Static analysis tool that catches 1000+ bug patterns across all popular programming languages, with auto-wiring into AI coding agent quality guardrails
This week focused on squashing false positives across JavaScript, Python, and verification logic. Key fixes addressed JavaScript operator matching leaking into comments and strings (GH-157), a quadratic backtracking issue in taint analysis (GH-156), suppression markers incorrectly spanning multiple…
Get this in your inbox every Monday →A deterministic 0–100 hygiene score — README, license, CI, tests, docs, and freshness.
Who ships this repo — author concentration and the bus factor across the last 300 mainline commits.
How welcoming this repo is to contributors — issue throughput, close time, responsiveness, and good-first-issue count.
What this project is built on — dependency count by ecosystem, the license mix, and anything worth a legal look before you adopt it.
Whether this project's CI can be trusted — pass rate, run times, flaky runs, and which workflow is the weak link.
Grounded in ultimate_bug_scanner's README, structure, and recent commits — answers won't invent code they haven't seen.
A Monday email with what shipped, in plain English — no account needed.
Showing raw commit titles for the newest commits. Sign in to generate AI summaries.
feat(cpp): track request bindings, helper effects and guarded sinks
fix(taint): bind Ruby numbered blocks and verify JVM path receivers
fix(ruby): follow mutable object aliases without conflating copied data
fix(jvm): retain basename flow through directory uses and filesystem APIs
fix(ruby): preserve sensitive API operands and literal splat order
fix(checksums): refresh the helper pins the JVM and Ruby taint changes left stale
fix(jvm): retain taint across unsafe path guards and Kotlin calls
A floor, not a guess: counts only commits whose author, co-author trailer, or message explicitly credits an AI tool (Claude, Copilot, Cursor, aider, Codex…). Based on 30 mainline commits. Unattributed AI code isn't counted here — the full audit estimates that separately.