This is a report. How to read one.
Borehole reads a repository's git history and working tree, and rates it on the seven dimensions a deal team cares about. Below is part of a real report, on prometheus/prometheus, as its public page shows it. The notes beside it say what each part is for.
dff7878 · 18,736 commits · 1,691 files
Reads strong: 4 of 6 rated dimensions are strong, 2 are adequate and none is significant.
| Dimension | Rating | ||
|---|---|---|---|
| 01 | Architecture & Codebase — including AI provenance | strong | |
| 02 | Engineering Process & SDLC Maturity | strong | |
| 03 | Organization & Key-Person Risk | strong | |
| 04 | Product & Engineering Maturity | adequate | |
| 05 | Security & Reliability Posture | adequate | |
| 06 | Observability & Operations | strong | |
| 07 | Fit with the Acquirer | not assessable |
Product & Engineering Maturity
04 · adequate109 direct dependencies in a single manifest
adequatego.mod declares 109 direct dependencies. Each one is a maintenance obligation, a supply-chain surface and a potential licence question that transfers with the asset. The count says nothing about whether any given dependency was a good choice; it says how many such choices a buyer inherits.
| direct-dependencies | go.mod — 109 declared |
| direct-dependencies | web/ui/mantine-ui/package.json — 39 declared |
| direct-dependencies | web/ui/react-app/package.json — 38 declared |
| direct-dependencies | web/ui/module/codemirror-promql/package.json — 2 declared |
What a person adds
Product & Engineering Maturity
04 · minimal coverage- measured 1,532 commits landed in the last year, against 1,085 the year before (+41%). What drove it: new people, a deadline, or code produced faster than before?
How a survey runs
The same checks run every way. What differs is where the code is read.
A public repository
- Paste its address, from GitHub, GitLab, Azure DevOps, Bitbucket, Codeberg, Gitea or SourceHut. No account, and no access to anything of yours.
- Borehole's worker clones it and reads it: the history and the working tree, at one commit. The clone uses no credential and is deleted when the survey ends.
- The report is public, and listed in the library.
- A paid survey gets a second read. A language model reads each finding against the code, and withdraws one it judges the code contradicts. The report says which and why. It never adds a finding and never raises a band. How the pieces fit.
A private repository, on your machine
- The collector reads it where it lives: your laptop, your CI or a server of yours.
- It sends what the checks need: never whole files; facts and short excerpts of up to 120 characters where a check matched. The dry run prints all of it, and sends nothing.
- The report is private to your account. Sending takes a Report key.
pip install -U borehole borehole collect . --dry-run
A private repository, in your own cloud
- The same collector runs in Confidential Compute, in your own Google Cloud project.
- Google Cloud attests which collector image ran, and signs the facts it sends. The report carries that signature.
- A buyer can check the facts were not edited, without trusting you or us.
A private target you're buying
- You send the target your key.
- The target runs the collector on its own systems, or in its own cloud, and sees the report first.
- The target decides who reads it, and shares the link with you.
What the seven dimensions cover
106 checks read the first six. Each dimension also hands a person the questions the code cannot settle: 41 in all, each with where its answer lives.