the exception type.
engine/src/Scanner/Defects/X20 · high confidence
New X29 defect check for fixed-element guards in loops
The engine now includes a new defect dimension (X29) that detects loops where a guard condition relies on a fixed index of a collection while the guarded statement operates on the current loop element. This pattern causes every iteration to use the same decision (typically from index 0) for all elements, leading to incorrect handling of non-zero indices. The check is implemented for C\# via Roslyn syntax analysis and extends to JavaScript, TypeScript, Java, and Rust via token-stream scanning, ensuring the rule applies across the entire repository regardless of the primary language. Users will now see warnings when a loop's \if\ condition reads a static subscript (e.g., \array\[0\]\) while the body accesses the array by the loop variable (e.g., \array\[i\]\), with advice to either make the condition per-element or hoist it outside the loop.
engine/src/Scanner/Defects/X29 · high confidence
New X31 defect detection for Erlang test-only exports
The engine now includes a new advisory (unscored) defect X31 that identifies Erlang modules exporting functions solely for testing purposes. Because Erlang lacks internal visibility, unconditional exports of test helpers widen the module's public contract unnecessarily. The analyzer flags these exports and recommends wrapping them in \-ifdef(TEST)\ to keep them out of the shipped module, while noting that production callers require the export to remain. This change also registers the X31 analyzer within the engine's dependency injection container and declares its emitted dimension.
engine/src/Scanner/Defects/X31 · high confidence
New X9 Coherence Smell analyzer detects subsumed logical operands
The engine now includes a new defect lens (X9) that identifies logical conditions where one operand is subsumed by another, rendering it dead code. For example, in an expression like \n.Contains("sbom") \|\| n.Contains("bom")\, the analyzer flags the first operand because any string matching "sbom" also matches "bom", making the check redundant. This analysis runs on C\# syntax trees and polyglot source files, reporting findings as unscored advisories to help users simplify conditions without altering behavior.
engine/src/Scanner/Defects/X9 · high confidence
New accessibility and observation render harnesses with deterministic analysis and secure file serving
The analyzer image now includes a new JavaScript-based accessibility and observation render harness in \engine/docker/analyzer/render\. This introduces \axe-render.mjs\, which serves static build output via a loopback server protected by a strict path-traversal and symlink containment boundary (\resolveServedFile\), and renders pages N times with a frozen clock, seeded RNG, and disabled animations to ensure deterministic accessibility results. It also introduces \observe-proxy.mjs\, a proxy that injects an axe-core runner into live application pages to capture accessibility violations and response headers during test-driven flows, while safely bypassing compressed HTML to prevent corruption. Both harnesses are supported by new pure-logic modules (\axe-lib.mjs\, \observe-lib.mjs\) and comprehensive test suites (\axe-lib.test.mjs\, \axe-render.test.mjs\, \observe-lib.test.mjs\, \observe-proxy.test.mjs\, \is-program.test.mjs\) that verify argument parsing, evidence shaping, and the deterministic freeze contract.
engine/docker/analyzer/render · high confidence
New architecture analysis artifacts published to the run bundle
The engine now generates several new files in the run bundle to support architecture reporting and UI features. A single HTML dependency-structure matrix (dependency-matrix.html) is rendered for both the report and the product UI, replacing the previous SVG-only approach and enabling cell popups without JavaScript. JSON artifacts are added for the namespace dependency graph (namespace-graph.json), the C4 architecture map (architecture-map.json), the D5 main-sequence measurements (main-sequence.json), and per-service Code Assurance Index scores (service-scores.json). Additionally, a grounded design review (design-review.json/.md) is produced, which cites specific modules, cycles, and findings from the run's evidence.
engine/src/CodeHealth.Reporting/Architecture · high confidence
New architecture-contract models for deployment topology and namespace dependency graphs
The engine now exposes a richer, authoritative view of the repository's architecture through new data contracts. A new DeploymentTopology model captures the definitive deployment structure (services, infrastructure, and external dependencies) extracted directly from declarative sources like Docker Compose, Kubernetes, and Terraform, complete with provenance and confidence levels. Additionally, the NamespaceDependencyGraph and ModuleLayering models now publish the internal namespace dependency graph, module levels, and deterministic layering order, enabling accurate C4 diagrams and dependency-structure matrices that reflect the actual codebase structure rather than inferred guesses.
engine/src/Core/ArchitectureContracts · high confidence
New authentication modes for development and end-to-end testing
The infrastructure layer now supports two new authentication schemes: a dev fallback that automatically signs in every request as a fixed 'Dev User' principal (with configurable admin status) when no identity provider is configured and the host is not in production, and an E2E loopback identity that allows end-to-end tests to authenticate as specific users (e.g., 'name@e2e-user') only when running on a preprod host via a direct loopback connection without proxy headers. These changes enable seamless local development and secure, topology-aware end-to-end testing without requiring a full identity provider setup.
src/Kennel.Infrastructure · high confidence
New centralized configuration subsystem for the CodeHealth analysis engine
The engine now uses a structured, YAML-based configuration system (rooted in \.codehealth/config.yaml\) to control analysis behavior, replacing scattered defaults and hard-coded constants. Users can now explicitly tune CI gating thresholds (e.g., regression limits, minimum scores), adjust LLM provider settings (including stable model aliases, concurrency limits, and timeout ceilings), and configure specific dimension behaviors such as test-reliability run counts, hotspot churn windows, and documentation sampling sizes. The system also introduces new capabilities for declaring bounded contexts for architecture analysis, defining ADR recognition patterns, and routing LLM calls to local judges for classification tasks, providing a single point of control for deployment-specific tuning without code changes.
engine/src/CodeHealth.Core/Configuration · high confidence
New deployment topology extraction for container images and infrastructure manifests
The engine now builds a unified deployment topology by extracting nodes and edges from Docker Compose, Kubernetes, Helm, Aspire, systemd units, and cloud IaC (Terraform, Bicep, ARM, CloudFormation, CDK, Crossplane, Pulumi, Ansible). A new ContainerImageClassifier identifies well-known infrastructure images (e.g., Postgres, Redis, Keycloak) as Infrastructure nodes, while images built from the repository or unrecognized pulled images are treated as Service nodes. Test harnesses and fixture files are excluded from the production topology to prevent noise. Extractors run in a deterministic order, merge overlapping nodes/edges by stable identity, and isolate failures so that one broken manifest does not break the entire map.
engine/src/Core/Architecture/Topology · high confidence
New dimension glossary and method descriptions for the reporting engine
The reporting engine now includes a comprehensive glossary and method description for each dimension (D1–D44, AX1–AX10, DM1–DM12, ED1–ED5, ES1–ES3, IC1, GD1, C1–C5, S1, SC1, AXR1, AXB1–AXB2, AXS1, AXA1, AXO1, AXI1, AXK1, AXH1, AXP1, LA1–LA6, M1–M4, P1–P12, X1–X16). The glossary provides plain-English explanations for each dimension, while the method descriptions detail how each dimension is measured, including the specific tools, algorithms, and data sources used. This enhances transparency and understanding of the analysis results for users.
engine/src/CodeHealth.Reporting/Dimensions · high confidence
New distillation pipeline for generating changelog and overview documents
The distillation engine now groups raw scan entries into capabilities, writes capability-specific changelog entries, and assembles them into a distilled product owner document and a sales value document. It enforces word limits, repairs formatting slips, and runs mechanical checks to flag unsupported claims, speculation, and names not found in the input, while code-written sections for security/API changes and scan signals are included verbatim.
engine/src/CodeHealth.Reporting/Distillation · high confidence
New duplication detection arms for edited copies and multi-member families
The D4 duplication detector now identifies two new patterns of code similarity. First, it detects 'edited copies'—members that were copied and then modified—by finding chains of identical token runs that form a contiguous span across both members, rather than relying on single large identical blocks. Second, it detects 'chained families' of four or more members that share a common core of 50+ tokens, even when no single duplicated block spans all members simultaneously. These changes allow the engine to surface duplication scenarios that were previously invisible because they lacked a single large witness block.
engine/src/Core/CodeShape · high confidence
New end-to-end acceptance and runtime evidence verification harnesses
The e2e directory now includes a suite of new scripts that provide automated, repeatable verification of the product's core capabilities. The \run-loop.sh\ script serves as the M1 acceptance harness, proving the closed evidence loop end-to-end by booting the real CAI registry, Watchdog, and Assay services to verify that a scan, signed delivery, access-grant-based retrieval, and decision report generation work correctly without mocking. A new \keycloak-login-roundtrip.sh\ script headlessly validates the full Keycloak OIDC sign-in and sign-out flow, ensuring session cookies and identity provisioning function as expected. Additionally, \three-system-e2e.sh\ offers a browser-driven acceptance test to confirm that data published by a seller in Watchdog is visible and usable by a buyer in Assay, and \runtime-evidence-tier.mjs\ verifies that runtime security and accessibility evidence cards are actually visible to a reader in the final report, addressing a semantic gap left by purely syntactic unit tests.
e2e · high confidence
New engine rules detect private keys in binary containers, raw blobs, and JSON config bindings
The security scanner now includes four new detection rules (WD-SECRET-0001 through WD-SECRET-0004) that identify private keys previously missed by regex-based text scanning. These rules detect private keys committed as raw binary blobs (including deleted blobs in git history), keys stored in binary key-store containers like PKCS\#12 (.pfx) or JKS (.jks), and credentials bound to named keys in structured JSON configuration files. This expands coverage to binary content and structured data contexts where pattern matching on line text fails.
engine/src/Scanner/Security/D28/Scanners · high confidence
New file-quality scoring and report model enhancements
The reporting layer now includes a new FileQualityScorer that calculates per-file quality scores (0-10) using diminishing-returns accumulation and per-signal floors to prevent repeated minor issues from skewing results. The RunReport model has been expanded to include new fields for tracking build load failures, package restore incompleteness, unmodelled production languages, and sidecar model failures, providing more precise diagnostics when scans are degraded. Additionally, new interfaces and classes for report rendering, CSS hooks for sensitive data hiding, and LLM model display genericization have been added to improve report security and clarity.
engine/src/CodeHealth.Reporting · high confidence
New language-specific analysis modules for Dart, Elixir, F\#, and VB.NET
The engine now includes dedicated analysis modules for four additional languages, enabling deeper, language-aware insights. For Dart, a new analyzer exclusion scanner identifies stale paths and excluded packages in analysis\_options.yaml. Elixir support adds doctest detection to prevent false-positive secret scans in documentation and introduces domain-convention checks for event-sourcing patterns (aggregates, events, value objects). F\# support provides similar domain-convention analysis for functional aggregates and strongly-typed IDs, alongside a test-project scanner to discover .fsproj test suites. VB.NET receives a clone tokenizer that correctly handles designer-generated code and a god-class scanner, ensuring duplication and complexity metrics are accurate for Visual Basic projects.
(repo-wide) · high confidence
New migration tool for multi-phase data migration and verification
A new migration tool has been introduced to migrate data from the legacy 'watchdog' database to the new read-model architecture. The tool supports a phased execution model (Phases 0–5) covering identity, agents, scans, CRUD models, governance events, and language training. It provides idempotent upserts by primary key, ensuring re-runs are safe, and includes a verification mode that reconciles source and target row counts and checksums. The tool exposes CLI flags for dry-run, verify, and selective execution by context or phase, and logs unmapped columns to prevent silent data loss.
src/Kennel.Migration · high confidence
New model-aware .NET analysis capabilities: crypto-shredding detection, scattered decision/derivation checks, and invocation matching
The engine now includes a new model-aware Roslyn integration for .NET codebases, installed via \ModelAwareRoslynInstaller\. This adds three new behavioral checks: a \CryptoShreddingDetector\ that identifies proper crypto-shredding by verifying encryption, per-subject key storage, and key erasure (replacing the previous name-based heuristic); \ScatteredDecision\ and \ScatteredDerivation\ which detect domain rules or measurements implemented in multiple places rather than centralized on their owning types; and \InvocationMatching\ which provides precise semantic matching for API calls, eliminating false positives from comments, strings, and local buffers that plagued the previous string-based approach.
engine/src/Core/ModelAwareRoslyn · high confidence
New module graph readers for Bazel, CMake, and Cargo ecosystems
The engine now reads build manifests for Bazel (BUILD files), CMake (CMakeLists.txt), and Cargo (Cargo.toml) to construct module dependency graphs without executing the build tools. Bazel and CMake readers identify nodes by their build rules (e.g., \*\_library, add\_library) and edges by their dependency declarations (deps, target\_link\_libraries), while the Cargo reader resolves path dependencies and workspace patches to link crates. These readers also classify modules as test, non-production, or composition roots based on their rule types and directory locations, and record source file extensions for abstractness metrics.
engine/src/Core/Manifests · high confidence
New narration budget evaluation tool for measuring evidence caps
A new CLI tool (\narration-budget-eval\) and reporting script have been added to measure the impact of different evidence budgets on narration quality. The tool rebuilds repository history, samples code change clusters stratified by their evidence size, and runs them through the narration pipeline with various budget constraints (including unbounded, capped, and named-file variants) to compare token usage, completion success, and content fidelity against a baseline. This allows users to quantify the trade-offs between reduced context windows and narration accuracy.
engine/tools/narration-budget-eval · high confidence
New operator console and admin infrastructure in Kennel.Admin.Core
This change introduces the core backend for the new operator console, providing a unified administrative interface for managing both the Watchdog and Assay products. It adds the \AdminOperatorModule\ to wire up services for the scan queue, fleet capacity, and system health, alongside new APIs for managing the language-training cycle (\CycleApi\) and the recall-debt backlog (\BacklogApi\). The update also establishes the \admin\_ops\ database schema to store operational data, including temporal LLM pricing, machine rates, host health samples, and staff member records, enabling operators to monitor system health, manage pricing, and resolve degraded runs.
src/Kennel.Admin.Core · high confidence
New orchestration layer for parallel dimension execution and per-service decomposition
The engine now uses a new \DimensionOrchestrator\ to run analysis dimensions in parallel with per-dimension timeouts and concurrency throttling. This orchestrator handles critical reliability fixes: it charges the shared workspace warm-up to the run's budget (preventing false timeouts), re-runs dimensions that fail due to symlink loops during dependency installation, and ensures LLM calls are correctly attributed to the running dimension. Additionally, a new \PerServiceCaiPass\ decomposes monorepos into per-service Code Analysis Insights by scoping the workspace and re-running file-scoped dimensions and model-aware lenses for each service, improving performance and granularity for multi-service projects.
engine/src/Core/Orchestration · high confidence
New preprod deployment scripts and end-to-end verification tooling
This change introduces a suite of shell scripts and documentation for the preprod environment, including \provision-preprod.sh\ for idempotent setup, \build-sidecars.sh\ to ensure language-specific scan tools are present, and \assert-engine-verified.sh\ to gate promotions on actual scan evidence. It also adds end-to-end test scripts (\e2e-cycle-retention.sh\, \e2e-import-corpus.sh\, \e2e-redraw.sh\, \e2e-discard-repo.sh\) to validate telemetry retention, corpus seeding, and cycle management against real preprod data, alongside a \README.md\ detailing the tier's architecture, security boundaries, and operational landmines.
deploy/preprod · high confidence
New readiness probes for CI retry loops, version output hygiene, and Dart lockfile practices
The engine now detects specific CI and release hygiene patterns that were previously invisible. It identifies GitHub Actions (and compatible forges) jobs that automatically re-run on failure, flagging the 'retry until green' anti-pattern. It also scans for release pipelines that publish an empty version string due to undefined shell variables, and for Dart packages that incorrectly commit their \pubspec.lock\ files, which can mask dependency resolution issues for consumers.
engine/src/Core/Readiness · high confidence
New report-preview development tool for rendering report variants and dependency matrices
A new \report-preview\ tool has been added to the engine to allow developers to rapidly iterate on report visuals without performing full repository scans. This utility generates synthetic reports to preview the four states of the identification band (filed, signed-not-filed, no record, and no record/no findings) and renders the dependency matrix as a single server-side element (both HTML and SVG). It also supports generating a full report with runtime-evidence cards from canned observations, enabling end-to-end testing of the runtime accessibility tier in local environments.
engine/tools/report-preview · high confidence
New repository intent classification and DDD verdict reporting
The engine now explicitly detects and reports a repository's application kind (e.g., Web API, Desktop, Game, Microservices, Library) and architectural style (e.g., Clean Architecture, CRUD, Tactical DDD, Event-Sourced DDD) via the new \RepoIntent\ components. \AppKindDetector\ determines the kind using package references, csproj SDKs, and file presence to remain robust in offline checkouts, while \MaturityIntent\ identifies educational, proof-of-concept, or scaffolding templates based on owner-declared signals (environment variables, GitHub topics) and corroborated repository names/READMEs to prevent false positives. \DomainModelStyles\ and \DomainModellingVerdict\ provide a specific, evidence-backed verdict on whether a repository claims Domain-Driven Design, distinguishing it from clean architecture or CRUD patterns. These classifications are flattened into \RepoClassification\ for the report header and \scorecard.json\, ensuring that quality dimensions are correctly gated (e.g., marking web-security as N/A for libraries).
engine/src/Core/RepoIntent · high confidence
New run-history engine with regression detection and delivery-health signals
The engine now persists every analysis as a JSON sidecar (RunSidecar) in a local history directory, enabling trend tracking and regression checks against prior runs. A new regression gate compares the current headline score and per-dimension scores to the immediately preceding run, failing the build if the headline drops by the configured threshold or any dimension drops by five times that threshold, while correctly skipping the check on the first run or when schema/rubric versions mismatch. Additionally, the engine mines git commit history to compute advisory delivery-health signals—fix-commit ratio, commit cadence, and active author count—which are stored in the sidecar and available for trend visualization without affecting the core health score.
engine/src/CodeHealth.History · high confidence
New runtime security and compliance dimensions for bootable applications
The engine now includes a suite of new advisory report cards (AXA1, AXH1, AXI1, AXK1, AXO1, AXP1) that observe the live, booted application in a sandbox to provide evidence for CRA and NIS2 compliance. These dimensions check for unauthenticated access to authenticated routes (AXA1), verify the presence of baseline HTTP security headers (AXH1), inspect effective container hardening such as user and capabilities (AXI1), audit cookie security flags like HttpOnly and SameSite (AXK1), compare the served API surface against the repository's documentation (AXO1), and track third-party data flows at render time (AXP1). Unlike static analysis, these checks read the actual runtime state, ensuring that inherited configurations, proxy overrides, and dynamic behaviors are accurately reported.
engine/src/Scanner/AccessibilityRuntime · high confidence
New security scanners and refined false-positive handling for Android, C/C++, Rust, and Kubernetes
The engine now includes several new security scanners and premise re-checks to improve accuracy and coverage. A new scanner detects committed literal credentials in Kubernetes Secret manifests (WD-K8S-0002), addressing cases where standard secret scanners miss plaintext values. A new scanner identifies Docker Compose files that bind-mount the container runtime socket (e.g., docker.sock), a vector for container escape that previous config scanners missed. For Android, a re-check refutes 'exported activity' findings when the activity is the required LAUNCHER. For C/C++, a re-check suppresses 'insecure string copy' findings when the source is a literal or the copy is already bounded and NUL-terminated. For Rust, the engine now respects Cargo audit waivers from .cargo/audit.toml and parses Cargo.lock graphs to provide accurate remediation advice, including handling git-pinned dependencies and multi-lock workspaces.
engine/src/Scanner/Security/Shared/Scanners · high confidence
New security scanners for Docker, Kubernetes, and Compose configurations
Added five new security scanners to the D31 dimension to detect configuration gaps previously missed by vendor tools. The new rules include WD-DOCKER-0017 (BrowserSandboxDisabledScan) to flag Dockerfiles that disable the browser sandbox, WD-DOCKER-0002 (BuildTimeKeyMaterialScan) to detect private keys generated and baked into image layers, WD-K8S-0004 (AutomountedServiceAccountTokenScan) to identify Kubernetes workloads with mounted service account tokens, and two Compose rules: WD-COMPOSE-0003 (ComposeHostNamespaceScan) for services sharing host namespaces or running in privileged mode, and WD-COMPOSE-0002 (ComposeMutableServiceImageScan) for services using mutable image references.
engine/src/Scanner/Security/D31/Scanners · high confidence
New standalone CodeHealth Edition CLI with limited dimension set and PR comment output
A new standalone CLI binary (CodeHealth.Cli.Edition) is introduced that scans a repository and emits a SARIF report, but unlike the full engine it only composes a specific subset of dimensions (D1, D2, D12, D44, D13-D32, D43, AC1-AC7) and excludes model-judged dimensions, git history mining, and executive reporting. The edition explicitly reports languages present in the repository that it cannot analyze and details any dimensions that ran but measured nothing, ensuring transparency about coverage gaps. Additionally, it generates a concise Markdown pull-request comment summarizing findings and coverage limitations, designed to be posted by CI pipelines using their own credentials rather than having the CLI write directly to the repository.
engine/src/CodeHealth.Cli.Edition · high confidence
New statistics infrastructure for build diagnostics and dependency analysis
The engine now includes a new statistics module that provides detailed build diagnostics and inter-project dependency analysis. Build statistics capture not just pass/fail status but also specific failure reasons such as missing toolchains, unloadable source generators, uninitialised git submodules, and unparseable project files, allowing the system to distinguish between genuine code errors and environmental gaps. Dependency analysis has been refined to count only direct project references rather than the full transitive closure, preventing core libraries from artificially inflating coupling metrics. The system also introduces layer convention checking to detect architectural violations (e.g., Domain referencing Web) and a unified cycle detection service that ensures consistent reporting of dependency cycles across all relevant metrics.
engine/src/Core/Statistics · high confidence
Operator console dev seeding for realistic UI previews
The operator console now includes a comprehensive set of dev-only data seeders that populate the UI with realistic demo data, ensuring that screenshots and visual checks reflect actual populated states rather than empty pages. This includes seeding Watchdog and Assay billing subscriptions, scan queue entries with telemetry and failure states, detector-QA ledger items, language training cycles with verification runs and findings, programme cycle goals and holdouts, and recall backlog items with detection deltas. These seeders run exclusively in development environments (guarded by the DevSeedRunner to prevent production writes) and are wired into the AdminHostModule to support headless UI smoke tests and mock-parity validation.
src/Kennel.Admin.App · high confidence
Outbound HTTP resilience analysis now covers non-.NET ecosystems
The P7 readiness check, which evaluates whether outbound HTTP calls are protected by timeouts, retries, and circuit breakers, has been expanded beyond .NET. It now scans Go, JVM languages (Java, Kotlin, Scala), Python, JavaScript/TypeScript, Ruby, PHP, Rust, Elixir, Swift, Dart, and Erlang. The engine identifies service entry points and HTTP client usage in these languages, applying language-specific rules to determine if calls are bounded. It also introduces logic to distinguish browser-only modules from service code, ensuring that frontend fetch calls are not incorrectly flagged as service defects.
engine/src/Scanner/Readiness/P7 · high confidence
P2 Observability now measures non-.NET ecosystems
The P2 Observability dimension now assesses logging, tracing, and health checks for repositories written in JVM, Go, Python, JavaScript/TypeScript, Rust, Ruby, PHP, Swift, Dart, Elixir, and Erlang, rather than reporting them as unmeasurable. The engine identifies the dominant ecosystem via manifest files (e.g., go.mod, Cargo.toml, package.json) and applies ecosystem-specific patterns to determine if modules are service-like and observant. This change prevents false negatives where non-.NET services were incorrectly flagged as lacking observability or dismissed with a generic 'not measurable' gap.
engine/src/Scanner/Readiness/P2 · high confidence
Project Cohesion (D26) now measures non-.NET ecosystems and improves LLM split recommendations
The Project Cohesion analyzer now extends beyond .NET to evaluate build units in other ecosystems (such as Swift, Kotlin, F\#, Erlang, Deno, and Cargo) by detecting project manifests like .xcodeproj, .fsproj, and deno.json. This ensures that repositories without .NET projects are no longer reported as having no applicable data. Additionally, the LLM-based split recommendations have been refined to list actual namespace names rather than just counts, and the system now correctly treats language-specific internal visibility (e.g., Swift's default-internal) as part of the unit's public surface for cohesion scoring.
engine/src/Scanner/Architecture/D26 · high confidence
Python dependency licence compliance and currency analysis
The engine now supports D14 licence compliance and D12 currency checks for Python projects. It reads manifests (pyproject.toml, setup.cfg, requirements.txt) to identify shipped runtime dependencies, excluding dev/test extras and groups. It then queries the PyPI JSON API to resolve licences (using PEP 639 expressions, trove classifiers, and legacy text) and runtime requirements, allowing it to build a transitive dependency closure without a lockfile. The system also implements PEP 440 version parsing to check if pinned dependencies are current, strictly following the 'never suggest a preview' rule by ignoring pre-releases and dev builds.
engine/src/Core/Languages/Python/Dependencies · high confidence
Python dependency reachability analysis for security scanning
The engine now includes logic to determine whether Python packages are actually imported by the application code, distinguishing between production usage, test/tooling usage, and unknown status. This feature analyzes import statements against a curated map of distribution-to-module names to accurately identify unused dependencies, which is critical for security assessments to flag potentially vulnerable but unused libraries.
engine/src/Core/Languages/Python/Security · high confidence
Python domain conventions: new file defining DDD type detection
Added PythonDomainConventions.cs, a new file that implements the Python-specific DDD vocabulary for the engine. It provides predicates to identify Python value objects (dataclasses, pydantic models, etc.), ORM entities (Django, Flask-SQLAlchemy, SQLAlchemy), domain events, and strongly-typed IDs. It also includes a specific check for the DM6 fused active-record smell, detecting when an ORM entity carries domain behavior on its own declaration.
engine/src/Core/Languages/Python/Domain · high confidence
Python sidecar introduces schema v3 with Jedi-backed symbol resolution and structural fixes
The Python sidecar now emits an NDJSON snapshot using schema version 3, adding the \resolvedInRepo\ flag to TypeRef and CallSite records to honestly distinguish between in-repo bindings and name-only references. It integrates the Jedi library for best-effort static symbol resolution (base classes, typed annotations, call owners) while relying on the standard library \ast\ for reliable structural facts. The sidecar includes robustness improvements such as a 10-second cap per Jedi call, a per-file inference budget reset, and a parso cache GC disable to prevent crashes on large repositories. It also fixes structural analysis by correctly handling \@property\ and \@cached\_property\ as properties, excluding docstrings from logical line counts, and ensuring top-level functions have valid source positions in the model.
engine/sidecars/python-frontend · high confidence
Readiness checks P10 and P11 now cover non-.NET ecosystems and BDD specifications
The P10 (Library API & versioning) check now extends beyond .NET to detect published libraries in npm, PyPI, crates.io, Maven/Gradle, Go, RubyGems, Composer, SwiftPM, pub.dev, and Hex by reading their respective package manifests, and it reports on public API surface and versioning discipline for those ecosystems where type visibility is modelled. A new P11 (BDD / executable specs) check has been added to detect and score the presence of BDD frameworks and Gherkin .feature files. Both checks are registered as new readiness dimensions.
engine/src/Scanner/Readiness/P10 · high confidence
Recommendation engine restructured with churn-weighted prioritization and rendering fixes
The recommendation engine in CodeHealth.Reporting.Recommendations has been restructured to improve how remediation actions are prioritized and displayed. A new ChurnPriority component now weights recommendations by file change frequency (D15), ensuring that fixes for actively maintained code rank higher than those for cold code, without altering the underlying dimension scores. The engine now correctly handles advisory cards (which are unscored by design) and unmeasured dimensions with infrastructure gaps, preventing them from incorrectly triggering 'enable measurement' actions or suppressing sibling recommendations. Additionally, the recommendation detail renderer now filters out non-scalar metrics (such as internal collection types) from the metrics table, and applies a consistent display floor to score gains to avoid showing '+0.0 pts' for negligible improvements.
engine/src/CodeHealth.Reporting/Recommendations · high confidence
Report linter enforces trust invariants and finding-text quality
The report generation pipeline now includes a durability linter that validates the final HTML artifact before it ships. It enforces seven hard rules (Error severity) to prevent leaks of internal scratch paths, broken cross-references, inconsistent vocabulary, and impossible counts or percentages, ensuring that faulty renders fail the build rather than reaching customers. Additionally, five heuristic rules (Advisory severity) scan finding text for unadjudicable patterns—such as missing enumerations or imperative instructions—logging them for review without blocking the run.
engine/src/CodeHealth.Reporting/Linting · high confidence
Ruby dependency analysis now scores outdated gems and checks manifest hygiene
The engine now fully supports Ruby dependency analysis for dimension D12. Previously, Ruby repositories returned an unscored abstention because the analyzer could not read local manifests or check for newer releases. This change introduces a new reader that parses Gemfiles, gemspecs, and Gemfile.locks to verify hygiene (such as ensuring applications commit lockfiles and git dependencies are pinned to immutable SHAs) and a new registry client that queries rubygems.org to detect when a locked version is older than the current release. This allows the analyzer to provide a scored, actionable assessment of Ruby dependency currency and stability.
engine/src/Core/Languages/Ruby/Dependencies · high confidence
Ruby test reliability analysis now supports Minitest alongside RSpec
The engine now detects and runs Minitest suites (files matching \\*\_test.rb\ under \test/\) in addition to existing RSpec support. To ensure accurate flakiness detection without altering the repository's dependency set, the engine injects a custom Ruby reporter and a retry-guard plugin into the test environment, allowing it to capture machine-readable JSON results from Minitest just as it does for RSpec. This change closes a coverage gap for approximately half of Ruby repositories that rely on Minitest, enabling reliability scoring for those projects.
engine/src/Core/Languages/Ruby/Testing · high confidence
Rust language support added to code analysis and testing dimensions
The engine now analyzes Rust codebases, introducing support for D9 (test census), D11 (test reliability), and file-length metrics. A new test census counts unit and integration test cases by scanning for standard and framework-specific test attributes (e.g., \\#\[test\]\, \\#\[tokio::test\]\), while a reliability collector executes Cargo suites using \cargo-nextest\ to detect flaky tests. To ensure accurate file-length scoring, the engine now distinguishes between production code and idiomatic inline test modules (\\#\[cfg(test)\]\), preventing Rust's convention of embedding tests in source files from triggering false-positive size violations. Additionally, domain-model heuristics have been added to correctly identify Rust-specific patterns such as error enums, ORM rows, and CLI argument structs.
engine/src/Core/Languages/Rust · high confidence
S1 compliance now measures JavaScript/TypeScript web-security posture
The S1 (Web-Security Posture) dimension now scans JavaScript and TypeScript repositories for cryptographic hygiene and outbound TLS configuration. It detects weak hash algorithms (MD5, SHA-1), weak ciphers (DES, 3DES, RC4, RC2, Blowfish), constant key material fixed in source, disabled TLS certificate validation, and obsolete TLS protocol versions. This reading applies only to production JavaScript/TypeScript code and does not assess server-side controls (HTTPS enforcement, HSTS, security headers, input validation), which remain unmeasured for this language; clean readings abstain from scoring rather than assigning a score.
engine/src/Scanner/Compliance/S1 · high confidence
Scan source checkouts moved to bounded RAM with safe pruning
The scan engine now mounts git source checkouts and scratch I/O on tmpfs (RAM) instead of the NVMe SSD, keeping the workspace size bounded via a new background reaper that prunes idle checkouts after 120 minutes (or 7 days for non-recloneable uploads) while safely preserving live scans using a heartbeat marker. The setup script also enforces correct ownership to prevent permission-denied failures and asserts that environment variables point to the new RAM paths.
deploy/engine-runtime/scan-ram · high confidence
Security engine adds license compliance scanning and key-store secret detection
The security engine now includes a license compliance dimension (D14) that collects package licenses for .NET projects using the dotnet-project-licenses tool or a NuGet API fallback, classifies license text for ecosystems without registry data (e.g., SwiftPM), and flags banned SPDX identifiers. It also adds detection of private keys committed inside PKCS\#12, JKS, and JCEKS key-store containers by parsing the binary format rather than relying on file extensions. Additionally, the engine honours the repository's .gitleaks.toml allowlist to prevent false positives from reviewed credential-shaped content, and embeds the CISA Known Exploited Vulnerabilities catalogue to annotate findings with exploitation evidence.
engine/src/Core/Security · high confidence
Shared incompleteness analysis for JavaScript and TypeScript stubs
The engine now detects unfinished JavaScript and TypeScript code (such as stubs throwing 'not implemented' errors) by extracting shared analysis logic into the Incompleteness.Shared module. This ensures that both the C\# incompleteness dimension (IC1) and the new JavaScript/TypeScript dimension (GD1) apply identical rules for identifying stubs, preventing conflicting reports on the same code. The shared module includes a message parser to identify 'not done' indicators in exception text and a shape analyzer to distinguish deliberate refusals from unfinished work, extending the engine's coverage to script files.
engine/src/Scanner/Incompleteness/Incompleteness.Shared · high confidence
Structured JSON scorecard output for SaaS integration
The system now emits a structured \scorecard.json\ file alongside the HTML report, providing a machine-readable, per-lens and per-dimension breakdown of the analysis results. This file is designed for the SaaS platform to drive trend visualizations, lens-specific popups, and dimension feedback without needing to scrape the HTML. It includes headline scores, weighted contributions, gate coverage gaps, assurance depth metrics, and repository classification details, ensuring that the SaaS can accurately reflect the analysis state and provide actionable insights to users.
engine/src/CodeHealth.Reporting/Scorecard · high confidence
Structured logging check now covers JavaScript and TypeScript
The X4 structured logging dimension now scans JavaScript and TypeScript repositories, closing the previous gap where only .NET code was analyzed. The engine now detects interpolated string messages in log calls (e.g., \logger.error(\...${id}...\\) when using template-capable libraries like pino, winston, or bunyan, and reports them as findings that defeat structured logging by collapsing values into plain text.
engine/src/Scanner/Defects/X4 · high confidence
Support for native mobile app accessibility rendering
The accessibility engine now supports analyzing native mobile applications in addition to web surfaces. A new \NativeApp\ render strategy allows the tool to build the app using its own toolchain, install it on an emulator, and read the platform's accessibility tree directly. This capability is gated by the Runtime Evidence module and is distinct from web-based strategies like Storybook or BootedApp, as it does not involve HTTP requests or server-side rendering.
engine/src/Core/Accessibility · high confidence
SwiftPM dependency analysis now grades currency and reads licences
The Swift language arm now performs two new dependency checks. For currency (D12), it lists git tags on dependency repositories to detect when a pinned version is behind a newer stable release on the same major version, using the git protocol to avoid forge API rate limits. For licences (D14), it first attempts to read the licence file at the pinned commit; if that fails or finds no recognised licence, it falls back to querying api.deps.dev for the repository's current declared licence. Both arms abstain from scoring if any required remote lookup fails.
engine/src/Core/Languages/Swift · high confidence
X10 duplicated-predicate check now covers 15 additional languages
The X10 check, which flags non-trivial boolean expressions written character-identically across multiple files, now extends beyond C\# to JavaScript, TypeScript, Java, Kotlin, Scala, Dart, Swift, Rust, Go, Python, Ruby, PHP, Elixir, Erlang, and F\#. This is achieved by introducing a polyglot lexer in PolyglotPredicates that extracts logical operator chains from source files using language-specific profiles, ensuring that spans are provably correct by rejecting chains at tokens with ambiguous precedence. The analyzer aggregates these cross-language predicates alongside C\# syntax findings to detect duplicated conditions that token-window clone detectors miss.
engine/src/Scanner/Defects/X10 · high confidence
X12 Unreachable Branch detection now covers JavaScript and TypeScript
The X12 dimension, which identifies dead switch arms and unreachable else-if branches, now scans JavaScript and TypeScript files in addition to C\#. This change eliminates the previous 'LanguageReach' gap for repositories that do not contain .NET source code, allowing the tool to report these defects in front-end stacks where case-normalization mismatches or dominated string checks would otherwise go undetected.
engine/src/Scanner/Defects/X12 · high confidence
X15 defect detection now covers JavaScript, Java, Kotlin, PHP, and Ruby
The X15 scanner, previously limited to C\# code, now analyzes JavaScript/TypeScript, Java, Kotlin, PHP, and Ruby repositories for unvalidated length defects. It detects cases where a length read from a binary stream (e.g., via \Buffer.readUInt32\, \DataInputStream.readInt\, \unpack\, or \String\#unpack\) is used to allocate memory (e.g., \Buffer.alloc\, \new byte\[\]\, \SplFixedArray\) without being bounded by a minimum or maximum check. This change ensures that non-.NET codebases are also scored for this specific security risk, closing the previous reach gap.
engine/src/Scanner/Defects/X15 · high confidence
X16 defect check now scans JavaScript and TypeScript for unfloored truncation loops
The X16 defect detector, which previously analyzed only C\# code, now also scans JavaScript and TypeScript files for unfloored truncation loops. This change addresses a gap where non-.NET repositories were not fully analyzed for this specific defect. The new implementation uses a token-based parser to identify while/do loops that shrink a string or array by one character per iteration without a proper lower bound, which can lead to infinite loops or silent data corruption in JavaScript/TypeScript environments.
engine/src/Scanner/Defects/X16 · high confidence
X17 defect detection now covers TypeScript repositories
The X17 scanner, which previously only analyzed .NET code for uncapped recursion over caller-supplied documents, now also scans TypeScript source files (.ts, .mts, .cts, .tsx). This extension allows the engine to detect the same stack-depth vulnerability in non-.NET repositories, closing the previous coverage gap for TypeScript projects.
engine/src/Scanner/Defects/X17 · high confidence
X18 now detects disposal-pattern defects in JavaScript and TypeScript
The X18 dimension (Mishandled disposal duty) has been extended to cover JavaScript and TypeScript repositories. Previously, this check only analyzed C\# code via Roslyn, leaving non-.NET projects with a reach gap. The new implementation scans JS/TS source files to identify ownership mismatches—such as disposing dependencies injected by a container, leaking instances created by a class, or abandoning disposable locals—using the same ownership-based logic as the C\# analyzer. This ensures consistent disposal-pattern correctness scoring across both .NET and front-end codebases.
engine/src/Scanner/Defects/X18 · high confidence
X19 defect check now covers JavaScript and TypeScript
The X19 defect detector, which previously analyzed only C\# code, now also scans JavaScript and TypeScript files for unrestored process-global state mutations (such as changing the working directory or environment variables without a try/finally). This extension ensures that non-.NET repositories are scored on this specific behavioral risk, closing the previous reach gap where these checks were silently skipped for Node.js or Deno projects.
engine/src/Scanner/Defects/X13, engine/src/Scanner/Defects/X19 · high confidence
X21 defect check now covers JavaScript, Java, Kotlin, Ruby, PHP, and Python
The X21 defect scanner, which previously only analyzed C\# \when\ clauses, has been expanded to detect side-effecting mutations in switch-case labels and pattern guards across JavaScript/TypeScript, Java, Kotlin, Ruby, PHP, and Python. This change eliminates the previous 'language reach' gap for these languages, allowing the tool to identify cases where a mutation (such as \++\ or assignment) inside a guard condition can be skipped by short-circuit operators like \&&\ or \\|\|\. The implementation includes language-specific lexers to correctly tokenize constructs like Java's \case ... when\, Kotlin's \when\ branches, Python's \case ... if\ walrus operator, and PHP's \match\ arms, ensuring accurate analysis of state-changing expressions in these contexts.
engine/src/Scanner/Defects/X21 · high confidence
X23 defect detection now covers JavaScript, TypeScript, and Java
The X23 rule, which flags unguarded diagnostic log materialisation (where expensive string operations or collection traversals are computed even when the log level is off), has been extended beyond C\# to analyze JavaScript, TypeScript, and Java source files. This change eliminates the previous 'LanguageReach' gap for non-.NET repositories, ensuring that performance-impacting logging patterns are detected across the entire codebase regardless of the primary language.
engine/src/Scanner/Defects/X23 · high confidence
X24 now detects unescaped document values in JavaScript, TypeScript, Java, and Ruby
The X24 security check, which previously analyzed only C\# code, now extends to JavaScript, TypeScript, Java, and Ruby repositories. It detects cases where text read from a document (such as XML attributes or DOM node content) is interpolated into HTML markup without escaping, potentially allowing injection attacks. The engine uses token-based analysis for these languages to trace tainted values from document reads to markup sinks, including support for single-file components (.vue, .svelte) and Ruby's Nokogiri/REXML libraries.
engine/src/Scanner/Defects/X24 · high confidence
X25 inert configuration knob check now covers JavaScript, TypeScript, Java, and PHP
The X25 defect detector, which previously analyzed only C\# code, has been expanded to scan JavaScript, TypeScript, Java, and PHP repositories. For non-.NET projects, the engine now tokenizes source files using a shared lexer and applies equivalent logic to detect inert configuration knobs: constructor parameters stored in private fields that are never read while their default value is re-spelled elsewhere, keyed setting lookups that fall back to the wrong member, and (for Java and PHP) culture-sensitive formatting bypasses. Additionally, a new Arm D check identifies C\# entry points that write culture-sensitive numbers to standard output while claiming invariant formatting elsewhere. This change eliminates the previous language-reach gap for these technologies, allowing the tool to report these behavioral defects across a broader set of codebases.
engine/src/Scanner/Defects/X25 · high confidence
X26 defect check now scans Java, Kotlin, and Scala repositories
The X26 (Unsynchronised callback handoff) defect detector has been extended beyond C\# to cover Java, Kotlin, and Scala. The engine now performs a reference-free token scan of these languages to identify race conditions where a callback mutates an unsynchronized collection (like ArrayList or HashMap) while the enclosing body waits on a synchronization primitive (like CountDownLatch or Semaphore) to consume it. For repositories containing only languages where this specific shared-memory race cannot be written (such as TypeScript, Rust, or Dart), the check now explicitly reports as 'not applicable' rather than a language reach gap.
engine/src/Scanner/Defects/X26 · high confidence
X27 defect detection now covers Java, Rust, Erlang, and F\#
The X27 defect detector, previously limited to C\# and VB.NET, now scans Java, Rust, Erlang, and F\# source files for self-mutating loops. This change introduces language-specific analyzers that detect structural collection changes during iteration (such as Java's ConcurrentModificationException, Rust's RefCell panic, Erlang's ETS badarg, and F\#'s InvalidOperationException) and updates the language reach census to accurately reflect which languages are now read and which remain gaps.
engine/src/Scanner/Defects/X27 · high confidence
X28 defect detection now supports 15 additional programming languages
The engine's X28 defect scanner (uncovered index guards) has been extended to read and analyze source code in Java, PHP, JavaScript, TypeScript, Python, Elixir, Erlang, Rust, Swift, Dart, Visual Basic, Ruby, Kotlin, F\#, Go, and Scala. Previously limited to C\#, the scanner now includes language-specific masking and condition-parsing logic for these languages, allowing the defect detection to apply uniformly across a much broader set of codebases.
engine/src/Scanner/Defects/X28 · high confidence
X3 dimension now detects swallowed exceptions in Java, Kotlin, Python, Ruby, and Scala
The X3 exception-handling dimension has been expanded to cover non-.NET languages. In addition to the existing C\# analysis, the engine now scans Java, Kotlin, Python, Ruby, and Scala catch/rescue/except clauses to identify swallowed exceptions—cases where a broad catch block is empty or discards the exception without logging, rethrowing, or recording it. The analysis applies consistent rules across these languages, such as treating empty bodies or bodies that merely return a value as swallows, while allowing intentional swallows if they are narrowed to specific exception types or accompanied by explanatory comments. This provides visibility into silent error handling across the full supported language portfolio.
engine/src/Scanner/Defects/X3 · high confidence
X30 defect detection now covers Scala, JavaScript/TypeScript, Java, Kotlin, and Python
The X30 defect detector, which previously only analyzed C\# code, now scans repositories written in Scala, JavaScript/TypeScript, Java, Kotlin, and Python. This expansion allows the engine to detect inverted support guards (De Morgan slips) in non-.NET codebases, ensuring that capability debt is identified regardless of the primary language used in the project.
engine/src/Scanner/Defects/X30 · high confidence
X5 defect check now measures null-typed discipline in TypeScript and JavaScript
The X5 (Nullable Reference Types) defect check has been expanded beyond C\# to cover TypeScript and JavaScript repositories. It now reads \tsconfig\ files to determine if \strictNullChecks\ is enabled and scans source files for the null-assertion operator (\!\) to calculate adoption and suppression metrics. This change eliminates the previous 'gap' for non-.NET projects, allowing the tool to grade null-safety discipline in TypeScript/JavaScript codebases that previously received no assessment for this dimension.
engine/src/Scanner/Defects/X5 · high confidence
X6 defect detection now covers non-C\# languages
The X6 check for hand-rolled JSON/XML parsing (using regex instead of a real parser) now applies to Python, JavaScript/TypeScript, Go, Java/Kotlin/Scala, Ruby, PHP, Rust, and Swift, in addition to C\#. For repositories without C\# projects, the engine scans source files on disk to detect these patterns, ensuring findings are only reported when a real parser of the matching format (JSON or XML) is already used in the same build unit.
engine/src/Scanner/Defects/X6 · high confidence
X7 defect detection now covers Python, TypeScript/JavaScript, Rust, Go, Java, Kotlin, and PHP
The X7 analyzer, which previously only inspected C\# method bodies for silent fallback defaults, now also measures the same defect in Python, TypeScript/JavaScript, Rust, Go, Java, Kotlin, and PHP by reading a language-neutral code model. This expansion allows the tool to flag cases where error-handling paths (such as catch blocks, exception handlers, or error-checking conditionals) return hard-coded constants without logging or throwing, effectively hiding data errors as silent behavior changes. Additionally, a new view-level rule detects Razor components that display a "pending" state (like "loading...") for data sourced from asynchronous message consumers but lack a corresponding failure state, ensuring that permanent delivery failures are not indefinitely masked as "not yet" ready.
engine/src/Scanner/Defects/X7 · high confidence
Security
New TLS edge vhosts and WebSocket upgrade hardening
This change introduces new Nginx configuration files for the deploy/edge location, establishing dedicated TLS vhosts for the admin console (admin.canine.dev), assay app (app.assay.canine.dev), watchdog app (app.watchdog.canine.dev), and partner portal (partner.canine.dev). It also updates the existing watchdog.canine.dev vhost to route legacy API paths to 410 Gone, redirect app traffic to the new app subdomain, and expose new routes for transparency and stable evidence addresses. Crucially, a new shared configuration file (00-connection-upgrade.conf) is added to strictly limit WebSocket upgrades to the 'websocket' value, preventing h2c-smuggling attacks by ensuring non-WebSocket connections receive a 'Connection: close' header.
deploy/edge · high confidence
SDK provisioning now enforces cryptographic signature and SHA-512 verification
The .NET SDK provisioning toolchain in \engine/src/CodeHealth.Toolchain.SdkProvisioning\ has been replaced with a verified installer that ensures only cryptographically signed SDK archives are installed. The system now fetches Microsoft's release metadata, validates the detached CMS signature against a pinned DigiCert root certificate (\digicert-trusted-root-g4.pem\), and verifies the archive's SHA-512 hash before extraction. This change eliminates the previous reliance on host-based trust or simple content-length checks, ensuring that SDKs are only provisioned when their integrity and origin are confirmed by Microsoft's signing identity.
engine/eng, engine/src/CodeHealth.Toolchain.SdkProvisioning · high confidence
Behavioural changes
2801 commits (1013 fixes) modifying tools
A change to existing behaviour in tools — 2801 commits (1013 fixs), 6343 files.
tools · medium confidence · unverified
AC4 keyboard semantics now enforces inline cursor precedence over class rules
The AC4 keyboard semantics analyzer has been refactored so that an element's own inline cursor style takes precedence over CSS class rules when determining interactivity. This change resolves a specific dispute regarding how cursor-based interactivity is detected, ensuring that explicit inline styles are correctly prioritized in the accessibility scan results.
engine/src/Scanner/Accessibility/AC4 · medium confidence
AC7 accessibility enforcement now uses actual markup population and ecosystem-aware advice
The AC7 dimension now determines which accessibility linter to recommend based on the actual markup files present in the repository rather than relying solely on dependency manifests, ensuring that non-Node projects (such as Go, Rust, or .NET) receive tool-neutral advice like asserting invariants in existing test suites instead of being incorrectly directed to install npm-based tools. It also discloses the specific number of markup files assessed and the scope of the search when no enforcement is found, preventing false absence claims and helping users distinguish between a genuine lack of tooling and a coverage gap in the scanner's own markup model.
engine/src/Scanner/Accessibility/AC7 · high confidence
Accessibility scan prework refactored into dedicated readers with shared script caching
The accessibility scan's prework pass has been restructured to read the repository once and share expensive data across all seven accessibility dimensions. A new \AccessibilityScan\ class now acts as the central coordinator, computing repo-level facts (such as CSS hidden classes and landmark presence) and per-document context (such as label associations and loaded scripts) in a single pass. This logic has been extracted into specialized reader classes (\ComponentCallSites\, \EventHandlers\, \LabelAssociation\, \LoadedScripts\, etc.) to improve maintainability. A key behavioral improvement is in \LoadedScripts\, which now caches module reads in a \ModuleReads\ singleton; this prevents OutOfMemory errors in large repositories (e.g., those with thousands of Javadoc pages loading the same scripts) by ensuring each script file is read from disk only once per scan, rather than once per document.
engine/src/Scanner/Accessibility/Accessibility.Prework · high confidence
Added CAI web application log file
A new log file (.claude/cai-web.log) has been added to capture runtime information for the CAI web application. This log records startup details, including the listening port (localhost:5290) and hosting environment, as well as detailed request/response traces for the /api/noise/cascade/resolve endpoint, showing successful HTTP 200 responses and JSON payload handling.
.claude · high confidence
Added Elixir fixture modules for cohesion analysis
The \cohesion-fixture\ sidecar now includes a comprehensive set of Elixir source files (e.g., \account.ex\, \agent\_state.ex\, \registry.ex\) that serve as test cases for the LCOM4 metric. These modules cover various state management patterns—including GenServer, Agent, GenStage, and plain structs—to verify how the analysis engine identifies field usage, handles stateless processes, and distinguishes between shared and independent responsibilities.
engine/sidecars/elixir-frontend/cohesion-fixture · high confidence
Architecture analysis now supports polyglot repositories and source-layout context detection
The engine's architecture map builder and bounded-context resolver have been refactored to operate on a language-neutral code model, enabling accurate C4 topology and boundary-coupling analysis for non-.NET languages (such as Go, Python, and Java) alongside C\#. Context detection now includes a new source-directory mode that identifies bounded contexts by sibling directories containing aggregate roots, resolving the previous limitation where non-Roslyn repositories were incorrectly reported as having no contexts. Additionally, the boundary coupling detector now excludes source-generated types from leak analysis to prevent false positives from auto-generated dispatchers, and fixes a deduplication bug in leaky contract reporting that previously ignored contracts sharing simple names.
engine/src/Core/Architecture · high confidence
Assay report building now requires payment upfront
Building a decision report in Assay now triggers a pay-up-front flow: the system generates a quote and creates a checkout order, returning a 402 status until the charge is paid. A new background dispatcher monitors for completed payments and composes the report once the order is settled, ensuring the process is restart-resilient and idempotent. This replaces the previous model where reports were composed immediately upon request.
src/Kennel.Assay.Core · high confidence
Automatic restart of .NET services after framework upgrades
A new APT post-invoke hook (99-restart-stale-dotnet) ensures that .NET services are automatically restarted if a package upgrade removes the shared framework directory they are running against. This prevents silent failures where services continue running with stale binaries, addressing issues caused by unattended upgrades or manual runtime swaps. The hook runs safely on every APT transaction, logs any actions, and explicitly excludes kennel-worker services to avoid disrupting scan dispatch.
deploy/apt · high confidence
C\# source census now uses Roslyn for accurate composition and size metrics
The engine now classifies C\# code into boilerplate, straight-line, and branching tiers using the Roslyn compiler, providing a more accurate measure of development effort than simple line counts. It also introduces a dedicated Roslyn-based size counter that correctly handles multi-targeted projects by deduplicating files, and fixes a bug where non-.NET repositories were incorrectly sized by falling back to a disk walk that inflated production line counts. Additionally, the census now properly excludes Roslyn analyzer and benchmark projects from the main product surface area.
engine/src/Core/SourceCensusRoslyn · high confidence
CAI presentation bands, quality bar adjustments, and delivery provenance logic
The Kennel.Cai module now centralizes the Code Assurance Index presentation logic and delivery handling. It introduces CaiBands to map 0–100 scores to five visual tiers (Exemplary, Strong, Adequate, Weak, Critical) using cutlines from the standard, while CaiQualityBarBands allows products to shift these thresholds based on declared tiers (Template, Preview, Production, Mission-critical) and lens criticality. CaiDeliveries handles evidence bundle inspection, payload building, and a new reproduction gate that verifies headline scores against the reference scorer before signing. Additionally, CaiSite consolidates the standard's public hostname and API URLs, and CaiMark provides the inline SVG for filed surveys.
src/Kennel.Cai · high confidence
CLI command structure and configuration options redefined
The CLI now introduces a new \AnalyzeCommand\ that orchestrates the full dimension analysis, report rendering, and JSON sidecar writing, replacing the previous monolithic command structure. The \AnalyzeCommandSettings\ now explicitly removes the \--config\ option to prevent silent misconfiguration, while wiring \--verbose\, \--cache-dir\, \--timeout\, \--output\, \--detailed\, and \--security-only\ flags. A new \ApiSurfaceCommand\ is added to extract HTTP routes syntactically without a build. Internal command helpers like \BootAttempt\, \BundleCompletion\, \BundleScrubbing\, \ChangelogDrafting\, and \CheckoutRestore\ are introduced to handle runtime boot outcomes, bundle artifact scrubbing, changelog drafting, and .NET checkout restoration respectively.
engine/src/CodeHealth.Cli/Commands · high confidence
CLI logging and LLM infrastructure overhaul
The CLI now supports the --verbose flag by using a dynamic log-level filter instead of a static minimum, ensuring that verbose output is actually emitted when requested. LLM interactions are now centrally managed with a process-wide concurrency permit, a retry ladder for transient failures, and detailed telemetry (usage, work-unit counters, and scan timings) published to JSON files for live progress and post-run analysis. Additionally, the composition root explicitly registers C\#-specific analyzers and tooling only when the build targets .NET, preventing unnecessary compiler dependencies in non-.NET editions.
engine/src/CodeHealth.Cli/Composition · high confidence
Complexity findings now include actionable remediation and precise nested-function attribution
The Cyclomatic (D1) and Cognitive (D2) complexity dimensions now provide specific, shape-aware remediation advice tailored to the code structure (e.g., distinguishing between flat dispatchers and deeply nested logic) and accurately attribute complexity to nested helper functions that dominate the score. The engine also suppresses flat dispatchers (high cyclomatic, low cognitive) from the main findings to reduce noise, while disclosing them separately, and ensures that supplementary language models are correctly included in the analysis to prevent hiding complexity in non-primary languages.
engine/src/Scanner/Complexity · high confidence
Custom branded login theme replaces default Keycloak UI
The login interface now uses a custom theme that matches the application's visual identity (dark/light modes, branding) instead of the stock Keycloak look. The sign-in page exclusively offers identity provider buttons (GitHub, GitLab, Bitbucket, Microsoft) and hides the traditional username/password form. This change is enforced by ensuring no user accounts hold password credentials, verified by a new deployment script, rather than disabling the form at the server flow level.
deploy/keycloak-themes · high confidence
D13 Secret Scoring and Noise Filtering
The D13 secret scanning dimension now scores based on unique secret fingerprints rather than raw occurrences, ensuring that duplicate detections of the same secret do not disproportionately penalize the score. It also introduces specific noise filters to suppress false positives from documented examples (e.g., Ruby \\# =\>\ lines), Homebrew formula test blocks, text sentinel constants, and keyboard-row placeholder compositions, while explicitly reporting the count of suppressed items in the analysis narrative for auditability.
engine/src/Scanner/Security/D13 · high confidence
D16 Bus Factor analyzer now uses living knowledge decay instead of git blame
The D16 (Bus Factor) dimension in the GitMining scanner has been refactored to calculate knowledge concentration based on 'living' commit history with a 6-month decay model, rather than relying on static git blame. This change prevents false positives where mechanical refactors or bulk updates incorrectly reassigned ownership, ensuring that only authors with recent, substantive contributions are considered when identifying single points of failure. The analyzer now registers as a standalone service and declares its dimension ID explicitly, while also introducing a 'drive-by' floor to distinguish between genuine sole ownership and repositories with many one-off contributors.
engine/src/Scanner/GitMining/D16 · high confidence
D23 Boundary Type-Coupling now measures non-.NET codebases and judges context necessity
The D23 Boundary Type-Coupling dimension now operates on repositories without C\#/VB projects (e.g., TypeScript, Go, Python) by analyzing the language-neutral code model, whereas it previously returned 'NotApplicable' for such codebases. Additionally, the dimension now uses an LLM-assisted judge (with a deterministic 20,000 LoC fallback) to determine if a codebase with no declared bounded contexts actually requires them, rather than simply skipping the measurement.
engine/src/Scanner/ArchitectureJudged/D23 · high confidence
D27 Navigability analyzer now correctly reports language reach gaps and abstentions
The D27 Navigability analyzer has been updated to accurately distinguish between a repository having no call sites and the analyzer lacking support for the repository's primary language. Previously, unsupported languages (such as Swift, Dart, or TypeScript) or failed loads could result in misleading 'NotApplicable' scores or confident perfect scores for the wrong code. The analyzer now explicitly flags these as 'OurGap' engine gaps, ensuring users understand when the analysis is incomplete due to missing language support rather than code quality. Additionally, the analyzer now correctly samples call sites from sidecars that emit census data, improving coverage for polyglot projects.
engine/src/Scanner/Architecture/D27 · high confidence
D28 secrets scanner now scans git history and working tree with improved precision and stability
The D28 security dimension now performs a deep scan of both the full git history and the current working tree to detect secrets, merging and deduplicating findings to catch credentials that were committed and later removed as well as live plaintext secrets. This change introduces a new registration component and assembly metadata declaring the analyzer as language-agnostic (with a specific noise filter for Rust inline tests), and fixes a regression where the scanner was ignoring the repository's .gitleaks.toml allowlist. Additionally, the implementation prevents OutOfMemory errors by writing gitleaks reports to temporary files instead of stdout, and adds gates to filter out false positives from renamed files and inline test regions.
engine/src/Scanner/Security/D28 · high confidence
D31 Infrastructure Security dimension now explicitly language-agnostic
The D31 Infrastructure Security analyzer (located in engine/src/Scanner/Security/D31) has been refactored to declare itself language-agnostic via the \[LanguageAgnostic\] assembly attribute. This change signals that the dimension scans infrastructure artifacts (Dockerfiles, Terraform, Kubernetes, Helm, CloudFormation, Bicep, Ansible) rather than source code, meaning it does not require per-language analysis arms. The dimension now correctly returns a 'NotApplicable' result for repositories lacking these manifests, preventing spurious scores, and registers its shared infrastructure security services (including the InfrastructureSecurityAnalyzer) via a dedicated registration method.
engine/src/Scanner/Security/D31 · high confidence
D32 Data Compliance analyzer now declares supported languages and fixes unanalyzed file reporting
The D32 (Data Compliance/PII/GDPR) analyzer now explicitly declares the languages it supports—including C\#, Dart, Elixir, Erlang, F\#, Go, Java, Kotlin, PHP, Python, Ruby, Rust, Scala, Swift, TypeScript, and VB—ensuring the declared matrix matches the underlying semgrep ruleset. Additionally, the analyzer now correctly reports files that semgrep could not parse (unanalyzed files) in its results, preventing a silent distinction between clean analysis and parsing failures, and improves the scoring logic to better reflect the severity of PII findings.
engine/src/Scanner/Security/D32 · high confidence
D4 duplication analysis now covers supplementary languages and excludes test projects
The D4 (Code Duplication) analyzer has been updated to scan all supplementary code models (e.g., Rust, Go, TypeScript sidecars) in addition to the primary language, preventing false 'not measured' gaps when non-primary languages contain duplicated code. It also explicitly excludes test projects from duplication counts to avoid inflating scores with repetitive test boilerplate, and now correctly reports 'Not Measured' with an 'OurGap' when the analysis window is truncated or no source files are found, rather than falsely reporting a perfect score.
engine/src/Scanner/CodeShape/D4/CodeShape · high confidence
D4 duplication dimension now requires token streams and registers independently
The D4 code duplication dimension has been refactored to operate as an independent, self-contained unit. It now explicitly declares a dependency on the \ModelFact.TokenStream\, meaning it will only produce results when actual tokenized source files are provided rather than just model metadata; if tokens are missing, it abstains from scoring instead of reporting a false positive. Additionally, the dimension's service registration has been moved out of the shared \AddCodeQualityDimensions\ composition into its own \AddD4Duplication\ method, allowing it to be added selectively without forcing the inclusion of other dimensions or their specific language dependencies.
engine/src/Scanner/CodeShape/D4 · high confidence
D7 Architectural Integrity analyzer now abstains when ADR classification is missing
The D7 (Architectural Integrity) dimension now explicitly abstains from scoring when ADRs require enforcement classification but the classification pass has not run, rather than silently scoring an unknown population. It also returns a 'Nothing to assess' result when there are no ADRs and no dependency cycles, preventing fabricated scores in empty repositories. The analyzer combines ADR enforcement maturity with dependency-cycle detection, penalizing for unenforced rules, cycles, and violated ADR rules, and now correctly discloses measurement gaps via EngineGaps.
engine/src/Scanner/Architecture/D7 · high confidence
DGX1 model host restart resilience and memory tuning
The DGX1 model host deployment now mounts persistent compile caches for vLLM and Triton, reducing restart times from \~350s to \~270s and shrinking the window for JIT-compile crashes. The BF16 service unit also lowers GPU memory utilization from 0.85 to 0.75 to provide the CUDA driver with more headroom, mitigating unified-memory faults. Additionally, two switch scripts with automatic rollback are provided to safely toggle between the BF16 and official FP8 model units.
deploy/dgx1 · high confidence
Dart dead-field detection now uses repository-wide usage counts to reduce false positives
The Dart defect detection for dead private fields has been refined to distinguish between truly unused members and those that escape their declaring class. Previously, the engine only checked if a field was unused within its own file, which led to false positives for public fields of private classes that were accessed via public variables in other files. The new implementation introduces a repository-wide identifier index that counts occurrences across all Dart files in the scanned project. This allows the detector to correctly identify fields that are only declared once (in their own definition) as dead, while preserving findings for fields that are actually read elsewhere in the repository, even if they belong to a private class.
engine/src/Core/Languages/Dart/Defects · high confidence
Dart domain conventions now detect aggregates, entities, value objects, and domain events
The engine now recognizes Dart-specific domain patterns, replacing previous stubs that returned false for aggregates, entities, value objects, and domain events. This enables the analyzer to correctly identify tactical DDD constructs in Dart code, such as classes inheriting from AggregateRoot or Entity, value objects with immutable state and value-based equality, and types conforming to a domain event contract. Presentation roles like Widgets, BLoCs, and Cubits are explicitly excluded from domain analysis to prevent false positives.
engine/src/Core/Languages/Dart/Domain · high confidence
Defect cards are split into language-specific and security-specific shared modules
The defect card generation logic has been reorganized into distinct shared modules: CSharpCards handles C\#-specific analysis predicates (such as identifying terminal text sinks and log-shaped methods), DataShapeCards provides shared counters for advisory findings, DefectCards builds standard code-health defect cards, and SecurityCards builds security-compliance cards. This separation ensures that C\#-specific logic is isolated from general defect reporting and security-specific rendering, while maintaining consistent gap handling for repositories without compiled C\# projects.
engine/src/Scanner/Defects/Defects.Shared · high confidence
Defects prework now distinguishes C\#-only checks from format-specific parser usage
The Defects prework pass has been split to handle tree admission and data collection separately for different defect families. For the X6 and X7 checks, a new DataShapeScan pass collects project-level facts about which structured formats (JSON or XML) are actually referenced by real parsers in the codebase, ensuring that recommendations are only made for formats the project already uses. For the broader X1-X5 checks, the main DefectsScan pass continues to handle tree admission, de-duplication across target frameworks, and test-path filtering, but now explicitly tracks whether any C\# project was loaded to correctly determine language reach for C\#-specific rules.
engine/src/Scanner/Defects/Defects.Prework · high confidence
Dependency findings now show usage context and sort by reachability
The findings report now provides clearer context for dependency issues. Within each severity level, dependency findings are sorted by reachability: production usage appears first, followed by unknown, then tests/tooling, and finally not-imported packages. Additionally, each dependency finding now displays a specific note indicating where the package is used (e.g., "imported by production code at path:line" or "used only by tests and tooling"), and for not-imported packages, it lists the specific affected packages rather than just the module. The report also now correctly includes meta-dimension findings in all summary counts and detail views, ensuring that previously hidden findings are visible to users.
engine/src/CodeHealth.Reporting/Findings · high confidence
Deterministic integrity and grounding guards for LLM findings
The engine now applies strict, code-based validation to LLM-generated findings to prevent hallucinations and ungrounded advice. New integrity checks ensure that quoted text actually exists in the source document, that claims about missing sections or topics are verified against the full document content, and that any code references (namespaces, types) cited by the model are confirmed to exist in the repository. Additionally, a JSON response validator now treats empty or null LLM outputs as failures rather than crashing, and a stability mechanism requires consensus between two independent evaluation passes before a critique is published, effectively filtering out one-off confabulations.
engine/src/CodeHealth.Llm.Abstractions/Validation · high confidence
Deterministic synthesis and runtime scanner cache seeding
The engine now provides deterministic, evidence-backed conclusions in the Diagnosis section, where every inference is tied to specific source signals and severity levels rather than relying on the LLM for logic. Additionally, the toolchain now automatically seeds scanner caches (such as Trivy and Semgrep) at runtime from the analyzer image, ensuring that production scans use the correct vulnerability databases and check bundles even when Docker volumes are initially empty.
engine/src/Core/Llm, engine/src/Core/Synthesis, engine/src/Core/Toolchain · high confidence
Engine gaps are now explicitly separated from findings and surfaced on the coverage surface
The engine now distinguishes between actual findings (defects in the repository) and engine gaps (limitations in the analysis run). Gaps are no longer hidden in raw metrics or incorrectly merged with findings; instead, they are collected in a dedicated list on the dimension result and synthesized for unmeasured dimensions. This ensures that engine limitations are visible on the coverage surface and in the watchdog-qa UI, rather than being lost or misreported as findings.
engine/src/CodeHealth.Core/Dimensions · high confidence
Engine now tracks scan phase timings and enforces strict budget hierarchies to prevent silent cancellations
The engine now records wall-clock timings for every analysis phase (checkout, restore, dimensions, etc.) and writes them to scan-timings.json, allowing operators to identify performance bottlenecks. Crucially, it introduces a strict, derived budget hierarchy where inner tool budgets are always capped below their enclosing dimension and run budgets, preventing scenarios where a tool's timeout exceeds its container's limit. This ensures that if a run is cancelled due to time limits, the engine can identify exactly which phase was in-flight before termination, rather than silently failing or misattributing the cause.
engine/src/Core/Diagnostics · high confidence
Engineering and Sprint Plan reports now include ranked task rationale, unmeasured dimension handling, and folded dimension visibility
The new Engineering and Sprint Plan renderers in the reporting engine provide more transparent, actionable outputs for developers and agents. The Engineering report now includes a 'RankReason' column explaining why each task is positioned where it is (based on score gain, effort, and code churn), ensuring the ranking is interpretable rather than arbitrary. It also correctly distinguishes between dimensions that scored zero and those that were never measured (displaying 'Not measured' instead of a misleading '0.0/10'), and explicitly lists 'AlsoLifts' for dimensions folded into a root-cause task, preventing machine consumers from missing related improvements. The Sprint Plan renderer leverages this same task list to generate release-readiness verdicts and sprint tickets with clear Definitions of Done, ensuring consistency between the human-readable markdown and the machine-readable JSON artifacts.
engine/src/CodeHealth.Reporting/Engineering · high confidence
Frontend analysis engine restructured into modular dimension slices
The frontend scanning logic has been refactored from a monolithic core into distinct, modular slices (e.g., R1 for Type Safety, R10 for Duplication), each registering its own analyzer and remediation logic. This change introduces a new \FrontendScan\ pass that computes shared module-graph facts and detector outputs (dead code, dependency hygiene, boundaries) which are then consumed by individual dimension analyzers. The R10 duplication dimension now includes a whole-tree fork detector that identifies byte-identical file trees outside the standard tokenized scope, and both R1 and R10 provide context-aware remediation text that adapts to the specific state of the repository (e.g., distinguishing between adopting TypeScript vs. migrating existing files).
engine/src/Scanner/Frontend · high confidence
Go security rules now suppress false positives via context-aware re-checks
The Go security scanner now applies specific re-checks to suppress false positives that arise from context the initial pattern match cannot see. For example, versionless \go install\ commands are no longer flagged if they run inside a module directory where the version is pinned in \go.mod\ and \go.sum\. Similarly, \InsecureSkipVerify\ is no longer reported when it is conditionally enabled by an operator opt-in flag (e.g., \if cfg.Insecure\), and \math/rand\ usage is cleared if every call site carries a required review comment. The engine also ignores \management.\*\ properties found inside JSON string literals (rather than live config) and treats empty \http.Cookie{}\ templates handed to constructors as non-configurative. These changes reduce noise while keeping genuine defects visible.
engine/src/Core/Languages/Go/Security · high confidence
God-class detection now excludes generated, vendored, and demonstration code
The God-class dimension (D3) now accurately distinguishes between the team's maintainable code and external or auto-generated artifacts. It excludes files in vendored trees (e.g., node\_modules, vendor), demonstration/example apps, and code marked as generated via banners or region comments. This prevents false positives where large third-party libraries or auto-generated codecs were previously flagged as maintainability debt. Additionally, the analyzer now deduplicates findings for the same physical file and ranks results by severity to ensure the most egregious offenders are visible in capped views.
engine/src/Scanner/CodeShape/D3/CodeShape · high confidence
Hardened hosting infrastructure with explicit background-loop roles, credential key wrapping, and meaningful health checks
The hosting layer now enforces stricter operational safety and security: background loops (reconcilers, sweeps) will refuse to start unless the host explicitly declares its role via the \Kennel:BackgroundServices:Enabled\ configuration key, preventing silent failures when the key is missing. Stored credentials are now wrapped with an off-machine Key Encryption Key (KEK) fetched from a custodian, ensuring that stolen backups or disks cannot be opened without the separate custodian. The \/health\ endpoint has been upgraded to report the specific build and tier (derived from the database connection) and includes a real database reachability check, replacing the previous empty green light. Additionally, all numeric and date formatting is pinned to Invariant Culture to prevent data-corrupting rendering bugs across different server locales.
src/Kennel.Hosting · high confidence
Improved clone detection accuracy and expanded coverage for C\# code
The C\# clone detection engine has been refactored to reduce false positives and detect previously missed duplication. String literals are now content-aware (hashed) rather than generic, preventing distinct code blocks that only share boilerplate strings from being flagged as clones. Additionally, the detector now keys clone windows by the original contract signature of overridden methods, allowing it to detect verbatim copy-paste errors between sibling classes in generic hierarchies. The engine also now analyzes declaration-only runs (such as constructors and field initializers), enabling the detection of duplicated structural code that was previously invisible to the detector.
(repo-wide) · high confidence
Improved dead-code detection accuracy for application assemblies and reflective usage
The dead-code detector now correctly identifies unreferenced public types in application projects (Exe/WinExe) as dead code, whereas previously public symbols were spared to avoid false positives in libraries. It also introduces a pre-pass that tracks home-grown attributes consumed via reflection and syntactic usage patterns (generic type arguments, member-access invocations, and reflection string lookups) to prevent false positives when Roslyn's reference search fails to bind due to unresolved packages. Additionally, the tool now scans the entire repository for all possible preprocessor symbol definitions (MSBuild, scripts, SDK shapes) to avoid flagging valid cross-platform conditional compilation as dead code.
engine/src/Core/ExplicitDebt · high confidence
Improved frontend reachability analysis for TypeScript and Node.js projects
The engine now more accurately identifies live code by recognizing TypeScript ambient declaration files (\.ts\/\.tsx\ without imports/exports) as non-dead, mapping compiled build outputs back to their source files via \tsconfig.json\ or package manifests, and detecting Node.js directory-barrel patterns that load modules dynamically. It also excludes non-JavaScript documentation sites (mdbook, MkDocs) from frontend analysis and correctly identifies Egg.js middleware references, ensuring that files loaded by runtime conventions are not falsely reported as dead code or untested.
engine/src/Core/Frontend · high confidence
Improved live progress visibility and crash resilience
The CLI now provides a more detailed and stable progress experience during code analysis. A new file-based progress sink writes real-time status to a JSON file, enabling the SaaS dashboard to display specific analysis phases (e.g., "Analyzing ADR quality") and LLM call counts instead of a generic "Analyzing…" message. Additionally, the console progress renderer has been hardened to prevent crashes caused by race conditions with late progress updates, ensuring that cosmetic UI issues no longer abort the analysis run.
engine/src/CodeHealth.Cli/Ui · high confidence
Java DDD and event-sourcing conventions now recognize Axon, jMolecules, and Spring Data
The Java language module now correctly identifies Domain-Driven Design and event-sourcing patterns specific to the JVM ecosystem. Aggregate roots are detected via Axon's @Aggregate, DDD library @AggregateRoot, jMolecules type interfaces, or Spring Data's AbstractAggregateRoot base class. Entities are recognized by JPA/Jakarta @Entity or DDD @Entity annotations. Value objects are identified as records, @Embeddable/@ValueObject annotated types, or immutable classes with final fields. Domain events are detected by implementing jMolecules' DomainEvent interface, or by being immutable classes/records with names ending in 'Event' or using past-tense naming in event packages. Event-sourcing state folds are identified by @EventSourcingHandler annotated methods. This module is strictly gated to Java/Kotlin types to avoid false positives from other languages.
engine/src/Core/Languages/Java · high confidence
LCOM4 cohesion calculator migrated to D6 with multi-language support and refined exemption logic
The LCOM4 cohesion calculator has moved from the D5 dimension into D6 (CodeHealth.Core.Cohesion), consolidating the metric's consumer with its implementation. This change introduces support for VB.NET classes via a neutral code model and expands the set of measured file extensions to include Go, Scala, Swift, Dart, Java, Python, Kotlin, TypeScript, JavaScript, PHP, Ruby, Rust, and Erlang/Elixir. The calculator now applies more granular exemptions to avoid false positives, excluding classes that are event-sourcing shaped, stateless, stub-like, inherit state, fulfill multiple contract obligations, are source-generated, act as state holders or fluent builders, or have unexposed bodies. Additionally, it correctly handles multi-targeted projects by computing cohesion per TFM leg and reporting the worst-case score, while de-duplicating partial classes and excluding co-located test code.
engine/src/Scanner/Architecture/D6/Cohesion · high confidence
LLM-judged compliance dimensions are now individually registered and more robustly handle non-.NET code and LLM abstentions
The LLM-judged language compliance checks (LA1–LA5) have been split into individual, independently registerable slices (e.g., \LA1GdprPersonalDataRegistration\, \LA2AltTextQualityRegistration\), allowing them to be composed without requiring the entire family. For LA1 (GDPR personal data), the analyzer now uses a neutral code model to detect personal data in non-.NET repositories (Ruby, Python, etc.) instead of silently reporting no findings, and it correctly distinguishes between "no source read" and "no personal data found." For LA3 (Security policy) and LA4 (Environment separation), the system now correctly reports an "OurGap" when the LLM judge runs but abstains, rather than incorrectly asserting a clean 10.0 score. LA2 (Alt-text quality) and LA5 (Link-text quality) also include improved deduplication and reporting logic to ensure findings are accurately attributed to specific files and lines.
engine/src/Scanner/LlmJudgedLanguage · high confidence
Maturity dimensions M1 and M2 are split into independent, individually registerable components
The Maturity scanner's documentation (M1) and architecture documentation (M2) dimensions have been decoupled from a monolithic emitter into separate, standalone projects. Each dimension now has its own registration method (AddM1Documentation, AddM2ArchitectureDocs) and assembly-level declaration, allowing them to be included or excluded independently rather than as a single block. M1 now explicitly detects and reports repository end-of-life declarations found in READMEs, while M2 has expanded its architecture diagram detection to support additional formats like Mermaid, PlantUML, and D2, and refined its ADR detection logic.
engine/src/Scanner/Maturity · high confidence
Model-aware analysis now uses a language-neutral type surface and caches semantic models
The engine's model-aware detection now operates on a language-neutral type list (Nm.ICodeType) in addition to the existing Roslyn symbol path, ensuring byte-identical architectural style and domain-layer detection across all supported languages. This change introduces a new BodyModelLookup cache to efficiently resolve semantic models for body-level analysis without rebinding per node, and adds a DomainComplexityClassifier that infers domain complexity tiers based on detected architecture styles, app kinds, and decision density.
engine/src/Core/ModelAware · high confidence
Naming review now includes symbol annotations to resolve false inconsistencies
The D21 naming review engine now attaches declaration metadata—such as accessibility, property/field types, method return types, and test attributes—to sampled symbols. This change resolves specific disputes where the judge incorrectly flagged consistent naming as inconsistent because it could not distinguish test methods from helper methods, or mix verb/noun naming conventions across different method roles (void commands, bool predicates, value-returning helpers). By providing this context, the review tool can now accurately assess naming conventions without generating false positives for correctly named helpers or role-appropriate method signatures.
engine/src/Core/Naming · high confidence
New coupling scoring engine with refined abstractness calculation
The engine now uses a dedicated scoring pipeline in \engine/src/Core/Coupling\ to calculate Martin's D5 coupling metrics. This introduces a pure-arithmetic \CouplingScore\ that applies specific penalties for dependency cycles, unstable hubs, and off-main-sequence projects, while exempting shared-kernel libraries and degenerate graphs from the 'zone of pain' penalty. Additionally, the calculation of Martin's Abstractness (A) now explicitly excludes generated types and framework polyfills, ensuring the metric reflects only the project's own design choices rather than tooling artifacts.
engine/src/Core/Coupling · high confidence
New enforcement detection and PII resolution components
The engine now includes new components in the Enforcement and Pii namespaces to improve accuracy and privacy in reporting. CiGateDetection, DimensionEnforcementDetector, and DimensionEnforcementKeywords introduce stricter CI gate detection that distinguishes real build-failing invocations from comments, install lines, and soft-failed steps, while GateCoverage ranks missing security and quality gates by the repository's actual measured gaps. IdentityAnonymizer and PiiResolver provide audience-aware PII handling, replacing raw identities with stable anonymized labels in public reports and correctly decoding format-specific escapes (HTML/JSON) to ensure accurate identity resolution.
engine/src/Core/Enforcement, engine/src/Core/Pii · high confidence
New repository profiling vocabulary and gating logic for model-aware dimensions
The engine now classifies repositories by application kind (e.g., Library, WebApi, Worker) and architectural style (e.g., DDD-layered, CleanHexagonal, VerticalSlice) to determine which model-aware analysis lenses should run. This change introduces a conservative detection mechanism that gates dimensions like Domain-Modelling and Event-Driven based on specific code markers, ensuring that lenses only activate when relevant evidence is present. It also refines scoring logic for adoption curves and hard-fact violations, and improves report clarity by explicitly stating why a lens was enabled or skipped, preventing misleading findings on repositories that do not match the targeted architectural patterns.
engine/src/CodeHealth.Core/Profile · high confidence
New scan contract types and refined finding data model
The engine introduces a new \ScanContracts\ assembly containing core data structures for security scanning. \ScanFinding\ is expanded to support dependency reachability (carrying affected Go packages and functions via \AdvisoryImport\), secret deduplication (via \SecretFingerprint\), and taint-mode source tracking (\TaintSource\). A new \PremiseRefutation\ system replaces a monolithic dispatcher, allowing individual rule re-checks to declare which premises they refute, improving precision. Path exclusions are updated to ignore SwiftPM's \.build/checkouts\ directory and Claude Code's \.claude\ directory, preventing false positives from vendored dependencies and agent tooling. A new \LineReader\ provides cached access to source lines for re-checks, and \ScanDetectorIds\ centralizes detector identifiers to resolve assembly cycles.
engine/src/Core/ScanContracts · high confidence
P6 Release Hygiene dimension now credits versioned release logs in READMEs, package manifests, and generated notes
The P6 (Release Hygiene) readiness scan has been expanded to recognize release history stored in locations other than a dedicated CHANGELOG file. It now credits versioned release logs found in README sections, package manifests (such as csproj \<PackageReleaseNotes\>), and automatically generated release notes driven by CI configuration. Additionally, the scoring logic has been adjusted so that repositories with explicit versioning or semver tags are rated as having traceable releases even if no changelog is present, preventing a 'Critical' rating for repos that maintain release traceability through other means.
engine/src/Scanner/Readiness/P6 · high confidence
P8 schema-migration check now supports non-.NET ORMs and abstains on unrecognised migration tools
The P8 (Schema migrations) readiness check has been expanded to evaluate database schema evolution for ORM ecosystems beyond .NET/EF Core, including GORM, SQLAlchemy, TypeORM, and Hibernate, by detecting their respective auto-create patterns (e.g., AutoMigrate, synchronize: true) and versioned migration mechanisms. For .NET projects using EF Core, the check now explicitly abstains from scoring when a migration runner other than EF Core migrations (such as DbUp, Flyway, or Liquibase) is used but not recognised, preventing false penalties for valid migration strategies. This ensures that repositories using non-EF migration tools are not incorrectly flagged as lacking a migration strategy, while still warning against unversioned auto-creation of schemas across all supported ecosystems.
engine/src/Scanner/Readiness/P8 · high confidence
Refactored localdev UI test runners into shared, testable library modules
The localdev UI test runners (capture and snap) now share a set of extracted, pure library modules in \tools/localdev/ui/lib\ to eliminate code drift and improve testability. This change introduces a shared CLI argument parser (\cli.mjs\) that standardizes \--app\ and \--base\ handling across layers, a unified PASS/FAIL tally (\checks.mjs\) for smoke results, and a consistent entry resolution path (\resolve.mjs\, \screens.mjs\) so that manifest entries are navigated identically in both capture and snapshot modes. It also adds a volatility normalizer (\normalise.mjs\) to replace dynamic values like timestamps and GUIDs with stable tokens before aria-snapshot comparison, and a contact sheet renderer (\contact-sheet.mjs\) with proper HTML escaping to safely display test results. Additionally, a new \acting.mjs\ module ensures a consistent acting scope for tests, and a coverage guard (\coverage-rules.mjs\) now correctly determines page ownership based on declared UI audiences rather than directory structure.
tools/localdev/ui · high confidence
Refined detection of shell projects and improved handling of multi-solution workspaces
The Solution Shape analyzer (D18) now more accurately identifies 'shell' projects by exempting specific structural patterns that were previously flagged as noise: AOT/trimming compatibility harnesses, content-only projects (e.g., documentation folders), test fixture assemblies, and composition root executables. Additionally, the analyzer now correctly handles repositories with multiple solutions by loading all live solutions into a single workspace, ensuring consistent scoring across complex monorepos.
engine/src/Scanner/BuildDependent/D18/SolutionShape · high confidence
Refined duplication findings and Razor name display logic
The engine now provides more precise duplication reports by introducing detailed metadata (such as content hashes, structural context flags, and identity fingerprints) to distinguish between different types of code clones and prevent false positives from overlapping or drifted groups. Additionally, a new utility class handles the display of member names within Razor \@code\ blocks, ensuring that internal synthetic wrapper names are hidden from users and replaced with readable file-and-member paths.
engine/src/Core/CodeShapeContracts · high confidence
Relocate CodeHealth analysis engine to kennel/engine/
The CodeHealth analysis engine has been moved into the new kennel/engine/ directory structure. This relocation includes the addition of a Markdown report template for generating deterministic dimension tables and a trend window utility that manages time-based and scan-count-based filtering for trend lines, ensuring consistent reporting across web and PDF outputs.
engine/docker/analyzer/nodecache, engine/src/CodeHealth.Reporting/Markdown, engine/src/CodeHealth.Reporting/Trends · high confidence
Repository scans now union multiple solutions and fix case-sensitivity issues
The toolchain now analyzes the union of all live solutions in a repository rather than just the single largest one, ensuring that code in disjoint solution files (e.g., product vs. engine) is included in the analysis. It also automatically repairs solution files where project paths have incorrect casing or use Windows-style backslashes on case-sensitive file systems, preventing projects from silently vanishing during load.
engine/src/CodeHealth.Toolchain.Solutions · high confidence
Roslyn code model refactored into a unified, language-neutral provider with precise C\# analysis logic
The Roslyn analysis layer has been restructured into a set of dedicated classes within the \CodeHealth.Core.Roslyn.CodeModel\ namespace, replacing scattered logic with a clean, shared provider (\RoslynProvider\) and neutral adapters. This change introduces precise, documented logic for C\# code analysis, specifically distinguishing whether an expression is a member's produced result (excluding lambda bodies) and identifying method-local buffer receivers to prevent false positives in mutation analysis. The refactoring also adds explicit support for VB.NET via a dedicated \RoslynVbMethodBody\ adapter, ensures correct language stamps for .NET types to avoid cross-language rule leakage, and resolves namespace ambiguity issues by using explicit aliases for shared enum names.
engine/src/Core/Roslyn/CodeModel · high confidence
Roslyn workspace integration becomes opt-in with per-service scoping
The Roslyn-based .NET analysis is now opt-in, introducing an \AbsentRoslynWorkspace\ that returns a failed load result when .NET support is not included, ensuring non-.NET scanners (e.g., Go) do not inadvertently report clean results for unloaded code. Additionally, a \ScopedRoslynWorkspace\ wrapper allows filtering loaded projects to specific services within a monorepo, enabling per-service Code Assurance Index calculations without re-loading or re-compiling the underlying solution.
engine/src/CodeHealth.Toolchain.RoslynContracts · high confidence
Ruby sidecar introduces schema version 5 and fixes branch scoring and UTF-8 line mapping
The Ruby sidecar now emits NDJSON snapshots using schema version 5, which is additive and introduces a new \type.isModule\ boolean to flag Ruby modules as interfaces (analogous to PHP traits) and extends the \resolvedInRepo\ resolution contract to cover superclass and mixin bindings. The sidecar fixes a critical bug where source files containing multi-byte UTF-8 characters (such as emojis) caused line-offset miscalculations and model degradation by switching from UTF-16 code units to UTF-8 byte offsets for line mapping. It also corrects cognitive complexity scoring by ensuring Ruby ternary operators are mapped to the \Conditional\ branch kind (consistent with other frontends) rather than being incorrectly counted as \If\/\Else\ pairs, and fixes safe-navigation operators (\&.\) to count as cyclomatic branches without adding cognitive complexity points.
engine/sidecars/ruby-frontend · high confidence
SARIF output now includes meta-dimension findings, commit provenance, and dependency details
The SARIF report renderer now includes findings from meta-dimensions (previously omitted, causing a mismatch with fingerprints.json) by treating them as rules. For history-anchored findings, the renderer now emits the specific commit SHA in the result's property bag to ensure file locations remain valid against the correct code version. Additionally, dependency-related findings now include package, version, advisory, and reachability data in their properties, and per-finding CWE tags are attached to results for better taxonomy alignment.
engine/src/CodeHealth.Reporting/Sarif · high confidence
Scoring engine overhaul: new id types, absence policies, and aggregate calculation
The scoring engine has been refactored to introduce strongly-typed identifiers (CategoryId, DimensionId, RunId) and a new epistemic framework for interpreting results. A new AbsencePolicy class replaces the previous boolean logic, explicitly distinguishing between 'CleanScan' dimensions (where zero findings is a positive result) and 'EvidenceRequired' dimensions (where zero findings means 'NotEvidenced' rather than a perfect score). It also introduces 'Reward-Leaning' dimensions where absence is neutral rather than a deduction. The AggregateScoreCalculator now computes category scores using only deterministic dimensions, excludes LLM-assisted dimensions from the score (marking them advisory), and calculates aggregate confidence based on the entire dimension battery to prevent confidence regression when new dimensions start scoring. Additionally, new metrics like ArchitectureDepth and AssuranceDepth provide transparency into survey coverage and enforcement rigor without affecting the final CAI score.
engine/src/CodeHealth.Core/Scoring · high confidence
Security scanner D29 advice and rechecks now enforce performable, ecosystem-aware remediation
The D29 security dimension now applies several precision filters and advice rewrites to ensure findings are actionable and accurate. CloudFront findings using the default certificate now receive corrected advice, as the original minimum-protocol fix was unperformable without a custom certificate. Advice for frameworks absent from the scanned repository is stripped and replaced with ecosystem-neutral guidance, preventing misleading instructions. Several JavaScript rechecks (dead field round-trips, redundant re-defaulting, regex capture group arity, and sibling scope reads) now drop false positives by analyzing the actual code context. Additionally, C\# findings inside inactive preprocessor regions (e.g., \#if false or untargeted framework symbols) are dropped, and Go generic decode findings now include precise advice on input validation where concrete struct decoding is not possible.
engine/src/Scanner/Security/D29/Scanners · high confidence
Solution discovery now excludes third-party, generated, and test fixtures while loading all live solutions into a single workspace
The engine's solution discovery logic has been refined to prevent misidentification of product code: it now explicitly filters out solutions located in third-party trees (such as node\_modules), generated/vendored directories, and test/fixture paths, ensuring that only genuine product solutions are analyzed. Additionally, when multiple disjoint solutions exist within a repository, the engine now loads them all into a single workspace rather than selecting only the largest or first-found one, providing a more complete analysis of the entire codebase.
engine/src/Core/Discovery · high confidence
Static analysis (D29) now uses pinned, pre-baked semgrep rulesets and declares supported languages
The D29 static analysis dimension no longer fetches semgrep rulesets at scan time; instead, it uses pinned, pre-baked packs (p/security-audit, p/owasp-top-ten, and the engine-owned p/watchdog-sast when baked), making scans deterministic and offline-capable. A new AssemblyDimensions file explicitly declares the languages D29 handles (CSharp, Dart, Elixir, Erlang, FSharp, Go, Java, Kotlin, Php, Python, Ruby, Rust, Scala, Swift, Ts, Vb), and a binding test ensures this list matches the ruleset. The analyzer also degrades cleanly when semgrep is absent or when rules fail to load, and it merges recovered findings from a primary-constructor shadow pass and engine-authored Ruby rows into the main findings pipeline.
engine/src/Scanner/Security/D29 · high confidence
Supply-chain provenance dimension (D36) now detects npm long-lived token usage and unguarded packaging scripts
The D36 supply-chain provenance analysis has been expanded to identify two new security risks: it now flags npm registry publishes that rely on long-lived repository secrets (NODE\_AUTH\_TOKEN, NPM\_TOKEN, etc.) instead of OIDC-based trusted publishing, and it detects POSIX shell packaging scripts that can silently ship mis-identified artifacts due to unguarded variable captures. Additionally, the dimension now reads packaging steps declared in package.json scripts, ensuring that release automation defined in manifests is included in the provenance assessment.
engine/src/Scanner/SecurityPosture · high confidence
Synthesis engine now generates cross-signal conclusions and invariant narratives
The SynthesisEngine component has been introduced to transform raw measurement data into grounded, deterministic conclusions (such as compound hotspot risks, trajectory trends, and root-cause clusters) rather than just listing individual findings. This change ensures that the Diagnosis section of the report is formatted invariantly, removing dependency on the analyzer host's locale for consistent user-facing narratives. Users will now see synthesized insights that combine multiple signals to highlight specific risks like fragile change-hotspots or declining quality trends, with each conclusion citing the underlying evidence.
engine/src/CodeHealth.Reporting/Synthesis · high confidence
TS/JS sidecar now accurately measures call sites, state writes, and catch-fallback defaults
The TypeScript/JavaScript sidecar has been refactored to provide precise behavioral metrics for code analysis. It now correctly captures function call sites (including owner resolution and async context) instead of emitting empty arrays, accurately tracks instance state writes (including constructor parameter properties and symbol-keyed fields) to support cohesion metrics like LCOM4, and measures silent fallback defaults in catch blocks. These changes fix structural blindness in navigability and cohesion measurements and ensure that test files, e2e harnesses, and emitted/bundled output are correctly excluded from the production model.
engine/sidecars/tsjs-frontend · high confidence
Unified dependency vulnerability scanning across ecosystems
The engine now consolidates dependency vulnerability scanning (D30) and malicious package detection (D43) into a single shared collection pass, eliminating redundant scans and double-counting of CVEs across NuGet, npm, and OSV ecosystems. This change introduces a unified arm-based architecture where findings from different scanners are deduplicated and scored once, ensuring that partial scan failures do not incorrectly degrade the overall security score or hide valid findings.
engine/src/Scanner/Security/Shared · high confidence
Unified dependency vulnerability scoring and malicious package detection
The engine now consolidates dependency vulnerability analysis into a single D30 dimension that aggregates findings from all supported ecosystems (including NuGet, npm, Go, Python, Erlang, and Scala) and scores them once, rather than splitting results across multiple dimension IDs. Malicious dependencies are now detected and scored separately in a new D43 dimension with a binary severity model, ensuring hostile packages are not diluted by standard vulnerability scores. Additionally, dependency reachability is annotated post-scan to distinguish between directly used and transitive-only dependencies, providing more accurate risk context for users.
engine/src/Scanner/Security/D30 · high confidence
Unified source masking for Python, PHP, and Ruby
The engine now uses a shared \ScriptSourceMask\ component to blank comments and string literals in Python, PHP, and Ruby source files while preserving line offsets for accurate reporting. This replaces previous language-specific masking logic, ensuring consistent handling of comments (such as \\#\ in Python/Ruby and \//\ in PHP) and strings (including triple-quoted strings in Python and heredocs in PHP/Ruby). A specific fix for PHP ensures that only code between \\<?php\ and \?\>\ tags is processed, preventing apostrophes in surrounding HTML markup from incorrectly opening strings that would leave code comments unmasked.
engine/src/Core/ScriptLexing · high confidence
Version-controlled image reaper with automated self-tests
The image reaper for the codehealth-analyzer is now version-controlled and includes a self-test suite. The reaper script prunes stale tags from the local Docker store and the :5005 registry while protecting pinned images, rubric tags, and the newest preprod tags. A new self-test script validates the keep-set logic by simulating the reaper's behavior against mocked Docker and registry calls, ensuring that pinned images survive and stale ones are deleted.
deploy/engine-runtime/image-reaper · high confidence
Watchdog app scaffolding and hardened dev-provider stub
The Watchdog application host is initialized with a full module composition (including Billing, Onboarding, Scans, and Reporting) and a static SSR UI chassis. A critical safety fix is applied to the development-only provider picker stub: the replacement of the real GitHub client with canned demo data is now strictly gated by the absence of a Postgres connection string, preventing the accidental exposure of fake repository data on production hosts that might otherwise inherit the environment variable. Additionally, the app enforces invariant number formatting to resolve locale-specific parsing errors in settings fields and enables static web assets in all environments to ensure the UI renders correctly outside of local development.
src/Kennel.Watchdog.App · high confidence
X22 now analyzes Java handoffs and correctly marks Erlang/Elixir as not applicable
The X22 (Contradicted release guard) defect check has been expanded to read Java source files from disk, allowing Java repositories to be measured for handoff contradictions rather than being skipped. Additionally, the analyzer now explicitly identifies Erlang and Elixir as languages where this specific contradiction cannot be written, marking those repositories as 'not applicable' instead of reporting a reach gap.
engine/src/Scanner/Defects/X22 · high confidence
X32 analyzer now correctly excludes non-.NET repositories
The X32 defect detector (Type resolved by simple name) has been refactored into its own standalone project. A key behavioral change is that repositories without .NET source code are now explicitly marked as 'not applicable' rather than being treated as a language-reach gap. This prevents false demands from Java, TypeScript, or other non-.NET projects while maintaining the same detection logic for .NET codebases.
engine/src/Scanner/Defects/X32 · high confidence
d29-screen tool now validates corpus paths and attributes findings to rules
The d29-screen tool has been updated to require a corpus directory, ensuring that file paths in reports can be resolved on disk; it now fails fast if the corpus is missing or if specific files cannot be located, rather than silently dropping them. Additionally, the tool verifies that published findings match known rule IDs from the sweep reports, counting any unattributed findings separately to prevent misattribution in precision samples.
engine/tools/d29-screen · high confidence
Fixes
Added compiler-verified null filtering for string sequences
Introduced a new \NullableStringSequences\ utility in the CodeHealth.Core.Text namespace that provides \NotBlank\ and \NotEmpty\ extension methods for filtering nullable string collections. This change replaces manual null-forgiving operators (\!\) with iterator-based logic that leverages the \\[NotNullWhen(false)\]\ attribute on \string.IsNullOrWhiteSpace\ and \string.IsNullOrEmpty\, allowing the compiler to automatically verify that returned strings are non-null. This eliminates the need for manual null assertions, ensuring that any future breaking changes to the null-checking logic will cause a build failure rather than a runtime null reference exception.
engine/src/CodeHealth.Core/Text · high confidence
Centralized authored-source gate for D1, D2, and D3 dimensions
The \AuthoredSourceGate\ class has been introduced in the core engine to serve as the single decision point for D1, D2, and D3 dimensions regarding what constitutes maintainer-authored production source code. This change resolves a cross-dimension dependency error (CS0103) that occurred when splitting the codebase, by extracting the gate logic from \ComplexityScoring\ into a shared core component. The gate now explicitly handles language-specific source identification (C\#/VB via Roslyn) and correctly filters non-authored sidecar paths, including a fix for Storybook stories (e.g., \stories.tsx\) that were previously misclassified as authored complexity in non-.NET repositories.
engine/src/Core/AuthoredSource · high confidence
D15 Hotspot Analyzer: Polyglot Support, Exemptions, and Scoring Fixes
The D15 (Churn × Complexity Hotspots) dimension has been refactored to correctly analyze non-C\# languages by unconditionally passing the neutral code model to the complexity calculator, ensuring that languages like VB.NET and JavaScript are no longer ignored. It now incorporates supplementary code models to detect complexity in secondary languages within polyglot repositories. The analyzer also introduces robust exemptions for generated code (via banners and policies), literal resource catalogs, and analysis fixtures to prevent false positives. Additionally, the scoring logic now applies a complexity floor so that files refactored to be simple are removed from the hotspot list, and it correctly distinguishes between file creation and repair commits.
engine/src/Scanner/GitMining/D15 · high confidence
Documented exit codes and strict CLI parsing replace undocumented failures
The CodeHealth CLI now uses explicit, documented exit codes (D-062) to distinguish between specific failure modes—such as analyzer crashes (3), configuration errors (4), timeouts (7), scratch-ceiling exhaustion (8), and empty targets (9)—instead of previously returning undocumented codes like 255 or 2. A new exception handler maps unhandled exceptions to these specific codes, ensuring that operators can reliably distinguish between a tool fault, a user misconfiguration, and a budget stop. Additionally, the CLI now enforces strict parsing, failing immediately if an unrecognized option is provided, which prevents silent misconfigurations where typos in flags (e.g., --securityonly) would otherwise result in a full, incorrect analysis.
engine/src/CodeHealth.Cli · high confidence
Erlang sidecar now emits method bodies and call censuses
The Erlang frontend sidecar now includes \body\ records for every method and \calls\ records for every function, enabling accurate D1/D2 complexity scoring and D27 call-census analysis. Previously, these records were null or missing, causing the engine to abstain from scoring Erlang code entirely. The sidecar also fixes several parsing and classification issues: it correctly handles OTP umbrella projects and stops deleting production \\*\_test.erl\ modules, resolves guard alternatives without over-counting complexity, and properly identifies test-only exports using the X31 logic. Additionally, it fixes a crash caused by em-dashes in \.app.src\ files and prevents duplicate parsing of source files reached via directory symlinks.
engine/sidecars/erlang-frontend · high confidence
Exclude semgrep rule test targets from production code analysis
The engine now correctly excludes static-analysis rule test targets (files containing semgrep annotations like \// ruleid:\) from the production code population. Previously, these test specimens were scored as product code, leading to false positives (e.g., anemic entity warnings on test fixtures). The new \RuleTestTargetFile\ class identifies these files by parsing their comment lines, and \SymbolHelpers.ProductionTypesOutsideFixtureCorporaAsync\ filters them out alongside other fixture types, ensuring only actual product code is analyzed.
engine/src/Core/Symbols · high confidence
Exclude vendored third-party libraries from knowledge census
The engine now filters out copied third-party libraries from the knowledge census (D16 Bus Factor, D34 Knowledge Freshness) by detecting their presence via language-specific manifests. For C\# and PHP, files are excluded if they declare namespaces that do not match the project's declared identity (from .csproj or composer.json) and meet a minimum file count threshold. For Python, files are excluded if they reside in a nested package declaring a different literal version than the enclosing project package. This prevents vendored dependencies from being incorrectly counted as orphaned or single-author code.
engine/src/Scanner/GitMining/GitMining.Shared · high confidence
Expanded Erlang selftest fixtures for code analysis accuracy
Added a comprehensive suite of Erlang source files to the sidecar's selftest fixtures to validate and correct the engine's analysis of cyclomatic complexity, call census, and test-surface detection. These fixtures cover specific edge cases including macro-expanded complexity, guard alternative scoring, literal-named function calls (true/false/null), and the distinction between test-only and production modules, ensuring the sidecar correctly models Erlang code without false positives or regressions.
engine/sidecars/erlang-frontend/selftest/fixtures · high confidence
F\# code analysis now supports multi-project solutions and Paket restore
The F\# code model provider has been updated to scan and analyze all .fsproj files within a target directory, rather than processing only a single project. This ensures that large F\# solutions with multiple projects are fully analyzed instead of being under-analyzed. Additionally, the provider now handles Paket-based repositories by using the managed \dotnet paket restore\ command, avoiding failures caused by missing Mono dependencies, while maintaining best-effort behavior so that restore or analysis failures do not crash the overall scan.
engine/src/CodeHealth.CodeModel.FSharpCrack · high confidence
Fix build failures in Swift and Dart sidecars caused by gitignore conflicts
Added specific .gitignore and build scripts for the Swift and Dart sidecars to resolve source code dropping and build errors. The previous global gitignore rules incorrectly ignored the sidecar source directories (bin/ for Dart, Sources/ for Swift) and built binaries, causing the Docker build stages to fail with 'file not found' errors. The new .gitignore files explicitly un-ignore the necessary source paths and anchor the built binary names to prevent accidental exclusion, ensuring the sidecars can be compiled and tracked correctly in version control.
engine/sidecars/dart-frontend, engine/sidecars/swift-frontend · high confidence
Fix read-only diagnostics role visibility for newly created tables
The read-only diagnostics role (kennel\_ro) is now correctly provisioned to see all tables, including those created by application migrations. A previous implementation of the setup script used \ALTER DEFAULT PRIVILEGES\ without specifying a \FOR ROLE\, which meant it only applied to tables created by the \postgres\ superuser, leaving tables created by the application's migration user invisible to the diagnostics role. The updated script dynamically discovers all table-owning roles and applies default privileges for each, ensuring the diagnostics role has immediate read access to any new tables. Additionally, a new reporting script has been added to detect and list any tables the read-only role cannot access, helping to prevent future permission gaps.
deploy/postgres · high confidence
Fixes MSBuild restore and build failures on Linux for Windows-targeting and legacy .NET Framework projects
The analyzer now successfully restores and compiles repositories that previously failed on Linux due to environment-specific build constraints. It neutralizes strict CI policies (TreatWarningsAsErrors, NuGetAudit) and enables Windows TFMs on Linux hosts (EnableWindowsTargeting) to prevent restore failures. It resolves case-sensitivity issues by locating central package management manifests with incorrect casing and normalizing ResX file references with backslashes or wrong casing. It also relaxes strict SDK pins in global.json to match installed versions and lends the System.Resources.Extensions assembly to handle legacy BinaryFormatter resources in .resx files, ensuring the compiler-dependent analysis dimensions are measured instead of returning zero.
engine/src/CodeHealth.Toolchain/MsBuild · high confidence
Fixes complexity measurement for non-.NET languages and JavaScript hotspots
The engine now correctly measures complexity for non-.NET languages (such as F\# and Ruby) by properly vouching for files read by neutral code models, preventing false 'unread' abstentions. It also fixes JavaScript complexity scoring to include nested functions in their enclosing body's score and correctly handle module wrappers, ensuring accurate hotspot detection for first-party JS code.
engine/src/Core/Complexity · high confidence
Fixes false-positive language presence and dead sidecar reports across multiple languages
The engine now aligns language presence probes with the actual file-walking logic of each sidecar, preventing test-only or build-output files from triggering false reads. Specifically, the Kotlin, PHP, Scala, and Elixir presence probes now prune the same directories that their respective sidecars prune, so test fixtures or build logic (like sbt) no longer register as unread source. The TypeScript/JavaScript routing and launch probes now consult git-tracked paths to ignore files written during package restores, and the frontend walk-up is constrained to the initial checkout directory. These changes ensure that CI-only files, undeclared test fixtures, and transient build artifacts do not cause the engine to report a language as present but unread or to launch a dead sidecar.
engine/src/CodeHealth.CodeModel.Sidecars · high confidence
Fixes to deployment scripts and documentation for blue-green and credential security
This change introduces several critical fixes to the deployment infrastructure on canine-wrx1. It corrects the \advance-engine-pin.sh\ script to update the engine image pin in all relevant environment files (not just the worker's), preventing stale engine versions from being silently used. It adds a new guard script, \assert-preprod-touches-no-prod.sh\, to prevent preprod pipelines from accidentally modifying production configuration or databases. The \compute-version.sh\ script is fixed to use a full git clone for accurate build numbering, avoiding incorrect version stamps from shallow clones. Additionally, the \dotnet-stale-runtime.sh\ hook is updated to correctly exclude blue-green worker template instances from automatic restarts, and documentation files (\DEPLOY.md\, \DISASTER-RECOVERY.md\) are updated to reflect the current state of the blue-green deployment, credential key custody, and backup procedures.
deploy · high confidence
Go domain analysis now distinguishes contract adapters and demo code from genuine anemic aggregates
The engine now provides specific, actionable context for Go types flagged as anemic (DM4). It identifies types that serve as contract adapters (implementing an interface where all methods are queries) and types located in demonstration trees, explaining why business logic cannot or should not be moved onto them. This prevents misleading recommendations for interface implementations and example code, while preserving the original finding for genuine anemic aggregates.
engine/src/Core/Languages/Go/Domain · high confidence
Improved accuracy of defect-density and churn signals by filtering non-behavioral commits and anchoring history windows
The engine now provides more reliable defect-density and churn metrics by excluding commits that do not represent actual code repairs or by using unstable time windows. CommitClassifier now ignores commits that only fix prose (typos, spelling, comments), static-analysis reports (lint warnings, findings), or tool-run commands (e.g., go fix, eslint --fix), ensuring that only genuine behavioral fixes contribute to hotspot risk scores. Additionally, the churn window is now anchored to the analyzed commit's committer date rather than the current clock time, making churn counts reproducible and preventing silent drops in reported activity when scans are delayed. Shallow-history detection also distinguishes between truncated clones and repositories with genuinely few commits, providing accurate guidance on whether history can be fetched to improve signal reliability.
engine/src/Core/Git · high confidence
Improved classification of Elixir/Erlang documentation, HTML inline scripts, and generated code
The classification engine now more accurately distinguishes product code from documentation and generated artifacts. It correctly excludes Elixir and Erlang triple-quoted documentation attributes (e.g., \@moduledoc """\ and \-moduledoc\) from line counts, preventing false positives for file length. It also treats inline JavaScript within HTML pages as production code when appropriate, while excluding scripts in generated pages or minified bundles. Additionally, the system now better identifies machine-generated files by checking for specific headers and banners, ensuring that generated code is not counted towards product complexity or size metrics.
engine/src/Core/Classification · high confidence
Improved diagnostics for degraded and partial solution loads, plus stricter run-time budget enforcement
The engine now provides clearer, more accurate diagnostics when a C\# solution fails to load fully. For degraded runs (zero or near-zero projects loaded), a new report explains the cause by listing missing project references, showing the actual file tree structure, and detailing SDK resolution issues, including a specific check for an empty analyzed root. For partial loads, the project count headline now correctly counts .csproj files rather than TFM-expanded Roslyn projects, and explicitly reports how many loaded projects actually had their dependencies restored, preventing misleading success signals when restores failed. Additionally, a new budget backstop ensures that runs exceeding their time or scratch limits are forcibly stopped and explicitly name the stuck phase, preventing silent hangs that would otherwise be killed by the host.
engine/src/CodeHealth.Cli/Diagnostics · high confidence
Improved reliability and clarity in generated report prose
The reporting engine now ensures that discarded LLM responses are explicitly logged rather than silently falling back to deterministic text, providing visibility into when the AI-generated executive summary or findings narrative is replaced by a template. Additionally, leadership phrases in the report executive lede are now cleaned of internal file paths and redundant verb prefixes, presenting concise, path-free recommendations to users.
engine/src/CodeHealth.Reporting/Prose · high confidence
Isolation engine fixes for empty checkouts, symlink cycles, and scratch space exhaustion
The CodeHealth analysis engine's isolation layer now prevents several failure modes that previously caused incorrect results or system instability. It refuses to analyze an empty isolated checkout, throwing a specific exception instead of reporting a false 'clean' result. Symlink cycles in the source tree are now detected and broken (or unfolded for npm-installed links) to prevent ELOOP errors during file walks. Additionally, a per-scan scratch ceiling (default 48 GB) and a configurable scratch root (via CODEHEALTH\_SCRATCH\_ROOT) ensure that large builds cannot exhaust the shared temporary filesystem, which previously caused ENOSPC errors and masked build failures as repository defects.
engine/src/CodeHealth.Toolchain/Isolation · high confidence
LLM cache now respects --cache-dir and isolates rubric-sensitive results
The LLM caching layer now correctly applies the --cache-dir CLI option to control where cached responses are stored, fixing a previous issue where the option was parsed but ignored. Additionally, cache keys now include the rubric version for scoring requests to prevent stale answers from being reused when rubric definitions change, while content-classification requests remain rubric-independent to avoid redundant re-classification of unchanged items.
engine/src/CodeHealth.Llm.Abstractions/Caching · high confidence
Refined git history analysis for churn, identity, and coupling
The engine now uses a unified, streamed git log pass to power history dimensions, introducing three key improvements: ChurnCommitIdentity prevents double-counting by collapsing reverts and cherry-picks, excludes file creations from change counts, and treats pure renames as non-changes; CommitIdentityGraph resolves multiple author identities to a single human using transitive name/email matching (including GitHub noreply logins) to fix bus-factor inaccuracies; and GitDiffShapes distinguishes substantive code edits from directive-only changes (like //go:generate) to eliminate false co-change signals.
engine/src/CodeHealth.Toolchain/Git · high confidence
Report accessibility and brand assets overhaul
The report engine now uses a self-contained brand stylesheet and embedded SVG assets (Watchdog logo, Code Assurance Index mark) instead of external resources. To fix WCAG contrast failures on dimension cards, band text now uses CSS classes mapped from band labels rather than inline hex colors, and pill text automatically selects black or white ink based on the background color's luminance. The report also includes a fixed overlay drawer for chapter navigation and a server-rendered dependency matrix.
engine/src/CodeHealth.Reporting/Brand · high confidence
Roslyn workspace loading and symbol search reliability improvements
The Roslyn toolchain now loads all live solutions in a repository into a single shared workspace rather than loading them individually, ensuring that project references across multiple solution files resolve correctly. It also filters out advisory diagnostics—such as NuGet security warnings, pruning advice, and SourceLink remote URL issues—from load failure checks, preventing the dead-code detection pass from being silently skipped when a repository contains vulnerable or redundant dependencies. Additionally, the engine now removes unresolved analyzer references before symbol searches to prevent crashes caused by missing analyzer assemblies, ensuring accurate caller-count analysis for obsolete members.
engine/src/CodeHealth.Toolchain.Roslyn · high confidence
Rust sidecar introduces static musl binary build and corrects cfg-gated code analysis
The Rust sidecar now ships as a fully static, libc-free musl binary (codehealth-rust-sidecar) built via a new build.sh script, ensuring it runs without a Rust toolchain or libc at runtime. Analysis accuracy improves significantly: the sidecar now correctly parses and reports the full predicate of \#\[cfg(...)\] attributes, preventing mutually exclusive code arms from being incorrectly unioned into a single record. It also properly identifies test-only modules declared via \#\[cfg(test)\] mod foo;, excluding them from the product model, and correctly handles \#\[cfg(target\_os = ...)\] blocks by discounting alternative platform branches to avoid inflating complexity scores.
engine/sidecars/rust-frontend · high confidence
Scala sidecar introduces v10 NDJSON schema with full complexity, duplication, and cohesion data
The Scala sidecar now emits a schema-versioned (v10) NDJSON model that provides the structural and behavioral data previously missing for Scala repositories. This update enables the engine to correctly measure cyclomatic and cognitive complexity (D1/D2) by emitting detailed branch information for every method body, including specific handling for Scala idioms like \else if\ ladders and \for\ generators. It also activates clone-unit detection (D4) by emitting token streams and restores cohesion analysis (D6) by tracking method calls and member accesses. Additionally, the sidecar now correctly attributes types to their specific modules in multi-module repositories and reports source file census data to distinguish between scanned and empty files.
engine/sidecars/scala-frontend · high confidence
Source census now respects .gitignore and includes extensionless manifest-declared scripts
The source census engine now correctly excludes files that are ignored by the repository's .gitignore (even if git tracks them), preventing generated build artifacts from being counted as production source. It also discovers and counts extensionless executable scripts (such as Ruby or PHP entry points) that are declared in package manifests (gemspec, composer.json, package.json), ensuring these authored files are included in production line counts and complexity metrics.
engine/src/Core/SourceCensus · high confidence
Stable finding identities and unified dependency data in fingerprints.json
The engine now ensures that every finding in fingerprints.json has a unique, stable identity that survives routine code edits and prevents unrelated findings from colliding. Volatile measurements (like cyclomatic complexity counts) are stripped from identity keys unless they are the only distinguishing feature, and same-key siblings are disambiguated using occurrence ordinals or explicit discriminators. Additionally, fingerprints.json now includes a unified dependency wire shape (package, version, advisory, and reachability details) shared with SARIF and MCP outputs, ensuring machine readers see consistent dependency data. Legacy fingerprint keys are preserved in an array for rows that have re-keyed, allowing existing rulings to remain valid across schema changes.
engine/src/CodeHealth.Reporting/Fingerprints · high confidence
Stable scanning in the standalone edition image when the .NET SDK is missing
The standalone edition image no longer crashes when the .NET SDK is absent, which is expected since it does not include an SDK by design. A new EditionMode flag distinguishes the standalone edition from the hosted analyzer, allowing the tool to gracefully degrade to source-text analysis instead of failing with an exit code. This ensures that repositories can be scanned reliably in the standalone environment without requiring a full .NET SDK installation.
engine/src/CodeHealth.Toolchain · high confidence
Support for build-less C\# and VB.NET projects and improved .NET project classification
The engine now measures C\# and VB.NET source code in repositories that lack MSBuild project files (such as Unity projects using .asmdef files) by parsing them directly with Roslyn, ensuring these files are no longer reported as unread. Additionally, the classification of .NET projects has been refined to read Directory.Build.props files, allowing for more accurate detection of published packages and non-shipping test/benchmark harnesses, which prevents false positives in complexity and surface-area metrics.
engine/src/Core/Roslyn · high confidence
Swift sidecar now emits method bodies, call censuses, and cohesion touches
The Swift sidecar now generates the \body\ record for methods and top-level code, enabling D1 (Cyclomatic Complexity), D2 (Cognitive Complexity), and D4 (Clone Detection) metrics for Swift projects which previously abstained due to missing body data. It also emits a full call census (\calls\[\]\) distinguishing between in-repo, external, and unresolved calls to support D27 (Indirection), and provides touch surface data (\touches\[\]\) for D6 (LCOM4 Cohesion). Additionally, the sidecar now correctly identifies top-level functions in script-mode files as a synthetic facade member, ensuring their bodies are analyzed.
engine/sidecars/swift-frontend/Sources · high confidence
Test suite wiring and build-gate reliability for Go, Java, and Rust sidecars
This change introduces dedicated self-tests and parsing utilities to ensure that the Go, Java, and Rust sidecar unit suites are actually executed and that their results are validated against the declared test counts. Previously, these suites were built but never run (or were skipped by build flags), meaning broken tests could remain undetected. The new \go-test-count.sh\, \surefire-count.sh\, and \cargo-test-count.sh\ scripts parse the actual test output to verify that tests ran and to detect silent failures (e.g., \go test\ exiting 0 with no tests, or Maven skipping tests). Additionally, \jar-freshness.sh\ and its self-test ensure that sidecar JARs are rebuilt when sources change, preventing stale artifacts from being used in analysis. The \check-cohesion.py\ script consolidates cohesion self-tests for Swift and Dart into a single shared file to prevent divergence.
engine/sidecars · high confidence
Toolchain introduces precise process kill tracking and raw artifact storage
The toolchain now distinguishes between a tool that is missing, one that exited cleanly, and one that was killed, with the kill reason explicitly named as timed out, stalled (no output), or cancelled by an enclosing budget. This prevents empty output from being misinterpreted as a missing tool or a parsing failure, ensuring reports accurately reflect whether a dimension was skipped due to budget exhaustion or a genuine tool issue. Additionally, raw scanner output is now persisted as JSON artifacts for reproducibility and evidence.
engine/src/CodeHealth.Toolchain/Tools · high confidence
Unified dimension anchors and structured report view models
The reporting engine now uses a single canonical anchor format (e.g., D14 becomes d14) for all dimension and meta-dimension links, ensuring cross-references in the report always resolve correctly. Additionally, the report structure is rebuilt using explicit view models (such as LensReferenceRow and DimensionCard) that separate lens-based scoring from legacy category roll-ups, enforce gating rules (e.g., Critical findings capping bands), and clearly distinguish between unmeasured dimensions and checks that observed findings but carry no score.
engine/src/CodeHealth.Reporting/Templates · high confidence
Unified source-tree classification and path-scoping logic
This change consolidates and corrects how the engine identifies and excludes non-product code. It introduces a shared \RepoPathScope\ to standardize the exclusion of vendored dependencies (e.g., \node\_modules\, \Pods\, \paket-files\), build outputs, and documentation trees, ensuring consistent behavior across all quality signals. It adds \GeneratedFileFilter\ to reliably exclude machine-generated files (such as \.g.cs\, \.pb.go\, and EF Core migrations) based on naming conventions and headers, preventing false positives in duplication and complexity metrics. Additionally, it adds \CFamilySourceMask\ to correctly parse comments and strings in Rust, Swift, and Dart, and \GitRefStore\ to properly resolve Git tags in worktrees, fixing issues where tags were previously missed or source code was misclassified.
engine/src/Core/SourceTree · high confidence
Updated Go sidecar self-test golden output
The golden test fixture for the Go sidecar self-test has been updated to reflect the current analysis output. The new \golden.ndjson\ file contains 129 lines of structured data, including a header specifying schema version 9 and tool \codehealth-go-sidecar\, a source census of 15 files, and detailed type records for the \example.test/shop\ module. This update ensures the self-test expectations match the actual behavior of the sidecar.
engine/sidecars/go/selftest · high confidence
Test coverage
1458 commits adding/updating tests in tests; Accessibility analyzer tests: AC7 enforcement detection and advice precision; Add self-test fixtures for cache, storage, and dependency modules; Added CodeHealth test fixtures for sample solutions; Added CodeHealth test fixtures for static analysis validation; Added D9 test distribution analysis and registration; Added Dart cohesion snapshot fixture for JVM tests; Added Dart fixture classes for LCOM4 cohesion analysis edge cases; Added F\# provider test coverage for body trees, namespaces, and clone normalization; Added JVM-side regression and guard tests for multi-language engine fixes; Added Kotlin fixture classes to test cohesion analysis edge cases; Added PHP fixture classes for LCOM4 cohesion analysis; Added Rust synthetic defect fixtures for self-test validation; Added Swift cohesion test fixtures to validate LCOM4 analysis; Added X7 sidecar fallback behavior fixtures; Added env-gated integration tests for the changelog pipeline; Added guard tests to prevent regression of engine gap and census defects; Added integration tests for LA5/LA6 model-aware analysis; Added lockguard test fixtures to demonstrate Go concurrency patterns; Added regression and guard tests for ModelAware analysis correctness; Added self-test fixtures for Dart value-object and typed-id patterns; Added selftest fixtures for Python accessor and method-count regression; Added selftest fixtures for TypeScript/JavaScript analysis edge cases; Added test data for declaration block handling in declruns; Added test fixture for R10 superset relation edge case; Added test fixtures and measurement records for the ModelFacts language matrix; Added test fixtures for Dart sidecar analysis and code health conclusions; Added test fixtures for Playwright Android, BrowserType, and Electron dispatchers; Added test fixtures for React and Vue custom message rendering hooks; Added test fixtures for WASI build tag validation; Added test fixtures for ecosystem manifest detection; Added test fixtures for frontend workspace analysis; Added test fixtures for reversed-order Playwright Core WebKit page implementations; Added tests for the D10 Test Quality dimension and its polyglot coverage gate; Added tests verifying dimensions abstain when declared model facts are missing; Added unit test fixture for .NET 2.0 release metadata; Added unit test fixtures for MariaDB and MongoDB repository adapters; Added unit tests for Architecture dimension analysis and remediation advice; Added unit tests for CFamilySourceMask string parsing and GeneratedCodeAttribute detection; Added unit tests for CLI analysis commands and engine behaviors; Added unit tests for CodeHealth configuration and LLM routing; Added unit tests for CodeHealth coupling and abstractness scoring; Added unit tests for CodeHealth denoising and multi-TFM deduplication; Added unit tests for CodeHealth engine components; Added unit tests for CodeHealth history, sidecar, and regression logic; Added unit tests for CodeHealth report linting rules; Added unit tests for CodeHealth statistics engine edge cases; Added unit tests for CodeQuality dimension analysis logic; Added unit tests for DDD domain model style classification and library shape detection; Added unit tests for Explicit Debt analysis rules and scoring; Added unit tests for Explicit Debt detection edge cases; Added unit tests for GitMining dimensions (D15, D16, D34, D35); Added unit tests for Gradle source set detection and machine author identification; Added unit tests for LLM JSON response validation; Added unit tests for Maturity analyzer precision fixes; Added unit tests for MsBuild toolchain components; Added unit tests for PII identity resolution and anonymization; Added unit tests for code classification and repo-kind detection; Added unit tests for dependency hygiene readers across multiple ecosystems; Added unit tests for deployment topology extractors and scanner; Added unit tests for dimension analysis integrity and path normalization; Added unit tests for file-quality changelog, compose, generated-code, and scoring logic; Added unit tests for fingerprint stability, reporting consistency, and rubric catalog integrity; Added unit tests for frontend analysis rules and heuristics; Added unit tests for markup parsing line-number accuracy and HTML string reconstruction; Added unit tests for public-API surface detection across multiple ecosystems; Added unit tests for scoring engine census and policy logic; Added unit tests for solution discovery, frontend analysis, and architecture mapping; Added unit tests for the API surface extractor; Added unit tests for the CodeHealth synthesis engine and conclusion golden snapshots; Added unit tests for the DeterministicNamingSampler and NamingSampleAnnotation logic; Added unit tests for the Distillation engine's core logic; Added unit tests for the Edition image's filtering, gating, and reporting logic; Added unit tests for the LLM proxy admission and queueing logic; Added unit tests for the Runtime Accessibility analysis engine; Added unit tests for the neutral code model and Roslyn providers; Dart sidecar self-test validates v19 body records and call census; End-to-end browser test for cross-system delivery visibility; Expanded unit tests for compliance dimensions in JavaScript/TypeScript and .NET; Go sidecar test fixtures for legacy, single-module, and workspace scenarios; Integration test harness and fixture coverage for CodeHealth dimensions; Integration test suite for the CodeHealth analysis engine; Integration tests verify language-neutral code model equivalence and polyglot architecture mapping; Java fixture adds cohesion test cases for nested classes, inheritance, and overload delegation; Java sidecar self-test infrastructure added; Kotlin sidecar self-tests expanded with new regression gates; PHP sidecar self-test gate for branch-walk and analysis correctness; Readiness engine test suite expanded with 166 new unit tests; Regression test fixtures added for Semgrep rules; Ruby sidecar self-test validates DSL folding, mixin handling, and member identity; Rust sidecar regression test fixtures for analysis engine fixes; Scala sidecar self-test suite added; Security test suite expansion for supply chain and secret scanning accuracy; Swift sidecar self-test suite for v19 body and v20 test-census contracts; Test coverage for Express cookie-session rules and Go advisory reachability data; Test doubles added for unit testing; Testing dimension: added unit tests for coverage and reliability analyzer fixes; Tests for Architectural Integrity (D7) ADR enforcement and coverage logic; TypeScript/JS sidecar selftest: accessor fixture and golden output; Unit tests added for C\# complexity analysis and remediation advice; Unit tests added for CodeHealth duplication and IL analysis gates; Unit tests added for CodeShape analysis logic; Unit tests added for test-quality detection edge cases; Unit tests added for the OpenAI-compatible LLM client and provider; Unit tests for ADR inventory builder and parsing logic; Unit tests for CodeHealth diagnostics and budgeting logic; Unit tests for CodeHealth orchestration engine behaviors; Unit tests for Git history analysis and identity resolution; Unit tests for GitMining census accuracy and delivery signals; Unit tests for LLM engine reliability, attribution, and caching; Unit tests for build-less Roslyn analysis and source deduplication; Unit tests for finding-text quality rules and scoped absence reporting; Unit tests for the CodeHealth isolation engine's checkout and safety logic; Unit tests for the Runtime Boot engine's Android, API surface, and boot mechanism detection; Unit tests for the deterministic ChangeSet fusion engine; Unit tests for the new changelog drafting, rendering, and narration engine; Unit tests for toolchain reliability and workspace loading.
Dependencies
Centralized dependency management and security-hardened toolchain provisioning
The .NET project now uses central package version management (Directory.Packages.props) to pin core libraries including EF Core 10.0.8, Npgsql 10.0.3, and the CAI scoring/delivery packages (0.2.0-ws-i). The analyzer render harness updates axe-core to 4.10.2 and Playwright to 1.55.1. The Go sidecar raises its minimum toolchain to 1.26.6 to address multiple stdlib advisories, and the Java sidecar pins transitive dependencies (Jackson, plexus-utils, commons-lang3) to patched versions to close known CVEs.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 82 → 82 (-0.1)
Lenses
- Code Health 87 → 87 (+0.0)
- Architecture 97 → 97 (+0.0)
- Maturity 90 → 88 (-1.8)
- Readiness 76 → 76 (-0.1)
- Security 97 → 97 (+0.0)
- Domain Modelling 97 → 97 (+0.0)
- Event-Driven 88 → 88 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 100 → 100 (+0.0)
- Performance 84 → 84 (+0.0)
Resolved (503)
- AdmissionController.Decide (cognitive 17) (src/Kennel.Watchdog.Core/Scheduling/Admission/AdmissionController.cs)
- AnalyzeCommand.ExecuteCoreAsync (cognitive 17) (engine/src/CodeHealth.Cli/Commands/AnalyzeCommand.cs)
- AnalyzeCommand.GatherRuntimeEvidenceAsync (cognitive 19) (engine/src/CodeHealth.Cli/Commands/AnalyzeCommand.cs)
- ArchitectureDepth.From (cognitive 18) (engine/src/CodeHealth.Core/Scoring/ArchitectureDepth.cs)
- ArtifactViewer.FirstLocation (cognitive 18) (src/Kennel.Watchdog.Core/Reporting/Rendering/ArtifactViewer.cs)
- AssayReportBuildService.BuildForProductAsync (cognitive 17) (src/Kennel.Assay.Core/DecisionReports/AssayReportBuildService.cs)
- AssayReportOrderDispatcher.DrainAsync (cognitive 28) (src/Kennel.Assay.Core/DecisionReports/AssayReportOrderDispatcher.cs)
- BazelModuleGraph.Resolve (cognitive 20) (engine/src/Core/Manifests/BazelModuleGraph.cs)
- BazelModuleGraph.Tokens (cognitive 18) (engine/src/Core/Manifests/BazelModuleGraph.cs)
- BindingCommandHandler.EnsureScopeInTenantAsync (cognitive 17) (src/Kennel.Assay.Core/Governance/Application/BindingCommandHandler.cs)
- BoundedContextResolver.ContextOf (cognitive 18) (engine/src/Core/Architecture/BoundedContextResolver.cs)
- BoundedContextResolver.DeriveModulesAsync (cognitive 19) (engine/src/Core/Architecture/BoundedContextResolver.cs)
- BuildDefinition.Dependencies (cognitive 19) (engine/src/Core/Manifests/MillModuleGraph.cs)
- C4SvgRenderer.AssignLayers (cognitive 20) (src/Kennel.Watchdog.Core/Architecture/Model/C4SvgRenderer.cs)
- C4SvgRenderer.CrossHostRelationships (cognitive 16) (src/Kennel.Watchdog.Core/Architecture/Model/C4SvgRenderer.cs)
- C4SvgRenderer.Graph (cognitive 17) (src/Kennel.Watchdog.Core/Architecture/Model/C4SvgRenderer.cs)
- CSharpCloneTokenizer.CollectUnrolledSequenceSpans (cognitive 21) (engine/src/Core/Languages/CSharp/CSharpCloneTokenizer.cs)
- CSharpCloneTokenizer.IsInExecutableBody (cognitive 16) (engine/src/Core/Languages/CSharp/CSharpCloneTokenizer.cs)
- CapabilityGapRepairService.PlanAsync (cognitive 20) (src/Kennel.Admin.Core/Admin/Services/CapabilityGapRepairService.cs)
- CapabilityGapRepairService.RunAsync (cognitive 18) (src/Kennel.Admin.Core/Admin/Services/CapabilityGapRepairService.cs)
- …and 483 more
New (136)
- AddressClassifierAnalyzer.InspectAddressClassifier (cyclomatic 21) (engine/src/Scanner/Defects/X14/AddressClassifierAnalyzer.cs)
- AdrConformanceAnalyzer.AppendTypeDependenciesAsync (cognitive 16) (engine/src/Scanner/Docs/D25/AdrConformanceAnalyzer.cs)
- CaptiveDependenciesAnalyzer.HoldsNoState (cognitive 23) (engine/src/Scanner/ArchitectureModel/AX1/CaptiveDependenciesAnalyzer.cs)
- CaptiveDependenciesAnalyzer.HoldsNoState (cyclomatic 18) (engine/src/Scanner/ArchitectureModel/AX1/CaptiveDependenciesAnalyzer.cs)
- CleartextIngressScan.FindingsIn (cognitive 18) (engine/src/Scanner/Security/D31/Scanners/CleartextIngressScan.cs)
- DisasterRecoveryAnalyzer.WalkInertContent (cognitive 18) (engine/src/Scanner/Readiness/P5/DisasterRecoveryAnalyzer.cs)
- DocAccuracyAnalyzer.DocAccuracyAsync (cognitive 16) (engine/src/Scanner/Maturity/M4/DocAccuracyAnalyzer.cs)
- DocAccuracyAnalyzer.DocAccuracyAsync (cyclomatic 17) (engine/src/Scanner/Maturity/M4/DocAccuracyAnalyzer.cs)
- DocAccuracyAnalyzer.SeedRemovedModuleDrift (cognitive 18) (engine/src/Scanner/Maturity/M4/DocAccuracyAnalyzer.cs)
- DocAccuracyAnalyzer.SeedRemovedModuleDrift (cyclomatic 16) (engine/src/Scanner/Maturity/M4/DocAccuracyAnalyzer.cs)
- Duplicated block (10 lines × 2) (engine/src/Core/Dependencies/PubDevLicenseClient.cs)
- Duplicated block (10 lines × 2) (engine/src/Scanner/Defects/X13/ForeignUndrainedStreamScan.Dart.cs)
- Duplicated block (10 lines × 2) (engine/src/Scanner/Defects/X8/JsInteropContractAnalyzer.cs)
- Duplicated block (10 lines × 3) (engine/src/Core/Languages/Swift/Domain/SwiftDomainConventions.cs)
- Duplicated block (10 lines × 4) (engine/src/Scanner/Compliance/Compliance.Prework/ForeignComplianceScan.DartAuditTrail.cs)
- Duplicated block (11 lines × 2) (engine/src/CodeHealth.Reporting/Linting/FindingTextRules.cs)
- Duplicated block (11 lines × 2) (engine/src/Core/Languages/Scala/Testing/ScalaTestCensus.cs)
- Duplicated block (11 lines × 3) (engine/src/Scanner/Defects/X12/ForeignDeadBranchScan.Dart.cs)
- Duplicated block (11–14 lines × 3) (engine/src/Scanner/Defects/Defects.Prework/DataShapeScan.cs)
- Duplicated block (13 lines × 2) (engine/src/Scanner/Defects/X13/ForeignUndrainedStreamScan.Dart.cs)
- …and 116 more
Changes since last survey
- 283 commits — 234 feature/other, 49 fixes
By area
- engine/src — 164 commits
- tools/train — 38 commits
- src/Kennel.Core — 20 commits
- src/Kennel.Watchdog.Core — 18 commits
- engine/tests — 14 commits
- src/Kennel.Admin.Core — 10 commits
- src/Kennel.Assay.Core — 8 commits
- src/Kennel.Migration — 3 commits
- engine/sidecars — 2 commits
- .claude/commands — 1 commit
- engine/rubrics — 1 commit
- engine/tools — 1 commit
- src/Kennel.Hosting — 1 commit
- src/Kennel.Infrastructure — 1 commit
- tools/qwen-poc — 1 commit
Notable commits
- fix: chore(backlog/01a117ac-f7b8): journal — PlainBridge run-budget failure is the Aspire booted-tier stall fixed by f0d6a1c91 (25 min, 36/36 dims)
- fix: chore(backlog/01a117d0-ff27): journal — AX4 C# gap is the AX8 sibling fixed by 261197a20 (C#+Java lanes)
- fix: fix(AC4): a native <dialog> whose click acts only on its own ::backdrop is a dismiss backdrop (backlog 01a11637-6a5f-7079-beeb-1ba7e7398111)
- fix: fix(AC4): a wrapper's named click handler is compared with its control by what it calls — <article onClick={handleCardClick}> calling open() around <button onClick={open}> charged bench-ts-frontend-a11y ResultCard.tsx:24 (backlog 01a11637-89ac-7a4b-87ef-7c09476b1ce4)
- fix: fix(AC6): large-scale text is held to 3:1, not 4.5:1 — 36px bold white on #2f8f9d (3.8:1) charged bench-ts-frontend-a11y hero.css 'below the 4.5:1 WCAG AA minimum for normal text' (backlog 01a11637-a5c6-71cc-9bce-5ff79fe85158)
- fix: fix(AX1): a singleton capturing a stateless, non-disposable transient is not a captive dependency (backlog 01a11637-c503-7f1e-a833-8e1376f9e934)
- fix: fix(AX8): an unshipped assertion-only project under the tests tree is test code — bench-csharp-tests Fx.Conversion.TestSupport (backlog 01a11751-94e4-7bff-a8ba-3ab5d0d4a88b)
- fix: fix(C1): a postal code alone is not personal data — a persisted parcel postcode charged bench-csharp-readiness and bench-csharp-architecture C1 'No data-protection/encryption' (backlog 01a11637-ed43-793f-a2af-412b892fccf6)
- fix: fix(C3): a C# repo with no Entity Framework is not told to add an EF SaveChanges interceptor — the write-side hook is named without EF (backlog 01a11638-07c2-7562-b85d-3c75a8f8f4a8)
- fix: fix(C3): an event stream credits coverage only when the events name the acting user — a stream with no actor scored 9.0 on bench-csharp-domain-events, now 7.5 (backlog 01a11638-4282-7cb3-af8d-627574c4ec46)
- fix: fix(D10): a fixed sleep against real timers in a JS/TS test is reported — bench-ts-readiness FLK-002 (backlog 01a11755-ea2a-7ad8-b996-a6c77d48e949)
- fix: fix(D10): a test whose only wall-clock read races a second, independent one — bench-csharp-tests TQ-006 (DateTime.Today vs TimeProvider.System), bench-ts-readiness FLK-001 (toBe(Math.floor(Date.now() / 1000) + …)) (backlog 01a11755-c993-744e-b96f-f191a1c81532)
- fix: fix(D10): the JS sleep rule's patterns carry no wall-clock deadline (backlog 01a11755-ea2a-7ad8-b996-a6c77d48e949)
- fix: fix(D20): a project-less .NET tree with a root Program.cs Main is a program, not an unclassifiable repo — thangchung/clean-code-dotnet (backlog 01a11715-45f8-7652-9abd-b67647230ad7)
- fix: fix(D25): the conformance judge sees what each production type derives from and is handed — a ControllerBase controller against a no-controllers ADR, an endpoint handed the DbContext against an endpoints-call-handlers ADR (backlog 01a11755-7d60-7d5b-9936-b33c70373d3f)
- fix: fix(D25): the judge checks each constrained type's own dependency line — a conforming sibling never vouches for it; qwen flipped Conforms/Violates on DriverEndpoints until it did (backlog 01a11755-7d60-7d5b-9936-b33c70373d3f)
- fix: fix(D25): the judge is told to check every endpoint/controller/handler dependency line against the decision — one contradicting type is a violation, conforming siblings do not cancel it (backlog 01a11755-7d60-7d5b-9936-b33c70373d3f)
- fix: fix(D31): a Kubernetes Ingress with no tls: section and no edge-certificate annotation serves plain HTTP — WD-K8S-0006 (0005 is reserved for the WD-K8S-0004 collision fix, 01a022d3), bench-csharp-security-iac IAC-013 (backlog 01a11756-0623-7d81-a0c2-afd46d7717fc)
- fix: fix(D7): a checkable dependency rule declared enforcement: prose is recommended for a test or analyzer (backlog 01a11755-5360-7f01-8dcd-25fa733c9846)
- fix: fix(M4): a module the CHANGELOG lists as removed that the README still documents is drift without a model (backlog 01a11755-987d-7617-bd63-8e0c3d223564)
- …and 263 more
API surface
- Unchanged — 505 HTTP endpoints
Architecture
- Containers 0 added · 0 removed · contexts 1 added · 1 removed · edges 0 added · 0 removed
Added bounded contexts (1)
- gopath.local/.
Removed bounded contexts (1)
- gopath.local/.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
CanineCC/kennel.canine.dev was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 7 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3195cc88dd02ac93528bcf199cf364d2916c944e — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-bbd7b4f07d52.