RepoAuditor: evidence-bounded security review for acquired codebases
Authors/Creators
Description
RepoAuditor is a security-review pipeline for acquired codebases. It combines deterministic scanners, bounded architecture and trust-boundary analysis, human-reviewed findings, quantitative evidence summaries, and separate engineering and leadership reports.
Evidence boundary: scanner matches and model outputs are review candidates, not proof of exploitability, actionability, compromise, exhaustive coverage, or production readiness. The package-local weak-RNG detectors are syntactic candidate detectors and do not execute PRNG recovery.
Files
erxxc/repoauditor-v0.1.0.zip
Files
(2.3 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:8711ce2b90fb3376400c8b2eb551d023
|
2.3 MB | Preview Download |
Additional details
Related works
- Is source of
- Software: https://github.com/erxxc/repoauditor (URL)
- Is supplemented by
- Software: 10.5281/zenodo.22697185 (DOI)
- Software: https://github.com/erxxc/prng-lattice-lab (URL)
Software
- Repository URL
- https://github.com/erxxc/repoauditor