Aliferous3/dev-ledger

An evolving ledger of code, commits, repositories, deployments, and the cumulative body of work behind them.

JavaScript

0

305 commits

updated Sep 29, 2026

See the code

See what people are saying

SourceMessageScoreDate

I wanted more than GitHub’s green squares, so I built Dev Ledger (r/SideProject)

**I built an open-source app that turns your GitHub history into a visual record of your work** I wanted something more useful than just the GitHub contribution graph, so I built **Dev Ledger**. It analyzes your GitHub history and shows things like: * source-code growth * activity over time *…

0

Sep 29, 2026

README

DEV LEDGER. Your GitHub history, made legible. Open source · Privacy-conscious · Read-only. v1.3.0 · AGPL-3.0-only

Live App · Documentation · Security · License

Dev Ledger product demo

What Dev Ledger measures

Dev Ledger connects through a GitHub App and builds a read-only analytical record from repositories the user explicitly authorizes.

MEASUREACTIVITYCODE
Net source growthActive daysLanguage composition
Additions & deletionsStreaks & extremesRepository history
ChurnCircadian patternsProject evolution
CommitsRhythm & milestonesLongitudinal change
SHAREHISTORYSYNC
Range-aware visual recordsMonths and years of developmentGitHub webhooks
Compact exportsChange over timeResumable history coverage
Selected-range contextLongitudinal patternsRate-limit-aware continuation

Privacy by design

[!IMPORTANT] Dev Ledger measures development activity without indexing repository source code.

Dev Ledger is intentionally narrower than a source-code indexing product.

Dev Ledger usesDev Ledger does not persist
Repository metadata needed for product metricsRepository source code
Git-derived activity dataCommit messages
Language statisticsPull-request titles
Computed development historyGitHub email addresses
Synchronization stateGitHub OAuth access tokens
GitHub App installation tokens
Raw webhook payload bodies

The product stores only the GitHub-derived metadata needed to compute its metrics and maintain synchronization. Repository permissions are read-only.

The public Security & Privacy Trust Record documents the current implementation and security boundaries in detail.

Architecture

%%{init: {'theme':'base','themeVariables':{'primaryColor':'#0e0f0e','primaryTextColor':'#e8e6e0','primaryBorderColor':'#4a4945','lineColor':'#8a877f','edgeLabelBackground':'#131413','fontFamily':'SFMono-Regular, Menlo, monospace'}}}%%
flowchart LR
  B[Browser] -->|GitHub OAuth| G[GitHub]
  B -->|same-origin HTTPS| D[Dev Ledger / Vercel]
  G -->|GitHub App API + signed webhooks| D
  D -->|server-side only| S[(Supabase Postgres)]
  D -->|allowlisted product events| P[PostHog EU]
  B -->|cookieless traffic measurement| A[Vercel Web Analytics]

The frontend is React + Vite. API routes run as Vercel Functions. GitHub App ingestion writes normalized metadata to Supabase Postgres. The browser never receives a database service credential.

Read the architecture documentation →

Technology

FrontendReact 19 · TypeScript · Vite 8
InterfaceTailwind CSS 4 · Framer Motion
IdentityGitHub OAuth · GitHub App
ComputeVercel Functions
DataSupabase Postgres
Product analyticsPostHog · custom-event-only
Traffic analyticsVercel Web Analytics
CIGitHub Actions
Security checksTypecheck · tests · npm audit · gitleaks · artifact scan · recovery drill

Quick start

Requirements: Node.js 24 · npm · Git

git clone https://github.com/Aliferous3/dev-ledger.git
cd dev-ledger
npm ci
npm run dev

Plain Vite runs the UI with synthetic development fixtures. Production builds replace the fixture barrel with an inert stub, so fixture telemetry does not ship to users.

Run the full GitHub + Supabase stack

Install the Vercel CLI, copy the environment template, and populate your own GitHub App and Supabase values:

cp .env.example .env.local
vercel dev

Never commit .env.local, private keys, database dumps, or provider credentials.

Run the verification suite

Run the same core checks used by CI:

npm run build
npm run typecheck
npm test
npm audit --audit-level=moderate

The GitHub Actions security gate also scans git history with gitleaks and runs a synthetic Postgres 17 migrate → backup → restore verification.

Database operations

Migrations live in migrations/ and are the schema source of truth.

Postgres 17 or Docker is required only for local recovery-drill work.

npm run db:migrate
npm run db:backup
npm run db:drill

The recovery drill refuses non-local database targets. Production recovery remains an operator-controlled procedure documented in docs/disaster-recovery.md.

Security

[!CAUTION] Do not open a public issue for a vulnerability. Follow SECURITY.md for private reporting.

The repository CI is intentionally fail-closed around common release risks: dependency audit, secret scanning, browser/server environment separation, built-artifact inspection, strict typechecking, and a synthetic recovery drill.

Repository guides

Status

Current application version: v1.3.0

Dev Ledger is under active development. Metrics are derived from available GitHub history and can be affected by repository deletion, force-pushes, attribution gaps, API limits, and disconnected repositories.

License

Dev Ledger is open source under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). See LICENSE.

The AGPL permits use, modification, redistribution, and commercial use subject to its terms, including source-availability obligations for qualifying modified network deployments. The Dev Ledger name, logo, and distinctive branding are addressed separately in TRADEMARKS.md.

Contributions are welcome under CONTRIBUTING.md and the Contributor License Agreement.


Dev Ledger · Your GitHub history, made legible.

Live App · Privacy Policy · Terms of Service

analytics
developer-analytics
developer-tools
git
github
github-analytics
open-source
react
supabase
typescript
vercel

Aliferous3/dev-ledger

An evolving ledger of code, commits, repositories, deployments, and the cumulative body of work behind them.

JavaScript

0

305 commits

updated Sep 29, 2026

See the code

See what people are saying

SourceMessageScoreDate

I wanted more than GitHub’s green squares, so I built Dev Ledger (r/SideProject)

**I built an open-source app that turns your GitHub history into a visual record of your work** I wanted something more useful than just the GitHub contribution graph, so I built **Dev Ledger**. It analyzes your GitHub history and shows things like: * source-code growth * activity over time *…

0

Sep 29, 2026

README

DEV LEDGER. Your GitHub history, made legible. Open source · Privacy-conscious · Read-only. v1.3.0 · AGPL-3.0-only

Live App · Documentation · Security · License

Dev Ledger product demo

What Dev Ledger measures

Dev Ledger connects through a GitHub App and builds a read-only analytical record from repositories the user explicitly authorizes.

MEASUREACTIVITYCODE
Net source growthActive daysLanguage composition
Additions & deletionsStreaks & extremesRepository history
ChurnCircadian patternsProject evolution
CommitsRhythm & milestonesLongitudinal change
SHAREHISTORYSYNC
Range-aware visual recordsMonths and years of developmentGitHub webhooks
Compact exportsChange over timeResumable history coverage
Selected-range contextLongitudinal patternsRate-limit-aware continuation

Privacy by design

[!IMPORTANT] Dev Ledger measures development activity without indexing repository source code.

Dev Ledger is intentionally narrower than a source-code indexing product.

Dev Ledger usesDev Ledger does not persist
Repository metadata needed for product metricsRepository source code
Git-derived activity dataCommit messages
Language statisticsPull-request titles
Computed development historyGitHub email addresses
Synchronization stateGitHub OAuth access tokens
GitHub App installation tokens
Raw webhook payload bodies

The product stores only the GitHub-derived metadata needed to compute its metrics and maintain synchronization. Repository permissions are read-only.

The public Security & Privacy Trust Record documents the current implementation and security boundaries in detail.

Architecture

%%{init: {'theme':'base','themeVariables':{'primaryColor':'#0e0f0e','primaryTextColor':'#e8e6e0','primaryBorderColor':'#4a4945','lineColor':'#8a877f','edgeLabelBackground':'#131413','fontFamily':'SFMono-Regular, Menlo, monospace'}}}%%
flowchart LR
  B[Browser] -->|GitHub OAuth| G[GitHub]
  B -->|same-origin HTTPS| D[Dev Ledger / Vercel]
  G -->|GitHub App API + signed webhooks| D
  D -->|server-side only| S[(Supabase Postgres)]
  D -->|allowlisted product events| P[PostHog EU]
  B -->|cookieless traffic measurement| A[Vercel Web Analytics]

The frontend is React + Vite. API routes run as Vercel Functions. GitHub App ingestion writes normalized metadata to Supabase Postgres. The browser never receives a database service credential.

Read the architecture documentation →

Technology

FrontendReact 19 · TypeScript · Vite 8
InterfaceTailwind CSS 4 · Framer Motion
IdentityGitHub OAuth · GitHub App
ComputeVercel Functions
DataSupabase Postgres
Product analyticsPostHog · custom-event-only
Traffic analyticsVercel Web Analytics
CIGitHub Actions
Security checksTypecheck · tests · npm audit · gitleaks · artifact scan · recovery drill

Quick start

Requirements: Node.js 24 · npm · Git

git clone https://github.com/Aliferous3/dev-ledger.git
cd dev-ledger
npm ci
npm run dev

Plain Vite runs the UI with synthetic development fixtures. Production builds replace the fixture barrel with an inert stub, so fixture telemetry does not ship to users.

Run the full GitHub + Supabase stack

Install the Vercel CLI, copy the environment template, and populate your own GitHub App and Supabase values:

cp .env.example .env.local
vercel dev

Never commit .env.local, private keys, database dumps, or provider credentials.

Run the verification suite

Run the same core checks used by CI:

npm run build
npm run typecheck
npm test
npm audit --audit-level=moderate

The GitHub Actions security gate also scans git history with gitleaks and runs a synthetic Postgres 17 migrate → backup → restore verification.

Database operations

Migrations live in migrations/ and are the schema source of truth.

Postgres 17 or Docker is required only for local recovery-drill work.

npm run db:migrate
npm run db:backup
npm run db:drill

The recovery drill refuses non-local database targets. Production recovery remains an operator-controlled procedure documented in docs/disaster-recovery.md.

Security

[!CAUTION] Do not open a public issue for a vulnerability. Follow SECURITY.md for private reporting.

The repository CI is intentionally fail-closed around common release risks: dependency audit, secret scanning, browser/server environment separation, built-artifact inspection, strict typechecking, and a synthetic recovery drill.

Repository guides

Status

Current application version: v1.3.0

Dev Ledger is under active development. Metrics are derived from available GitHub history and can be affected by repository deletion, force-pushes, attribution gaps, API limits, and disconnected repositories.

License

Dev Ledger is open source under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). See LICENSE.

The AGPL permits use, modification, redistribution, and commercial use subject to its terms, including source-availability obligations for qualifying modified network deployments. The Dev Ledger name, logo, and distinctive branding are addressed separately in TRADEMARKS.md.

Contributions are welcome under CONTRIBUTING.md and the Contributor License Agreement.


Dev Ledger · Your GitHub history, made legible.

Live App · Privacy Policy · Terms of Service

analytics
developer-analytics
developer-tools
git
github
github-analytics
open-source
react
supabase
typescript
vercel

Languages

JavaScript

53.3%

TypeScript

44.3%

CSS

1.5%