Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

CodeJourney

A comprehensive Rust CLI that audits any git repository for code quality, security, license compliance, and project health — producing rich terminal output and exportable reports in PDF, HTML, JSON, and Markdown.

Recording 2026-04-10 at 14 29 51

Why CodeJourney

As part of funding due diligence, companies are often asked to provide an overview of their intellectual property. Too often, that overview is assembled ad hoc and fails to reflect the true state of the codebase. CodeJourney delivers real, reproducible metrics on your code and other IP assets, giving investors an accurate and verifiable picture.

Installation

Install script (recommended)

curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh | sh

This detects your platform, downloads the matching binary from the latest GitHub release, verifies its checksum, and installs it to /usr/local/bin (falling back to ~/.local/bin when /usr/local/bin isn't writable).

Pin a version or change the install location with environment variables:

VERSION=v0.2.0 sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"
INSTALL_DIR=~/bin sh -c "$(curl -fsSL https://raw.githubusercontent.com/adaptive-scale/codejourney/master/install.sh)"

From source

cargo build --release

The binary will be at target/release/codejourney.

Features

Repository Analytics

  • Repository overview — total commits, branches, tags, first/last commit, active span
  • Commit velocity — yearly, daily, and weekly averages
  • Top contributors with bar charts
  • Lines added/removed per author
  • Monthly commit frequency with sparklines
  • Activity heatmaps by day of week and hour of day
  • Most frequently changed files and code churn analysis
  • Bug-fix hotspot files
  • Emergency commits (reverts, hotfixes, rollbacks)
  • Merge frequency by month
  • Largest tracked files
  • Stale files sorted by last modification

Security Audit

  • Secret and credential detection in source files (passwords, API keys, AWS keys, Base64 blobs)
  • Dangerous code patterns — SQL injection, command injection, disabled TLS, weak crypto, CORS wildcards
  • Sensitive files committed to the repository (.env, *.key, *.pem, keystores)
  • Hardcoded IP address detection
  • Commits mentioning secrets or credentials
  • Commits touching security-sensitive files (auth, session, crypto, permissions)
  • .gitignore coverage check for common sensitive patterns

License Compliance

  • Detects project license from manifest files (Cargo.toml, package.json, go.mod)
  • Reads LICENSE/COPYING files and identifies the actual license type by matching against known SPDX license text signatures
  • Supports MIT, Apache-2.0, GPL-2.0/3.0, AGPL-3.0, LGPL-2.1/3.0, BSD-2/3-Clause, MPL-2.0, EPL-1.0/2.0, Unlicense, CC0, BSL-1.0, Zlib, WTFPL, Artistic-2.0, CDDL, ISC, 0BSD
  • SPDX-License-Identifier header detection as fallback
  • Confidence scoring (high / medium / low)
  • Categorizes licenses as permissive, weak copyleft, or strong copyleft
  • Warns on copyleft conflicts and missing license declarations

Cyclomatic Complexity Analysis

  • Per-function complexity scoring across Rust, Go, TypeScript/JavaScript, Python, and Java
  • Configurable threshold with warnings for functions exceeding limits
  • Top N most complex functions report
  • Per-language file and function counts

SAST (Static Application Security Testing)

  • Taint analysis for SQL injection (string interpolation in queries)
  • Insecure deserialization (Python pickle, yaml.load, Java ObjectInputStream, PHP unserialize)
  • Path traversal detection
  • Unsafe eval(), exec(), Function constructor, dynamic imports
  • Rust unsafe blocks and raw pointer usage
  • JavaScript prototype pollution patterns
  • Go template injection
  • Shell command execution with user input
  • Findings grouped by severity (HIGH / MEDIUM / INFO)

SCA (Software Composition Analysis)

  • Parses lockfiles: Cargo.lock, package-lock.json, go.sum, requirements.txt
  • Full dependency listing per lockfile
  • Detection of unpinned or loose version constraints
  • Pre-release / 0.x version flagging for stability risk

Dependency Graph & Reachability

  • Builds an inter-package dependency graph across the repo
  • Exports as DOT format (convert to SVG with dot -Tsvg -o deps.svg deps.dot)
  • Detects circular dependencies and unused phantom dependencies

Fix Suggestions & Autofix

  • Generates remediation hints for SAST findings
  • Suggests version bumps for vulnerable dependencies
  • Refactoring proposals for high-complexity functions

Historical Tracking

  • Stores scan results in a local SQLite database
  • Trend charts for complexity, vulnerability count, and license drift over time

Report Generation

  • PDF — styled multi-page report with charts and tables
  • HTML — interactive report with Tailwind CSS, Chart.js bar charts, and collapsible sections
  • JSON — structured machine-readable output for CI/CD integration
  • Markdown — a summary table followed by every finding, with tables and charts preserved as Markdown tables

Usage

Repository Scan

codejourney scan # Full analytics + security + advanced analysis
codejourney scan --analytics-only # Analytics only
codejourney scan --security-only # Security audit only
codejourney scan --path /other/repo # Scan a different repository

Report Exports

codejourney scan --pdf report.pdf # Export to PDF
codejourney scan --html report.html # Export to interactive HTML
codejourney scan --json report.json # Export to JSON
codejourney scan --markdown report.md # Export all findings to Markdown
codejourney scan --dot deps.dot # Export dependency graph as DOT

You can combine multiple export flags in a single run:

codejourney scan --pdf report.pdf --html report.html --json report.json

Filtering

codejourney scan --ignore-dirs docs,examples,fixtures

Built-in skip directories (vendor/, node_modules/, target/, .git/, dist/, build/) are always excluded; --ignore-dirs adds to this list.

Historical Tracking

codejourney scan --history-db ./scans.db # Store this scan in SQLite history
codejourney scan --show-trends # Display trend charts from history

HTTP Server

codejourney serve --port 3000 # Start HTTP API server

All responses follow {"ok": true, "data": ...} / {"ok": false, "error": "..."}.

About

No description, website, or topics provided.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages