The public record
Browse the public reports — see real code improve.
Every card below is a real repository whose owner chose to publish, and it opens the entire survey — every lens, every finding, and the exact rule each was scored by. No cherry-picked mock-ups, no testimonials we wrote ourselves. Audit how each number was reached — then run the same measurement on your own code.
No account is needed to read any of it. Start with a repository you may already know: 3b1b/manim or open-telemetry/opentelemetry-erlang — full reports, open right now.
Sign in with GitHub · No card · TypeScript, Python, Java, C#, Rust and more · The first full report on any repo is €0 — no depth is ever gated.
Thousands
of public surveys — counted live in the gallery, not typed on this page
100%
reproducible — exact rubric and scoring rules fixed for every reading
€0
first report on every repo
From the public record
Three published surveys — and the whole list on CAI.
Real repositories whose owners chose to publish. Each card opens its full survey — the first → best arc on it is the ratchet at work, earned scan over scan and never talked up. The complete list of measured open-source projects lives at codeassuranceindex.info/surveys.
What a scanner can't see
The findings behind the number — located, not counted.
A line-scanner counts lint. Watchdog locates the architecture, domain-model and event findings — a bounded-context leak, an anemic aggregate, a non-deterministic replay — to the exact file and line, straight from a real published report. Here are a few from one, with an honest count of the rest.
What every published survey carries
The full survey — not a badge.
Each published report is an opted-in repository with the complete measurement open: reproducible, with the exact rubric fixed for every reading.
A changelog
What moved since last time — CAI and per-lens deltas, findings resolved vs raised, features and fixes landed.
A CycloneDX SBOM
Downloadable with every survey — the dependency and licence inventory, current by construction.
CWE-tagged findings
Security findings tagged with their MITRE CWE id — the taxonomy an auditor recognises.
Behavioural signals
Hotspots and bus-factor, mined from git history — the risk that isn't in the code.
How reports get here
The free open-source lane publishes automatically — a condition, not an option. Paid cohorts publish only by explicit opt-in, and reports that regress below a previously published report are never published.
This page is the human gallery. The measured open-source projects are listed at codeassuranceindex.info/surveys, and the canonical registry of signed deliveries at codeassuranceindex.info/registry. Neither is ours alone: CAI is an open standard, so anyone who implements it can publish there — a survey on that list was not necessarily produced by Watchdog.
The code is the evidence. Measure it, trend it, own it.
Sign in with GitHub · no card · Elixir, Java, Go, C#, TypeScript and more · the first full report is €0.