Skip to content

CodeDelta scan

Actions

About

Measure churn and flag AI-generated / AI-agent code on every pull request
v2.2.0
Latest
Star (0)

CodeDelta GitHub Action

Measure code churn and flag AI-generated / AI-agent code on every pull request — then comment the summary on the PR, surface findings in the code-scanning (Security) tab, and optionally block the merge. Runs entirely on your own runner; no source leaves the machine and nothing phones home. Setup is two lines in a workflow file.

CodeDelta's actual PR comment posting itself — verbatim from the public demo PR, default mode

Real output: the comment above is character-for-character what CodeDelta posted on the public demo PR, running the default mode (churn + Agent Scan).

Who makes inline edits? Hand-maintained projects: 17 in every 100 changes. One agent-built codebase: fewer than 1 in 100.

The data behind the Action: inline edit = CHG_LLOC, a changed logical statement — study and reproduction hashes at codedelta.app/paper-repchurn.html.

# .github/workflows/codedelta.yml
name: CodeDelta
on: [pull_request]

permissions:
  contents: read
  pull-requests: write     # post the summary comment
  security-events: write   # upload SARIF to the code-scanning tab

jobs:
  codedelta:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }   # full history so churn (base..head) works
      - uses: code-delta-app/action@v1

That's the whole setup. Free and fully unlocked until 31 October 2026 with the built-in evaluation licence — no license, no secrets, no signup. The engine downloads itself. See example-workflow.yml for a fully configured workflow with gating and an AI Bill of Materials.

Setup (one minute)

  1. Add the workflow above to .github/workflows/codedelta.yml. Done.

To run past that date — or to use your own licence sooner — add one secret: CODEDELTA_LICENSE = base64 of your codedelta.lic (base64 -i codedelta.lic | pbcopy), then pass it as the license input. It overrides the built-in evaluation licence automatically. Get a license at codedelta.app.

No install on anyone's machine; it all runs on the GitHub runner.

Inputs

Input Default Description
license built-in evaluation licence Optional. base64 of codedelta.lic, or a path to it (use a repo secret). Overrides the evaluation licence (valid to 31 October 2026).
engine-url latest release URL of the CodeDelta Linux bundle (.tar.gz). Defaults to the latest published release; override to pin a version or self-host.
path . Directory to scan.
mode churn_agent churn_agent (churn + Agent Scan — the default) / both (adds the ML AI audit) / churn (churn only) / ai_audit (AI + agent, no churn) / ai / agent.
threshold 50 AI sensitivity 0–100 (affects rating cut-offs only).
baseline — Path to a committed codedelta-baseline.json.
fail-on-new false Fail the job if there are new findings vs the baseline.
comment true Post the summary as a PR comment (updates in place).
sarif true Upload findings as SARIF to the code-scanning tab.
gate false Fail the job on the default AI-governance policy: egress to a non-allied jurisdiction (CN/RU/KP/IR) or the rogue exec-on-model pattern. Needs an agent scan (mode: agent/both/ai_audit/churn_agent, i.e. any mode but plain churn/ai).
gate-policy — Path to a custom gate policy JSON (deny_jurisdictions / allow_providers / deny_flags / max_risk). Implies gate.
bom — Write an AI Bill of Materials to this path.
bom-format native native or cyclonedx (CycloneDX 1.6).

How findings reach the PR

  • Comment — a concise churn + AI summary, re-used (edited) on each push.
  • Annotations / Security tab — SARIF results appear inline on the diff and in code scanning, keyed to the flagged files. (Public repos, or private repos with GitHub Advanced Security.)
  • Merge gate — with baseline + fail-on-new, only files that got worse than the accepted baseline fail the check (exit code 3). On a pull request the baseline and any gate-policy file are read from the base branch, never from the PR: a change to either must land on the base branch first, in its own PR.

Notes

  • The license is verified locally on the runner; nothing leaves the machine. AI signals are pointers for review, not verdicts.
  • Generate a baseline once and commit it: codedelta-gui scan . --mode both --write-baseline codedelta-baseline.json -q
  • Default mode: churn_agent (churn + Agent Scan, no ML) is the ~90% case. mode: churn is pure measurement — it still posts the PR comment (churn totals, build-file alert); SARIF is skipped because churn has no findings to report. Switch to both to add the ML AI audit.

CodeDelta scan is not certified by GitHub. It is provided by a third-party and is governed by separate terms of service, privacy policy, and support documentation.

About

Measure churn and flag AI-generated / AI-agent code on every pull request
v2.2.0
Latest

CodeDelta scan is not certified by GitHub. It is provided by a third-party and is governed by separate terms of service, privacy policy, and support documentation.