Skip to content

Latest commit

 

History

310 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

DEV LEDGER. Your GitHub history, made legible. Open source · Privacy-conscious · Read-only. v1.3.0 · AGPL-3.0-only

Live App · Documentation · Security · License

Dev Ledger product demo

What Dev Ledger measures

Dev Ledger connects through a GitHub App and builds a read-only analytical record from repositories the user explicitly authorizes.

MEASURE ACTIVITY CODE
Net source growth Active days Language composition
Additions & deletions Streaks & extremes Repository history
Churn Circadian patterns Project evolution
Commits Rhythm & milestones Longitudinal change
SHARE HISTORY SYNC
Range-aware visual records Months and years of development GitHub webhooks
Compact exports Change over time Resumable history coverage
Selected-range context Longitudinal patterns Rate-limit-aware continuation

Privacy by design

Important

Dev Ledger measures development activity without indexing repository source code.

Dev Ledger is intentionally narrower than a source-code indexing product.

Dev Ledger uses Dev Ledger does not persist
Repository metadata needed for product metrics Repository source code
Git-derived activity data Commit messages
Language statistics Pull-request titles
Computed development history GitHub email addresses
Synchronization state GitHub OAuth access tokens
GitHub App installation tokens
Raw webhook payload bodies

The product stores only the GitHub-derived metadata needed to compute its metrics and maintain synchronization. Repository permissions are read-only.

The public Security & Privacy Trust Record documents the current implementation and security boundaries in detail.

Architecture

%%{init: {'theme':'base','themeVariables':{'primaryColor':'#0e0f0e','primaryTextColor':'#e8e6e0','primaryBorderColor':'#4a4945','lineColor':'#8a877f','edgeLabelBackground':'#131413','fontFamily':'SFMono-Regular, Menlo, monospace'}}}%%
flowchart LR
  B[Browser] -->|GitHub OAuth| G[GitHub]
  B -->|same-origin HTTPS| D[Dev Ledger / Vercel]
  G -->|GitHub App API + signed webhooks| D
  D -->|server-side only| S[(Supabase Postgres)]
  D -->|allowlisted product events| P[PostHog EU]
  B -->|cookieless traffic measurement| A[Vercel Web Analytics]
Loading

The frontend is React + Vite. API routes run as Vercel Functions. GitHub App ingestion writes normalized metadata to Supabase Postgres. The browser never receives a database service credential.

Read the architecture documentation →

Technology

FrontendReact 19 · TypeScript · Vite 8
InterfaceTailwind CSS 4 · Framer Motion
IdentityGitHub OAuth · GitHub App
ComputeVercel Functions
DataSupabase Postgres
Product analyticsPostHog · custom-event-only
Traffic analyticsVercel Web Analytics
CIGitHub Actions
Security checksTypecheck · tests · npm audit · gitleaks · artifact scan · recovery drill

Quick start

Requirements: Node.js 24 · npm · Git

git clone https://github.com/Aliferous3/dev-ledger.git
cd dev-ledger
npm ci
npm run dev

Plain Vite runs the UI with synthetic development fixtures. Production builds replace the fixture barrel with an inert stub, so fixture telemetry does not ship to users.

Run the full GitHub + Supabase stack

Install the Vercel CLI, copy the environment template, and populate your own GitHub App and Supabase values:

cp .env.example .env.local
vercel dev

Never commit .env.local, private keys, database dumps, or provider credentials.

Run the verification suite

Run the same core checks used by CI:

npm run build
npm run typecheck
npm test
npm audit --audit-level=moderate

The GitHub Actions security gate also scans git history with gitleaks and runs a synthetic Postgres 17 migrate → backup → restore verification.

Database operations

Migrations live in migrations/ and are the schema source of truth.

Postgres 17 or Docker is required only for local recovery-drill work.

npm run db:migrate
npm run db:backup
npm run db:drill

The recovery drill refuses non-local database targets. Production recovery remains an operator-controlled procedure documented in docs/disaster-recovery.md.

Security

Caution

Do not open a public issue for a vulnerability. Follow SECURITY.md for private reporting.

The repository CI is intentionally fail-closed around common release risks: dependency audit, secret scanning, browser/server environment separation, built-artifact inspection, strict typechecking, and a synthetic recovery drill.

Repository guides

CONTRIBUTE SECURITY OPERATIONS PROJECT
Contributing Security policy Architecture Changelog
Code of conduct Support Disaster recovery Trademark policy
Contributor agreement Security & Privacy Secret rotation Privacy Policy

Status

Current application version: v1.3.0

Dev Ledger is under active development. Metrics are derived from available GitHub history and can be affected by repository deletion, force-pushes, attribution gaps, API limits, and disconnected repositories.

License

Dev Ledger is open source under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). See LICENSE.

The AGPL permits use, modification, redistribution, and commercial use subject to its terms, including source-availability obligations for qualifying modified network deployments. The Dev Ledger name, logo, and distinctive branding are addressed separately in TRADEMARKS.md.

Contributions are welcome under CONTRIBUTING.md and the Contributor License Agreement.


Dev Ledger · Your GitHub history, made legible.

Live App · Privacy Policy · Terms of Service

About

An evolving ledger of code, commits, repositories, deployments, and the cumulative body of work behind them.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages