- Vulnerable dependencies100
- Test coverage76
- Complexity82
- Duplication90
- Outdated dependencies54
From workflow file to trend line in three steps
No agent to host and no test runner to configure. DebtDraft reads your repo inside your own GitHub runner.
Add the workflow
Drop one file into your repo. It runs on every pull request.
- uses: mohmmddd00/debtdraft/action@main with: github-token: ${{ secrets.GITHUB_TOKEN }} api-key: ${{ secrets.DEBTDRAFT_API_KEY }}Open a pull request
A health score lands on the PR as a comment, then updates in place on every push.
Watch the trend
Every scan is saved to your dashboard, so you see whether a repo is getting healthier or slipping.
Five signals, plus a secrets check
Each one is computed on your runner from your own code, and each one points back to what caused it.
Vulnerable and malicious dependencies
Audits the full installed tree, direct and transitive, against public vulnerability databases. One known-malicious package caps the grade at F.
Hardcoded secrets
Stays on your runnerFlagged on the exact lines a PR adds. Reported on the PR only, kept out of the score, and never uploaded.
Cyclomatic complexity
Flags functions that have grown too tangled to change safely, so you can simplify them before they slow you down.
Test coverage gaps
Overall line coverage plus patch coverage for just the lines a PR changed. Reads the reports your tests already produce.
Code duplication
Finds copy-pasted blocks before they turn into three places to fix the same bug.
Outdated dependencies
Tracks packages a breaking release behind or deprecated, with libyears from real publish dates.
One number, weighted by risk
The signals that hurt most when they go wrong count most. A signal DebtDraft cannot measure is left out, never counted as a perfect score.
- A90+
- B80+
- C70+
- D60+
- Fbelow 60
- Vulnerable dependencies
- Test coverage
- Complexity
- Duplication
- Outdated dependencies
A known-malicious package anywhere in the dependency tree caps the grade at F, whatever the other signals say.
Every repo, every scan, over time
See the trend for each repo, then open any scan to find the exact functions, files and advisories behind its score.
| Pull request | Score | Change |
|---|---|---|
| Add retry backoff #141 | 92 | +3 |
| Upgrade express to v5 #139 | 89 | +5 |
| Extract invoice helpers #136 | 84 | -1 |
The most complex functions in this scan. Threshold 10.
- applyDiscounts18src/billing/discounts.ts:42
- reconcileInvoice14src/billing/reconcile.ts:110
- parseWebhook11src/webhooks/parse.ts:23
Built to keep your code where it is
The analysis runs inside your own GitHub runner, so the dashboard only ever sees the results.
Secrets stay on your runner
Hardcoded secrets are reported on the pull request and never uploaded. Their values are masked in the logs.
Your tests stay yours
DebtDraft reads the coverage reports your own test run already produced. It never runs your tests or your code.
Findings, not source
The dashboard gets scores plus a capped list of file paths and line ranges. No source snippets are sent.
Add it to your repo in minutes.
Sign in with GitHub, connect a repository, and your next pull request gets a health score.
Continue with GitHub