- SignalDesk2 hr ago
Original Summary
I'm the founder. I've done technical due diligence on acquisitions for years, first at Amazon. The risks that changed a deal were rarely in the data/deal room. The clues we really we after was the repository: does the team review its code, does one person carry the recent work, did the licence change, do the tests run in CI? Most of it was answerable in the first afternoon, if you knew where to look. Borehole does that afternoon's reading, for free on public repositories. How it works - 106 deterministic checks (no LLM) read the history and the working tree and rate seven dimensions: architecture, engineering process, key-person risk, product maturity, security, operations, and fit with the acquirer. The free survey reads six of them; fit needs an acquirer. - Every finding cites the commit, path and lines it rests on. - What the code can't settle becomes a question for a person, not a guess. - No model writes the findings. A language model reviews paid reports of public repositories and can withdraw a finding it judges the code contradicts. It can be wrong too. - Private repositories: an open-source collector runs on your own machine and sends facts, never files.
--dry-runprints all of it first. What I learned building it - A check that sounds right is not a check that is right. Some checks I was sure of turned out wrong more often than right on real repositories. Those checks can no longer rate a finding significant; their findings read as worth checking first, until they prove themselves. - "Your code never leaves your machine" is a claim nobody should take on trust. The dry run exists so you don't have to. - A rating that never says "strong" tells a buyer nothing. Getting the top of the scale reachable took as much work as the bottom. Stack: Python, on Google Cloud. The collector is a Python package on PyPI. Public repositories are free: the first survey and five report reads need no account, then a free GitHub sign-in. It's in beta. If you want to run it on a private repository, email [ support@borehole.dev ](mailto: support@borehole.dev ) with the subject "Beta key" for a free Report key (30 days, private repos included). I'd like a three-question survey back, and to hear where it's wrong. https://borehole.dev/?utm_source=reddit&utm_medium=organic&utm_campaign=week1&utm_content=sideproject A sample report (RustDesk): https://borehole.dev/r/rustdesk/rustdesk/b5d8b97?utm_source=reddit&utm_medium=organic&utm_campaign=week1&utm_content=sideproject   submitted by   /u/nerolabs [link]   [comments]- 情报分类:技术学习与提效
- 分类依据:内容涉及技术、AI、软件工具或工程实践
- 信息来源:Reddit · SideProject
- 发布时间:2026/10/8 20:09:45
- No replies yet