Executive summary
Read through the Production lens — the standard calibration. *Green* means good enough to run in production. The score is absolute and comparable across repos.
XINCGer/Unity3DTraining carries serious gaps (47%). Several issues below can materially affect correctness, security, or the cost of changing it — and propagate to everything that depends on it.
It is strongest in Architecture (95%) — the structure is clean and changes stay contained.
The area that most needs attention is Readiness (35%) — releases are harder to depend on — versioning, release notes and dependency hygiene are thin, so consumers can't easily tell what changed or trust an upgrade. Security (47%) is the next concern — exposure to security and compliance incidents is elevated.
Leadership focus, highest impact first: CI workflow that builds and runs the test suite on every push/PR (CI/CD gates); Run what this repository's stack ships (Security & performance tooling); Keep a changelog (e.g. Keep-a-Changelog) recording what shipped… (Release Hygiene).
For scale: Small (~3,944 production lines); rebuilding it from scratch would take roughly ~0.8 person-years (~1–2 engineers). Approximate, ±~30%.
It builds on a genuinely strong Architecture foundation (95%); the priorities above are the highest-leverage way to bring the rest up to that level.
Raise Readiness 35 → 70 (the Healthy floor) ⇒ headline 47 → ~58.
New since the last scan (2+)
Rebuild cost & value ~ Modeled — €38,000–€190,000
| Cost to rebuild | €38,000–€190,000 |
| Domain complexity | Standard |
| Quality factor | 0.7× (at 47% quality) |
| Size & shape | Small · 34% boilerplate · 26% straight-line · 40% branching logic |
This codebase represents roughly ~0.8 person-years of build effort (about ~€110,000 to rebuild). Its weakest lens is Readiness at 35% — the part of that asset most exposed by the findings below.
Top priorities
Diagnosis — what's actually going on
Architecture — bounded-context dependency graph
Architecture — module dependency matrix
At a glance — Code Health
At a glance — Architecture
At a glance — Maturity
At a glance — Readiness
At a glance — Security
Security & Compliance — OWASP Top-10 mapping
| OWASP category | Findings | Severity |
|---|---|---|
| A02:2021 — Cryptographic Failures | 23 | High / Critical |
| A03:2021 — Injection | 2 | Medium |
| A04:2021 — Insecure Design | 2 | High / Critical |
Roadmap
First, establish a continuous integration pipeline that builds the code and runs the test suite on every push or pull request. Next, integrate a security analyzer, such as CodeQL or Semgrep, into this workflow to fail the build on security regressions. Additionally, maintain a changelog to track release history and address the identified secret scanning findings, starting with Client.cs and the specified asset files.
| Do this | Helps | Effort | Dimension |
|---|---|---|---|
| Resolve the 1 Leaked secret finding(s) in Secret Scanning — start with Client.cs. | +9.0 pts | Low | Secret Scanning |
| Add a CI workflow that builds and runs the test suite on every push/PR. | +12.8 pts | Medium | CI/CD gates |
| Run what this repository's stack ships: CodeQL's csharp pack (it analyses VB.NET too), or a security analyzer package — or `semgrep --config=auto`, which runs on any language — — locally for now, since there is no CI pipeline here yet, and as a step of the first workflow you add so a security regression fails the build instead of landing. | +12.8 pts | Medium | Security & performance tooling |
| Keep a changelog (e.g. Keep-a-Changelog) recording what shipped in each release. | +11.8 pts | Medium | Release Hygiene |
| Resolve the 2 High finding(s) in Data Compliance (PII/GDPR) — start with ToLuaExport.cs (2). | +4.2 pts | Low | Data Compliance (PII/GDPR) |
| Resolve the 21 Secret finding(s) in Secrets (history) — start with ProjectSettings.asset (15), Orc Skin (Diffuse).psd (2), 06 Character.psd (2). | +5.8 pts | Medium | Secrets (history) |
| Resolve the 1 NoWarnInCsproj repeated across 20 files finding(s) in Explicit Debt — start with Assembly-CSharp.csproj. | +2.2 pts | Low | Explicit Debt |
| Grow the ADR log (currently 1) — reach 8 to raise the maturity tier; document significant decisions as they're made. | +3.3 pts | Medium | Architecture documentation |
File quality
| File | Score | Band | Worst signal |
|---|---|---|---|
| Effective C#/Delegate_EventTraining/Assets/NGUI/Examples/Models/Orc/Orc Skin (Diffuse).psd | 5.8 | Mixed | Secrets (history): Secret: aws-access-token |
| UGUITraining/UGUIDemo02/Assets/UI/Source/06 Character.psd | 5.8 | Mixed | Secrets (history): Secret: aws-access-token |
| UGUITraining/UGUIDemo02/Assets/UI/Source/05 Window Frame.psd | 5.8 | Mixed | Secrets (history): Secret: aws-access-token |
| HotUpdate/uLuaDemo/Assets/ToLua/Editor/ToLuaExport.cs | 5.8 | Mixed | Data Compliance (PII/GDPR): High: watchdog-sensitive-personal-data-in-log |
| NetWorkAndResources/SampleSocket/Socket/Assets/Scripts/Client.cs | 7.2 | Mixed | Secret Scanning: Leaked secret: hardcoded-credential |
| SDK/XinGeSDK_Demo/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| SDK/PullUpQQGroupDemo/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| 2DPlatformer/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| UnityEditorExtension/MultiEditorWindow/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| MVP_Demo/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| UnityEditorExtension/NodeEditor/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| HotUpdate/AssetBundleFramework/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| ChangeCharacter/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| HotUpdate/UnityTechnologiesAssetbundleDemo/demo/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| HotUpdate/AssetBundleDemo/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| GuideSystem/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| SDK/XinGeSDK/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| HighScore/HighScore/Library/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| HighScore/HighScore/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
| UnityEditorExtension/NodeEditorCollection/NodeEditor/ProjectSettings/ProjectSettings.asset | 7.2 | Mixed | Secrets (history): Secret: generic-api-key |
Methodology & how to trust this report
Watchdog is a deep, periodic assessment — run each sprint, monthly, or quarterly, taking the time to go wider and deeper than a quick check and surfacing in one coherent report what you'd otherwise piece together from a dozen separate tools. It scores deterministically: the same commit yields the same score, every run. 33 of 36 evaluated dimensions are computed purely by tools and static analysis (confidence 1.0); 3 documentation/naming judgement(s) are LLM-assisted and labelled advisory. Overall confidence is 0.5 — the weighted average across measured dimensions; it falls as more of the score leans on LLM-assisted judgement and rises when it's fully tool-backed.
What we checked — 36 dimensions across the health lenses
- Can you open the finding? Real findings cite a repo-relative file and line you can open at the cited line — never an absolute scratch path. Here, 32 of 44 do; the remainder are repo-wide signals — a dimension-level measurement, not a single line.
- Is there a tool behind the number? Every score below names the method that produced it — Roslyn, git, a scanner, or (for a handful of documentation/naming dimensions) an LLM labelled sampled · advisory — not a narrative.
- Does re-running give the same result? Run it again on the same commit and the score — and this report, byte for byte — is identical. A report whose numbers move between runs is describing the run, not the code.
Tools & methods
| Method | Backs | Version | Evaluator |
|---|---|---|---|
| Roslyn static analysis | Complexity, cohesion, coupling, dead code, API surface, layering | 5.3.0 | ✓ deterministic |
| Native secret scanner | Hardcoded secrets / credentials | 1.0.0 | ✓ deterministic |
| jscpd | Code duplication | — | ✓ deterministic |
| Coverage (coverlet / dotnet-coverage) | Line & branch coverage | 10.0.302 | ✓ deterministic |
| NuGet / dotnet | Outdated, vulnerable & deprecated dependencies | 10.0.302 | ✓ deterministic |
| git / LibGit2Sharp | Churn hotspots, knowledge concentration, history | 2.43.0 · 0.31.0 | ✓ deterministic |
| gitleaks · semgrep · trivy | Secrets in history, SAST, CVEs, IaC & container, PII / GDPR | 1.86.0 · 0.69.3 | ✓ deterministic |
| LLM (sampled · advisory) | Documentation quality, ADR conformance, naming — sampled over a bounded sample; advisory, never a deterministic measurement | Local LLM | ◐ LLM · sampled · advisory |
Run transparency — what happened this run
- D19 Documentation Quality — LLM provider failed — The model provider returned an unusable result, so this LLM-assisted dimension fell back to a measurement gap (confidence 0) rather than a penalty. Re-run with a reachable provider to score it.
Limitations & what we did not check
Watchdog assesses the repository exactly as committed, and only the repository. By design it does not reach outside the source tree: the live cloud account, the running CI/CD pipeline, the host's branch-protection and approval rules, the production configuration, or a restore actually exercised against a backup are all out of scope. That boundary is a feature, not a gap — a repo-relative, deterministic scan re-runs identically on any commit and every finding opens at a real file and line, where a live audit can neither be reproduced nor traced. The visible consequence is that controls which leave no in-repo evidence are reported as "not evidenced" and excluded from the score rather than awarded a number a static scan cannot justify.
Per-dimension blind spots
- D4 Code Duplication: Duplication is token-similarity (jscpd) — it finds copy-paste, not semantic duplication expressed differently. Committed machine-written code (scaffolded migrations, designer/codegen output, protobuf/OpenAPI stubs, model snapshots) is EXCLUDED — its repetition is the tool's, not the team's — so the score reflects hand-written duplication only.
- D5 Coupling: Coupling is measured between projects/assemblies — runtime coupling through DI, reflection, messaging or shared databases is invisible to a static reference graph.
- D6 Cohesion (LCOM4): LCOM4 cohesion is syntactic — it infers connectivity from which methods touch which fields/methods by name, not from real runtime behaviour or intent.
- D7 Architectural Integrity: Layering is checked against detected/declared rules — an architecture whose boundaries live in convention or in code review, not in a rule a scanner can read, is not enforced here.
- D9 Test Distribution: The test-pyramid shape is inferred from project/folder naming and references, with a single test host bucketed per-file by its path tier and content signals — a suite that names tiers unconventionally and gives no per-file signal can still be mis-bucketed.
- D10 Test Quality: Assertion density is structural — it cannot tell a meaningful behavioural assertion from a trivial one, only that an assertion is present.
- D12 Dependency Hygiene: Dependency health reads manifests and lockfiles — a vulnerability in a vendored/copied dependency, or risk from how a dependency is actually used, is outside this view.
- D13 Secret Scanning: Secret detection is signature- and entropy-based on the current tree — a secret that does not match a known pattern, or one already rotated, will not be flagged (a clean scan is "nothing matched", not "no secrets exist").
- D14 License Compliance: License compatibility is checked against declared package metadata and a policy — mislabelled or missing license metadata, and obligations that depend on how you distribute, are not resolved here.
- D17 Explicit Debt: Acknowledged-debt signals (TODO/FIXME, suppressions, dead code) are textual — undocumented debt that nobody marked, and debt that lives in design rather than annotations, is invisible. Committed machine-written code (scaffolded migrations, designer/codegen output, generated stubs) is excluded — it is never the team's dead code to delete.
- D18 Solution Shape: Build integrity reflects whether the solution compiled in this environment — a build that needs a private feed, a specific SDK, or a generated file absent from the repo can read as broken when it is merely unreproducible here.
- D20 ADR Quality: ADR quality is an LLM read of the decision records present — it cannot know about decisions made and never recorded, and its verdict is sampled and advisory.
- D21 Naming Consistency: Naming quality is an LLM judgement over a bounded sample — it assesses clarity/consistency of the names it sees, not domain-correctness, and is advisory.
- D24 Comment Value: Comment value (WHY vs WHAT) is an LLM judgement over a bounded sample — it is advisory and cannot weigh a comment against the precise code change it was written to explain.
- D26 Project Cohesion: Project focus is sized from members/namespaces per project — a project that is broad by deliberate design reads the same as one that has sprawled.
- D28 Secrets (history): Secret-history scanning sweeps the git log for known patterns — a secret that predates the available history, or never matched a signature, is not found (clean means "nothing matched in the history we can see").
- D29 Static Analysis (SAST): SAST findings are pattern-based (semgrep) — it finds classes of bug it has rules for; logic flaws, auth/authorization gaps and issues needing runtime context are out of reach (and clean means "no rule matched").
- D32 Data Compliance (PII/GDPR): PII/GDPR signals are heuristic pattern matches in code — they flag likely handling concerns, not legal compliance, and cannot trace where data actually flows at runtime.
- D34 Knowledge Freshness: Freshness is decayed commit RECENCY, not comprehension — code read often but rarely committed reads as orphaned, and stable code that genuinely needs no changes is penalised the same as forgotten code; bot/squash commits distort it like the bus factor.
- D35 Change Coupling: Change coupling is co-change in COMMITS — files split across separate commits, or coupled only through a shared config/build step, read as uncoupled, and a sweeping commit (rename/format) is excluded so it doesn't couple everything. It shows that files change together, not WHY: a high coupling can be a healthy cohesive pair as readily as a hidden leak.
- AX10 Code composition: Role is inferred from namespace/folder convention, not semantics — a domain concept living in a folder named "Services" reads as application, and the split is lines-of-code, not business value. The business-logic-share score is a SOFT, FLOORED signal: it contributes to the Architecture lens but is floored at the Critical gate, so an infrastructure-heavy design (a gateway, an ETL, a driver) is legitimately low without being nuked to zero.
- M4 Documentation accuracy: Onboarding quality is an LLM read of the docs/setup present — it cannot run the onboarding or measure how long a real new joiner takes; the verdict is sampled and advisory.
- P6 Release Hygiene: Rollback/observability controls are inferred from repo artefacts (pipelines, dashboards-as-code) — controls configured in external tooling, with no in-repo trace, cannot be credited.
The LLM boundary
Dimensions
D4 · Code Duplication
4 duplicated block group(s) detected.
D5 · Coupling
3 projects, 0 dependency cycle(s), 0 unstable depended-on project(s).
What to do
- Resolve the 1 Off the main sequence finding(s) in Coupling. — One of this dimension's main actionable groups (1 warning-level).
- Stand up a CI pipeline, then gate Coupling in it to reach Verified (currently Documented). — This repository has no CI pipeline, so there is nothing to add a gate to yet — the pipeline comes first. Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
D6 · Cohesion (LCOM4)
0 of 35 classes have LCOM4 above 3.
D7 · Architectural Integrity
No mechanizable ADR was identified, so enforcement is not measured (scan coverage 100 %). Cycles found: 0.
What to do
- Stand up a CI pipeline, then gate Architectural Integrity in it to reach Verified (currently Documented). — This repository has no CI pipeline, so there is nothing to add a gate to yet — the pipeline comes first. Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
D9 · Test Distribution
4 test methods: 4 unit, 0 integration, 0 BDD, 0 e2e.
D10 · Test Quality
0 skipped, 0 zero-assertion, no mocking-framework packages referenced (hand-written doubles or no mocking) across 4 tests.
D12 · Dependency Hygiene
0 outdated, 0 vulnerable, 0 deprecated packages.
D13 · Secret Scanning
1 secret(s) detected.
What to do
- Resolve the 1 Leaked secret finding(s) in Secret Scanning — start with Client.cs. — One of this dimension's main actionable groups (1 issue-level).
- Stand up a CI pipeline, then gate Secret Scanning in it to reach Verified (currently Documented). — This repository has no CI pipeline, so there is nothing to add a gate to yet — the pipeline comes first. Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
D14 · License Compliance
0 of 5 packages use a banned license.
D17 · Explicit Debt
40 deducted debt markers + 0 dead symbols across 3944 LoC (6.7/KLoC) → score 0.0.
What to do
- Resolve the 1 NoWarnInCsproj repeated across 20 files finding(s) in Explicit Debt — start with Assembly-CSharp.csproj. — One of this dimension's main actionable groups (1 issue-level).
- Stand up a CI pipeline, then gate Explicit Debt in it to reach Verified (currently Documented). — This repository has no CI pipeline, so there is nothing to add a gate to yet — the pipeline comes first. Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
D18 · Solution Shape
2 projects, 228 source files, 52943 hand-written lines of code (52943 production / 0 test), 1 inter-project edges (build failed).
D20 · ADR Quality
Evaluated 1 ADR(s) individually; mean quality 2.0/10 (frequently incomplete). 0 flagged with a specific gap.
What to do
- Improve ADR Quality — currently 2.0/10. — Evaluated 1 ADR(s) individually; mean quality 2.0/10 (frequently incomplete). 0 flagged with a specific gap.
D21 · Naming Consistency
0 naming inconsistencies across 200 sampled symbols.
D24 · Comment Value
26 valuable / 1 redundant across 200 sampled comments; 1 shown with locations.
D26 · Project Cohesion
0 of 3 projects flagged as possibly oversized/incoherent.
D28 · Secrets (history)
21 finding(s): 0 critical, 21 high, 0 medium, 0 low. Remediation for historically-committed secrets is credential rotation — they remain in history regardless of later deletion.
What to do
- Resolve the 21 Secret finding(s) in Secrets (history) — start with ProjectSettings.asset (15), Orc Skin (Diffuse).psd (2), 06 Character.psd (2). — One of this dimension's main actionable groups (21 issue-level).
- Resolve the 1 Rotate the exposed credentials finding(s) in Secrets (history). — One of this dimension's main actionable groups (1 recommendation-level).
D29 · Static Analysis (SAST)
2 finding(s): 0 critical, 0 high, 2 medium, 0 low.
D32 · Data Compliance (PII/GDPR)
2 finding(s): 0 critical, 2 high, 0 medium, 0 low.
What to do
- Resolve the 2 High finding(s) in Data Compliance (PII/GDPR) — start with ToLuaExport.cs (2). — One of this dimension's main actionable groups (2 issue-level).
D34 · Knowledge Freshness
Every significant source file has living knowledge — recently and meaningfully worked.
D35 · Change Coupling
No strong hidden change-coupling between production files.
Frontend & cross-cutting dimensions
AX10 · Code composition
What to do
- The domain core is a small share of production code — check that business logic isn't leaking into the application/infrastructure layers (a thin domain is the anemic-domain smell).
AX3 · Project dependency cycles
AX4 · Dependency direction
AX5 · Architecture & structure
GD1 · Unfinished & placeholder code
- A placeholder string ("Replacement") is still in shipped code — typical of generated boilerplate that was never filled in. — AutoMobileShaderSwitch.cs:106
- A placeholder string ("replacement") is still in shipped code — typical of generated boilerplate that was never filled in. — AutoMobileShaderSwitch.cs:107
What to do
- Finish or delete NotImplementedException stubs and replace placeholder literals before shipping.
IC1 · Incompleteness & stubs
- A line of code has been commented out rather than removed — dead weight that rots and confuses. Delete it (version control remembers). (×5) — HeadBob.cs:25, HeadBob.cs:31, HeadBob.cs:52, …
What to do
- Clear the softer debt: remove commented-out code and dead branches, re-enable or delete skipped tests, and replace blanket warning suppressions with targeted ones.
M1 · Documentation (README)
What to do
- Add a build/run (quick start) section to the root README — the first thing a newcomer needs.
- Add a 'Testing' section to the root README — how to run the test suite.
- Add an 'Architecture' / 'How it works' section to the root README — the high-level shape.
M2 · Architecture documentation
What to do
- Grow the ADR log (currently 1) — reach 8 to raise the maturity tier; document significant decisions as they're made.
M3 · Folder & project structure
- Production code isn't grouped under a src/ folder — it's spread across several top-level directories, so there's no one place that says 'this is the product'.
- Tests aren't grouped in a dedicated test folder — the test surface isn't separable from production code at a glance.
- Only 1/3 projects share a common root namespace — the code's module identity is inconsistent.
What to do
- Group production code under src/ (or split deliberately, e.g. backend/ + frontend/) so production and tooling code aren't mixed at the root.
- Group tests in the folder your build system expects (tests/, test/, spec/, or your module's test source set) so the test surface is discoverable and CI can scope it.
- Adopt a consistent root-namespace convention (a shared prefix, e.g. Acme.*); short project-file/directory names are fine as long as the RootNamespace is uniform.
M4 · Documentation accuracy
P1 · CI/CD gates
- No CI workflow found (.github/workflows, azure-pipelines.yml, .gitlab-ci.yml, …) — changes aren't gated by an automated build/test.
What to do
- Add a CI workflow that builds and runs the test suite on every push/PR.
P3 · Security & performance tooling
- No static application security testing detected. For this repository's stack, add CodeQL's csharp pack (it analyses VB.NET too), or a security analyzer package (or `semgrep --config=auto`, which runs on any language) — this repository has no CI pipeline yet, so run it locally to clear the existing findings, then make it a step of the first workflow you add so a regression fails the build.
What to do
- Run what this repository's stack ships: CodeQL's csharp pack (it analyses VB.NET too), or a security analyzer package — or `semgrep --config=auto`, which runs on any language — — locally for now, since there is no CI pipeline here yet, and as a step of the first workflow you add so a security regression fails the build instead of landing.
- Enable Dependabot/Renovate or a dependency-review gate.
- Add gitleaks/trufflehog in CI to block PRs that introduce committed secrets.
P6 · Release Hygiene
- No CHANGELOG/HISTORY/RELEASES file — what shipped when isn't easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)
What to do
- Keep a changelog (e.g. Keep-a-Changelog) recording what shipped in each release.
X1 · Async correctness
X3 · Exception handling
X4 · Structured logging
Reference — by lens
| Lens | Score | Rating | Impact |
|---|---|---|---|
| Code Health | 70% | Adequate — gated by D17 | Capped at Fair by a Critical contributor — resolve it before relying on this lens. |
| Architecture | 95% | Exemplary | Strongest area. |
| Maturity | 62% | Adequate | Acceptable, with room to improve. |
| Readiness | 35% | Weak — gated by P1, P3 | Capped at Fair by a Critical contributor — resolve it before relying on this lens. |
| Security | 47% | Weak — gated by D28 | Capped at Fair by a Critical contributor — resolve it before relying on this lens. |
Not included — 61 check(s) not relevant to this codebase
- AC1 Text alternatives — No web markup found — accessibility is not applicable to this repository.
- AC2 Forms & labels — No web markup found — accessibility is not applicable to this repository.
- AC3 Page structure — No web markup found — accessibility is not applicable to this repository.
- AC4 Keyboard semantics — No web markup found — accessibility is not applicable to this repository.
- AC5 ARIA correctness — No web markup found — accessibility is not applicable to this repository.
- AC6 Visual & motion safety — No web markup found — accessibility is not applicable to this repository.
- AC7 A11y enforcement — No web markup found — accessibility is not applicable to this repository.
- AX1 Captive dependencies — no DI registrations detected
- AX2 Stateful singletons — no singleton implementations detected
- AX6 Interface segregation — no public interfaces
- AX7 Slice cohesion — not applicable — not a vertical-slice architecture
- AX8 Test isolation — no test/production split to check
- AX9 CQS / query purity — no CQRS query handlers detected — query purity is not applicable to this codebase
- AXB2 Runtime readiness — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
- C1 Data Protection — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
- C2 Access Controls — No access-control surface detected in the analyzed source — no web/app surface to authorize (no HTTP API or web-UI project) and no authorization code at all (no [Authorize]/policies, no imperative guard methods). Access control is therefore N/A here — this is a library/CLI, which is authorized by its CALLER, not by itself. If this codebase grows request handlers, the dimension reactivates and a default-deny posture is expected then.
- C3 Audit Trail — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
- C4 Data Retention — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
- C5 Data-Subject Rights — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
- D1 Cyclomatic Complexity — Most of this repository's production source (.cs, .fs, .java, .py) had no cyclomatic complexity computed for it, so cyclomatic complexity was not measured — whatever else this pass did read is not this repository's complexity. Not scored: no method bodies were exposed for those file kinds by any language model this pass could load. This is a gap in the analysis run, not a finding about this repository.
- D11 Test Reliability — Test reliability not measured — no test run produced results
- D15 Churn × Complexity Hotspots — complexity unreadable for .cs, .fs, .java, .py — churn × complexity hotspots could not be measured
- D16 Bus Factor — dormant codebase — no living knowledge left to concentrate
- D19 Documentation Quality — LLM evaluation failed
- D2 Cognitive Complexity — Most of this repository's production source (.cs, .fs, .java, .py) had no cognitive complexity computed for it, so cognitive complexity was not measured — whatever else this pass did read is not this repository's complexity. Not scored: no method bodies were exposed for those file kinds by any language model this pass could load. This is a gap in the analysis run, not a finding about this repository.
- D22 Internal API Consistency — No exposed public API
- D23 Boundary Type-Coupling — At only 65k LoC the codebase is small despite three projects, so its size alone makes it not need boundaries.
- D25 ADR Conformance — none of 1 ADRs are conformance-checkable — unverifiable.
- D27 Navigability — No calls could be sampled, so navigability was not assessed — tracing effort is measured over resolved call sites and this target exposed none. Not scored — this is a gap in the analyzer's reach, not a verdict about this repository.
- D3 God Classes — Most of this repository's production source (.cs, .fs, .java, .py) was not read by god-class detection, so class size was not assessed for the languages that are the product — whatever else this pass did read is not this repository's class size. Not scored — this is a gap in the analyzer, not a verdict about this repository.
- D30 Dependency Vulnerabilities — the solution did not restore on the analyzer's .NET SDK (an SDK/target-framework/restore mismatch, common for an older codebase), so there was no restored dependency graph to scan for NuGet CVEs — excluded rather than scored; re-run on an SDK that can restore this solution
- D31 IaC & Container Security — No Infrastructure-as-Code or container manifests found (Dockerfile, Terraform, Kubernetes/Helm, CloudFormation); nothing to scan.
- D33 JS/npm Dependency Vulnerabilities — No JS/npm manifest or lockfile found outside build output (package.json, package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lockb); no JS dependencies to scan.
- D36 Supply-chain Provenance & Signing — No CI/build pipeline found (.github/.forgejo/.gitea workflows, .gitlab-ci.yml, azure-pipelines*.yml, .pipelines/, .vsts-ci/, Jenkinsfile, .circleci); there is no build to attest provenance for.
- D37 Vulnerability-disclosure Policy — No vulnerability-disclosure policy file found (SECURITY.md/.markdown/.rst/.txt at root or under .github/.forgejo/.gitea/docs, .well-known/security.txt). A coordinated-disclosure policy may live off-repo, so this is not evidenced rather than failed.
- D38 OSV Dependency Vulnerabilities — No supported non-.NET dependency lockfile found outside build output (npm package-lock/yarn/pnpm/bun, Go go.mod, Rust Cargo.lock, Maven pom.xml, Gradle lockfiles, Python requirements.txt/poetry.lock/Pipfile.lock/pdm.lock, PHP composer.lock, Ruby Gemfile.lock, Elixir mix.lock, Dart pubspec.lock, Swift Package.resolved); nothing for OSV to scan. A NuGet-only repo stays NotApplicable — .NET CVEs are D30's domain.
- D39 IL Efficiency — The target did not build, so no IL was available to measure.
- D40 Network Egress Confinement — No Kubernetes/orchestration workloads found in the repository manifests; network egress policy is a cluster-native control that may live at the platform/firewall layer, so there is nothing to assess here.
- D41 Kernel & Syscall Confinement — No Kubernetes/orchestration workloads found in the repository manifests; seccomp/AppArmor/SELinux confinement is a workload-level control, so there is nothing to assess here.
- D42 Runtime Threat Enforcement — No Kubernetes/orchestration workloads found in the repository manifests; runtime threat-detection and admission-control policy are cluster-level controls, so there is nothing to assess here.
- D8 Code Coverage — Coverage not measured — analyzer environment
- DM1 Domain Modelling — not scored — this repository shows none of the 3 signals this check looks for
- ED1 Event-Driven — not scored — this repository shows none of the 3 signals this check looks for
- ED5 Idempotency — no mutating command handlers or message consumers detected — idempotency check not applicable
- ES1 Event Sourcing — not scored — this repository shows none of the 3 signals this check looks for
- P12 CI test-gate honesty — no CI workflow found
- P2 Observability — Observability was not assessed: this check reads a source model that does not carry this repository's product — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of a logging idiom this check recognises is NOT evidence that this repo lacks structured logging (it may log through its own ecosystem's logger). This is a gap in the analyzer, not a finding about this repository.
- P4 Deployment & Rollback — not evidenced — no deploy/rollback/approval signal in the repo; absence of evidence is not evidence of a manual release
- P5 DR & Backup — not evidenced — repo shows no backup/RTO/RPO controls; absence of evidence is not evidence of a working control
- P7 Outbound HTTP resilience — not applicable — this isn't a service/API/worker
- P8 Schema migrations — no EF Core usage detected
- P9 Domain vs controller coverage — no coverage report found on disk — produce a coverage report in a standard format (Cobertura — `dotnet test --collect:"XPlat Code Coverage"` with a `coverlet.collector` PackageReference) into the repo working tree before the scan — a CI step is the usual place, since the artefact is commonly gitignored, or wire coverage collection into CI, to enable this cross-layer check
- PF1 Benchmark discipline — Performance is assessed only for perf-relevant repos — a packaged library, one that ships benchmarks, or one already using allocation-aware APIs. This repo isn't one, so the Performance lens is not applicable and is excluded from the score.
- PF2 Allocation hygiene — Performance is assessed only for perf-relevant repos — a packaged library, one that ships benchmarks, or one already using allocation-aware APIs. This repo isn't one, so the Performance lens is not applicable and is excluded from the score.
- PF3 Async & latency hygiene — Performance is assessed only for perf-relevant repos — a packaged library, one that ships benchmarks, or one already using allocation-aware APIs. This repo isn't one, so the Performance lens is not applicable and is excluded from the score.
- S1 Web-Security Posture — No web surface detected in the analyzed source — no HTTP API or web-UI project (no controllers/minimal-API endpoints, no Razor/Blazor views) and no web middleware (HTTPS redirection, HSTS, security headers, cookies). Transport security, security headers, secure cookies, CSRF/input-validation and middleware-order controls are therefore N/A here — this is a library/CLI/worker, not a web app. Crypto hygiene was still checked and found nothing to flag. If this codebase becomes web-facing, the dimension reactivates automatically.
- SC1 Supply-chain hygiene — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
- X2 Cancellation propagation — no async methods found
- X5 Nullable reference types — no NRT-eligible projects
- X6 Hand-rolled structured-format parsing — Reported, not scored — this card publishes what it found rather than grading it. Its content is the findings and the key metric above.
- X7 Silent fallback defaults — Reported, not scored — this card publishes what it found rather than grading it. Its content is the findings and the key metric above.
Appendix A — Findings (grouped)
Issue — 25 finding(s)
- Secret: generic-api-key SDK/XinGeSDK_Demo/ProjectSettings/ProjectSettings.asset:526
- Secret: generic-api-key SDK/PullUpQQGroupDemo/ProjectSettings/ProjectSettings.asset:589
- Secret: generic-api-key 2DPlatformer/ProjectSettings/ProjectSettings.asset:527
- Secret: generic-api-key UnityEditorExtension/MultiEditorWindow/ProjectSettings/ProjectSettings.asset:506
- Secret: generic-api-key MVP_Demo/ProjectSettings/ProjectSettings.asset:507
- Secret: generic-api-key UnityEditorExtension/NodeEditor/ProjectSettings/ProjectSettings.asset:506
- Secret: generic-api-key HotUpdate/AssetBundleFramework/ProjectSettings/ProjectSettings.asset:506
- Secret: generic-api-key ChangeCharacter/ProjectSettings/ProjectSettings.asset:527
- Secret: generic-api-key HotUpdate/UnityTechnologiesAssetbundleDemo/demo/ProjectSettings/ProjectSettings.asset:523
- Secret: generic-api-key HotUpdate/AssetBundleDemo/ProjectSettings/ProjectSettings.asset:506
- Secret: generic-api-key GuideSystem/ProjectSettings/ProjectSettings.asset:506
- Secret: generic-api-key SDK/XinGeSDK/ProjectSettings/ProjectSettings.asset:507
- Secret: generic-api-key HighScore/HighScore/Library/ProjectSettings.asset:286
- Secret: generic-api-key HighScore/HighScore/ProjectSettings/ProjectSettings.asset:286
- Secret: aws-access-token Effective C#/Delegate_EventTraining/Assets/NGUI/Examples/Models/Orc/Orc Skin (Diffuse).psd:5669
- Secret: aws-access-token Effective C#/Delegate_EventTraining/Assets/NGUI/Examples/Models/Orc/Orc Skin (Diffuse).psd:7856
- Secret: generic-api-key UnityEditorExtension/NodeEditorCollection/NodeEditor/ProjectSettings/ProjectSettings.asset:506
- Secret: aws-access-token UGUITraining/UGUIDemo02/Assets/UI/Source/06 Character.psd:13872
- Secret: facebook-page-access-token UGUITraining/UGUIDemo02/Assets/UI/Source/06 Character.psd:19840
- Secret: aws-access-token UGUITraining/UGUIDemo02/Assets/UI/Source/05 Window Frame.psd:18124
- Secret: facebook-page-access-token UGUITraining/UGUIDemo02/Assets/UI/Source/05 Window Frame.psd:24092
- High: watchdog-sensitive-personal-data-in-log HotUpdate/uLuaDemo/Assets/ToLua/Editor/ToLuaExport.cs:2724
- High: watchdog-sensitive-personal-data-in-log HotUpdate/uLuaDemo/Assets/ToLua/Editor/ToLuaExport.cs:2731
- Leaked secret: hardcoded-credential NetWorkAndResources/SampleSocket/Socket/Assets/Scripts/Client.cs:68
- NoWarnInCsproj repeated across 20 files Minecraft/Assembly-CSharp.csproj:25
Warning — 13 finding(s)
- Medium: use-defused-xml UnityEditorExtension/Python/unpack_plist.py.py:3
- Medium: unsafe-path-combine XlsxTools/Xls2Lua/Xls2Lua/FileExporter.cs:112
- Test reliability not measured — no test run produced results
- dormant codebase — no living knowledge left to concentrate
- Monorepo: only 1 of 71 solutions was scored
- Analyzed solution does not cover the bulk of the repository
- LLM evaluation failed
- Duplicated block (17 lines × 2) Minecraft/Assets/Standard Assets/Utility/AutoMobileShaderSwitch.cs:142
- Duplicated block (15 lines × 2) Minecraft/Assets/Standard Assets/Utility/AutoMobileShaderSwitch.cs:118
- Duplicated block (14 lines × 2) Minecraft/Assets/Standard Assets/CrossPlatformInput/Scripts/Joystick.cs:58
- Duplicated block (8 lines × 2) Minecraft/Assets/Standard Assets/Utility/AutoMobileShaderSwitch.cs:176
- Off the main sequence: Assembly-CSharp-firstpass
- Coverage not measured — analyzer environment
Recommendation — 3 finding(s)
- complexity unreadable for .cs, .fs, .java, .py — churn × complexity hotspots could not be measured
- redundant comment Minecraft/Assets/Scripts/LifeManager.cs:19
- Rotate the exposed credentials — git history can't be un-committed
Info — 3 finding(s)
- Build did not complete in the analyzer
- No exposed public API
- Tests co-located / outside the solution
Appendix B — Reproduction & audit trail
| Dimension | Tool | Version | Command | Findings | Raw output |
|---|---|---|---|---|---|
| D28 · Secrets (history) | gitleaks | — | gitleaks detect --no-banner --report-format json --report-path /dev/stdout --exit-code 0 --source . | 21 | artifacts/raw/gitleaks-history.json |
| D29 · Static Analysis (SAST) | semgrep | — | semgrep --config /opt/semgrep-rules/security-audit.yml --config /opt/semgrep-rules/owasp-top-ten.yml --json --quiet --timeout 0 --metrics off . | 2 | artifacts/raw/semgrep.json |
| D30 · Dependency Vulnerabilities | dotnet | — | dotnet: not applicable — the solution did not restore on the analyzer's .NET SDK (an SDK/target-framework/restore mismatch, common for an older codebase), so there was no restored dependency graph to scan for NuGet CVEs — excluded rather than scored; re-run on an SDK that can restore this solution | 0 | — |
| D31 · IaC & Container Security | trivy | — | trivy: not applicable — No Infrastructure-as-Code or container manifests found (Dockerfile, Terraform, Kubernetes/Helm, CloudFormation); nothing to scan. | 0 | — |
| D32 · Data Compliance (PII/GDPR) | semgrep | — | semgrep --config /opt/semgrep-rules/gdpr.yml --json --quiet --timeout 0 --metrics off . | 2 | artifacts/raw/semgrep-gdpr.json |
| D33 · JS/npm Dependency Vulnerabilities | trivy | — | trivy: not applicable — No JS/npm manifest or lockfile found outside build output (package.json, package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lockb); no JS dependencies to scan. | 0 | — |
| D36 · Supply-chain Provenance & Signing | provenance | — | provenance: not applicable — No CI/build pipeline found (.github/.forgejo/.gitea workflows, .gitlab-ci.yml, azure-pipelines*.yml, .pipelines/, .vsts-ci/, Jenkinsfile, .circleci); there is no build to attest provenance for. | 0 | — |
| D37 · Vulnerability-disclosure Policy | disclosure | — | disclosure: not applicable — No vulnerability-disclosure policy file found (SECURITY.md/.markdown/.rst/.txt at root or under .github/.forgejo/.gitea/docs, .well-known/security.txt). A coordinated-disclosure policy may live off-repo, so this is not evidenced rather than failed. | 0 | — |
| D38 · OSV Dependency Vulnerabilities | osv-scanner | — | osv-scanner: not applicable — No supported non-.NET dependency lockfile found outside build output (npm package-lock/yarn/pnpm/bun, Go go.mod, Rust Cargo.lock, Maven pom.xml, Gradle lockfiles, Python requirements.txt/poetry.lock/Pipfile.lock/pdm.lock, PHP composer.lock, Ruby Gemfile.lock, Elixir mix.lock, Dart pubspec.lock, Swift Package.resolved); nothing for OSV to scan. A NuGet-only repo stays NotApplicable — .NET CVEs are D30's domain. | 0 | — |
| D40 · Network Egress Confinement | runtime-hardening | — | runtime-hardening: not applicable — No Kubernetes/orchestration workloads found in the repository manifests; network egress policy is a cluster-native control that may live at the platform/firewall layer, so there is nothing to assess here. | 0 | — |
| D41 · Kernel & Syscall Confinement | runtime-hardening | — | runtime-hardening: not applicable — No Kubernetes/orchestration workloads found in the repository manifests; seccomp/AppArmor/SELinux confinement is a workload-level control, so there is nothing to assess here. | 0 | — |
| D42 · Runtime Threat Enforcement | runtime-hardening | — | runtime-hardening: not applicable — No Kubernetes/orchestration workloads found in the repository manifests; runtime threat-detection and admission-control policy are cluster-level controls, so there is nothing to assess here. | 0 | — |
Appendix C — Personal-data map
Phone — 3 field(s)
- CrossPlatformInitialize.mobileBuildTargetGroups Minecraft/Assets/Standard Assets/Editor/CrossPlatformInput/CrossPlatformInputInitialize.cs:91
- SimpleMouseRotator.autoZeroVerticalOnMobile Minecraft/Assets/Standard Assets/Utility/SimpleMouseRotator.cs:21
- SimpleMouseRotator.autoZeroHorizontalOnMobile Minecraft/Assets/Standard Assets/Utility/SimpleMouseRotator.cs:22