Syndical
Quality
70/100
Maintainability
93/100
Static security checks
High severity
0 critical · 1 high · 0 medium · 0 low
5 qualified rules · findings require review
529 / 749 files without configured warnings or errors.
11332 / 12145 recognized functions within every limit. 1.53% of tokens duplicated.
Measured 3 October 2026 · b18c880cbbff
Coverage & evidence
749 selected production files. csharp: 544 · javascript: 7 · typescript: 198.
- Native checks: 749 / 749 files analyzed
- Function analysis: 749 / 749 files analyzed
- Duplication: 749 / 749 files analyzed
- Security checks: 749 / 749 files analyzed
Function limits: complexity ≤ 15, lines ≤ 80, parameters ≤ 5. Maintainability takes the lower of 93% function compliance and 98% duplication-free tokens. Function parsing limitations are recorded below.
Duplication: at least 5 lines and 50 tokens, mild mode.
Qualified security checks
- HttpClientHandler certificate callbacks that explicitly accept every certificate. (high; csharp).
- Explicit rejectUnauthorized:false settings and NODE_TLS_REJECT_UNAUTHORIZED=0 assignments. (high; javascript, typescript).
- BrowserWindow object literals explicitly disabling context isolation. (high; javascript, typescript).
- BrowserWindow object literals explicitly enabling renderer Node integration. (medium; javascript, typescript).
- Direct console arguments named password, token, key or client secret; this is not a dataflow rule. (high; javascript, typescript).
Included roots: apps/, libs/. Extensions: .cs, .ts, .tsx, .js, .jsx, .mjs.
Excluded paths and suffixes: test, tests, fixtures, bin, obj, node_modules, out, dist, resources, .test.ts, .test.tsx, .spec.ts, .spec.tsx, .d.ts, .g.cs, .generated.cs.
Gate: passed. Accepted existing findings still count in these scores.
Findings beyond the accepted baseline: 0.
Policy: syndical-oss-quality-v1
- Scores measure compliance with this named profile; profiles can differ between languages and repositories.
- Quality measures configured native warnings and errors, not functional correctness or test effectiveness.
- C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.
- Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.
- No overall quality or human-superiority claim is supported by this scorecard.
Report SHA-256 b2cff48d9f15b6ee656d4f5f4b51fd6d5c80ab3d6f79d28e403237c535533f35