boinger/Codebase Audit

Cold-start codebase audit powered by Claude Code. Finds bugs, security issues, architecture problems, tech debt, and test gaps.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jun 9, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: boinger/zorille@8ec4e943de57bf5cc78fb4c895e0cf091bd38a09 # v1.12.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
anthropic-api-keyAnthropic API key for Claudeyes
fail-onFail threshold: critical (default) or importantnocritical
formatOutput format: json (default) or sarifnojson
changed-onlyScope audit to files changed in this PR/branchnofalse
baseline-onlyEstablish baseline without failing (for CI onboarding)nofalse
fail-on-newFail only on new findings vs previous baselinenofalse
fail-on-regressionAlso fail if health score regressednofalse
min-severityFilter findings to this severity and above: critical, important, notableno""
no-infraSkip infrastructure scanningnofalse
upload-sarifAuto-upload SARIF to GitHub Code Scanning (requires security-events: write)notrue
sarif-categoryCategory for SARIF upload (disambiguates multiple analysis tools)nocodebase-audit
cache-baselinePersist baselines across runs via actions/cachenotrue
claude-code-versionClaude Code CLI version to install (default: latest)nolatest
extra-flagsAdditional flags passed directly to /codebase-auditno""
namedescription
statusAudit result: pass or fail
health-scoreCodebase health score (0-100)
findings-countNumber of findings
sarif-filePath to SARIF file (when format=sarif)