Borehole reading · not a certification

Check a mark

A Borehole code resolves to the analysis we actually ran. Type the code printed on a report and this page re-renders the authoritative version — not a claim about it.

Twelve characters. Case and dashes do not matter.

Verified

This code matches a Borehole analysis of codeberg.org/forgejo/forgejo, and the record is unchanged since the mark was issued.

Repository
codeberg.org/forgejo/forgejo
Commit
994e539b556f7908d1390b1f0992743621ec0944
Surveyed
2026-09-27
Mark issued
2026-09-29
Assessor
borehole 0.7.2
Checks run
103
Ran in
cloud-run — not attested

This commit has been surveyed again since this mark was issued. The mark above is still valid — it attests to the survey it was issued for, and always will. But a newer reading of the same commit exists, made by borehole 0.7.13 on 2026-10-04, finding 15 things against this one's 15. Read the newer one.

Its report page publishes this analysis under today's rules. The mark above still attests to the record as issued. The page differs from it as follows, and its headline band reads adequate.

This mark covers 103 checks. Borehole now runs 106. A mark attests to the survey that was run, not to the checks written since it was issued. If the newer checks matter to you, ask for a fresh repo survey at this commit.

What the analysis recorded

DimensionBandFindings
Architecture & Codebase — including AI provenance adequate 2
Engineering Process & SDLC Maturity adequate 1
Organization & Key-Person Risk not assessable 0
Product & Engineering Maturity adequate 2
Security & Reliability Posture significant findings 9
Observability & Operations adequate 1
Fit with the Acquirer not assessable 0

Read the full analysis