Know your pull request's health before you merge it.

DebtDraft is a GitHub Action that scans every pull request for complexity, test coverage, duplication, outdated and vulnerable dependencies, and hardcoded secrets. It posts one health score on the PR and tracks the trend for every repo.

  • Secrets never leave your runner
  • JavaScript and TypeScript today
Refactor billing retry logic #128
debtdraftcommentededited
Health scoreUpdated on every push. Example scan result.
  • Vulnerable dependencies100
  • Test coverage76
  • Complexity82
  • Duplication90
  • Outdated dependencies54
0 hardcoded secrets found
Complexitytangled code, caught early
Duplicationcopy-paste, found fast
Vulnerabilitiesrisky packages, flagged
Coverageuntested changes, exposed
How it works

From workflow file to trend line in three steps

No agent to host and no test runner to configure. DebtDraft reads your repo inside your own GitHub runner.

1

Add the workflow

Drop one file into your repo. It runs on every pull request.

.github/workflows/debtdraft.yml
- uses: mohmmddd00/debtdraft/action@main
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
api-key: ${{ secrets.DEBTDRAFT_API_KEY }}
2

Open a pull request

A health score lands on the PR as a comment, then updates in place on every push.

debtdraftedited
7886Bafter the new push
3

Watch the trend

Every scan is saved to your dashboard, so you see whether a repo is getting healthier or slipping.

Health, last 8 scans+20
Signals

Five signals, plus a secrets check

Each one is computed on your runner from your own code, and each one points back to what caused it.

Vulnerable and malicious dependencies

Audits the full installed tree, direct and transitive, against public vulnerability databases. One known-malicious package caps the grade at F.

Hardcoded secrets

Stays on your runner

Flagged on the exact lines a PR adds. Reported on the PR only, kept out of the score, and never uploaded.

Cyclomatic complexity

Flags functions that have grown too tangled to change safely, so you can simplify them before they slow you down.

Test coverage gaps

Overall line coverage plus patch coverage for just the lines a PR changed. Reads the reports your tests already produce.

Code duplication

Finds copy-pasted blocks before they turn into three places to fix the same bug.

Outdated dependencies

Tracks packages a breaking release behind or deprecated, with libyears from real publish dates.

The score

One number, weighted by risk

The signals that hurt most when they go wrong count most. A signal DebtDraft cannot measure is left out, never counted as a perfect score.

  • A90+
  • B80+
  • C70+
  • D60+
  • Fbelow 60
  • Vulnerable dependencies
  • Test coverage
  • Complexity
  • Duplication
  • Outdated dependencies

A known-malicious package anywhere in the dependency tree caps the grade at F, whatever the other signals say.

Dashboard

Every repo, every scan, over time

See the trend for each repo, then open any scan to find the exact functions, files and advisories behind its score.

acme/billing-serviceExample
Current healthLatest completed pull request scan+28 over 14 scans
708090
Pull requestScoreChange
Add retry backoff #14192+3
Upgrade express to v5 #13989+5
Extract invoice helpers #13684-1
Scan #141 / ComplexityExample
ComplexityCoverageDuplicationDependenciesVulnerabilities

The most complex functions in this scan. Threshold 10.

  • applyDiscounts18
    src/billing/discounts.ts:42
  • reconcileInvoice14
    src/billing/reconcile.ts:110
  • parseWebhook11
    src/webhooks/parse.ts:23
Privacy

Built to keep your code where it is

The analysis runs inside your own GitHub runner, so the dashboard only ever sees the results.

Secrets stay on your runner

Hardcoded secrets are reported on the pull request and never uploaded. Their values are masked in the logs.

Your tests stay yours

DebtDraft reads the coverage reports your own test run already produced. It never runs your tests or your code.

Findings, not source

The dashboard gets scores plus a capped list of file paths and line ranges. No source snippets are sent.

Add it to your repo in minutes.

Sign in with GitHub, connect a repository, and your next pull request gets a health score.

Continue with GitHub