An evolving ledger of code, commits, repositories, deployments, and the cumulative body of work behind them.
See the codeLive App · Documentation · Security · License

Dev Ledger connects through a GitHub App and builds a read-only analytical record from repositories the user explicitly authorizes.
MEASURE | ACTIVITY | CODE |
|---|---|---|
| Net source growth | Active days | Language composition |
| Additions & deletions | Streaks & extremes | Repository history |
| Churn | Circadian patterns | Project evolution |
| Commits | Rhythm & milestones | Longitudinal change |
SHARE | HISTORY | SYNC |
|---|---|---|
| Range-aware visual records | Months and years of development | GitHub webhooks |
| Compact exports | Change over time | Resumable history coverage |
| Selected-range context | Longitudinal patterns | Rate-limit-aware continuation |
[!IMPORTANT] Dev Ledger measures development activity without indexing repository source code.
Dev Ledger is intentionally narrower than a source-code indexing product.
| Dev Ledger uses | Dev Ledger does not persist |
|---|---|
| Repository metadata needed for product metrics | Repository source code |
| Git-derived activity data | Commit messages |
| Language statistics | Pull-request titles |
| Computed development history | GitHub email addresses |
| Synchronization state | GitHub OAuth access tokens |
| GitHub App installation tokens | |
| Raw webhook payload bodies |
The product stores only the GitHub-derived metadata needed to compute its metrics and maintain synchronization. Repository permissions are read-only.
The public Security & Privacy Trust Record documents the current implementation and security boundaries in detail.
%%{init: {'theme':'base','themeVariables':{'primaryColor':'#0e0f0e','primaryTextColor':'#e8e6e0','primaryBorderColor':'#4a4945','lineColor':'#8a877f','edgeLabelBackground':'#131413','fontFamily':'SFMono-Regular, Menlo, monospace'}}}%%
flowchart LR
B[Browser] -->|GitHub OAuth| G[GitHub]
B -->|same-origin HTTPS| D[Dev Ledger / Vercel]
G -->|GitHub App API + signed webhooks| D
D -->|server-side only| S[(Supabase Postgres)]
D -->|allowlisted product events| P[PostHog EU]
B -->|cookieless traffic measurement| A[Vercel Web Analytics]
The frontend is React + Vite. API routes run as Vercel Functions. GitHub App ingestion writes normalized metadata to Supabase Postgres. The browser never receives a database service credential.
Read the architecture documentation →
Frontend | React 19 · TypeScript · Vite 8 |
Interface | Tailwind CSS 4 · Framer Motion |
Identity | GitHub OAuth · GitHub App |
Compute | Vercel Functions |
Data | Supabase Postgres |
Product analytics | PostHog · custom-event-only |
Traffic analytics | Vercel Web Analytics |
CI | GitHub Actions |
Security checks | Typecheck · tests · npm audit · gitleaks · artifact scan · recovery drill |
Requirements: Node.js 24 · npm · Git
git clone https://github.com/Aliferous3/dev-ledger.git
cd dev-ledger
npm ci
npm run dev
Plain Vite runs the UI with synthetic development fixtures. Production builds replace the fixture barrel with an inert stub, so fixture telemetry does not ship to users.
Install the Vercel CLI, copy the environment template, and populate your own GitHub App and Supabase values:
cp .env.example .env.local
vercel dev
Never commit .env.local, private keys, database dumps, or provider credentials.
Run the same core checks used by CI:
npm run build
npm run typecheck
npm test
npm audit --audit-level=moderate
The GitHub Actions security gate also scans git history with gitleaks and runs a synthetic Postgres 17 migrate → backup → restore verification.
Migrations live in migrations/ and are the schema source of truth.
Postgres 17 or Docker is required only for local recovery-drill work.
npm run db:migrate
npm run db:backup
npm run db:drill
The recovery drill refuses non-local database targets. Production recovery remains an operator-controlled procedure documented in docs/disaster-recovery.md.
[!CAUTION] Do not open a public issue for a vulnerability. Follow SECURITY.md for private reporting.
The repository CI is intentionally fail-closed around common release risks: dependency audit, secret scanning, browser/server environment separation, built-artifact inspection, strict typechecking, and a synthetic recovery drill.
Current application version: v1.3.0
Dev Ledger is under active development. Metrics are derived from available GitHub history and can be affected by repository deletion, force-pushes, attribution gaps, API limits, and disconnected repositories.
Dev Ledger is open source under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). See LICENSE.
The AGPL permits use, modification, redistribution, and commercial use subject to its terms, including source-availability obligations for qualifying modified network deployments. The Dev Ledger name, logo, and distinctive branding are addressed separately in TRADEMARKS.md.
Contributions are welcome under CONTRIBUTING.md and the Contributor License Agreement.
Dev Ledger · Your GitHub history, made legible.
JavaScript
53.3%
TypeScript
44.3%
CSS
1.5%
An evolving ledger of code, commits, repositories, deployments, and the cumulative body of work behind them.
See the codeLive App · Documentation · Security · License

Dev Ledger connects through a GitHub App and builds a read-only analytical record from repositories the user explicitly authorizes.
MEASURE | ACTIVITY | CODE |
|---|---|---|
| Net source growth | Active days | Language composition |
| Additions & deletions | Streaks & extremes | Repository history |
| Churn | Circadian patterns | Project evolution |
| Commits | Rhythm & milestones | Longitudinal change |
SHARE | HISTORY | SYNC |
|---|---|---|
| Range-aware visual records | Months and years of development | GitHub webhooks |
| Compact exports | Change over time | Resumable history coverage |
| Selected-range context | Longitudinal patterns | Rate-limit-aware continuation |
[!IMPORTANT] Dev Ledger measures development activity without indexing repository source code.
Dev Ledger is intentionally narrower than a source-code indexing product.
| Dev Ledger uses | Dev Ledger does not persist |
|---|---|
| Repository metadata needed for product metrics | Repository source code |
| Git-derived activity data | Commit messages |
| Language statistics | Pull-request titles |
| Computed development history | GitHub email addresses |
| Synchronization state | GitHub OAuth access tokens |
| GitHub App installation tokens | |
| Raw webhook payload bodies |
The product stores only the GitHub-derived metadata needed to compute its metrics and maintain synchronization. Repository permissions are read-only.
The public Security & Privacy Trust Record documents the current implementation and security boundaries in detail.
%%{init: {'theme':'base','themeVariables':{'primaryColor':'#0e0f0e','primaryTextColor':'#e8e6e0','primaryBorderColor':'#4a4945','lineColor':'#8a877f','edgeLabelBackground':'#131413','fontFamily':'SFMono-Regular, Menlo, monospace'}}}%%
flowchart LR
B[Browser] -->|GitHub OAuth| G[GitHub]
B -->|same-origin HTTPS| D[Dev Ledger / Vercel]
G -->|GitHub App API + signed webhooks| D
D -->|server-side only| S[(Supabase Postgres)]
D -->|allowlisted product events| P[PostHog EU]
B -->|cookieless traffic measurement| A[Vercel Web Analytics]
The frontend is React + Vite. API routes run as Vercel Functions. GitHub App ingestion writes normalized metadata to Supabase Postgres. The browser never receives a database service credential.
Read the architecture documentation →
Frontend | React 19 · TypeScript · Vite 8 |
Interface | Tailwind CSS 4 · Framer Motion |
Identity | GitHub OAuth · GitHub App |
Compute | Vercel Functions |
Data | Supabase Postgres |
Product analytics | PostHog · custom-event-only |
Traffic analytics | Vercel Web Analytics |
CI | GitHub Actions |
Security checks | Typecheck · tests · npm audit · gitleaks · artifact scan · recovery drill |
Requirements: Node.js 24 · npm · Git
git clone https://github.com/Aliferous3/dev-ledger.git
cd dev-ledger
npm ci
npm run dev
Plain Vite runs the UI with synthetic development fixtures. Production builds replace the fixture barrel with an inert stub, so fixture telemetry does not ship to users.
Install the Vercel CLI, copy the environment template, and populate your own GitHub App and Supabase values:
cp .env.example .env.local
vercel dev
Never commit .env.local, private keys, database dumps, or provider credentials.
Run the same core checks used by CI:
npm run build
npm run typecheck
npm test
npm audit --audit-level=moderate
The GitHub Actions security gate also scans git history with gitleaks and runs a synthetic Postgres 17 migrate → backup → restore verification.
Migrations live in migrations/ and are the schema source of truth.
Postgres 17 or Docker is required only for local recovery-drill work.
npm run db:migrate
npm run db:backup
npm run db:drill
The recovery drill refuses non-local database targets. Production recovery remains an operator-controlled procedure documented in docs/disaster-recovery.md.
[!CAUTION] Do not open a public issue for a vulnerability. Follow SECURITY.md for private reporting.
The repository CI is intentionally fail-closed around common release risks: dependency audit, secret scanning, browser/server environment separation, built-artifact inspection, strict typechecking, and a synthetic recovery drill.
Current application version: v1.3.0
Dev Ledger is under active development. Metrics are derived from available GitHub history and can be affected by repository deletion, force-pushes, attribution gaps, API limits, and disconnected repositories.
Dev Ledger is open source under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). See LICENSE.
The AGPL permits use, modification, redistribution, and commercial use subject to its terms, including source-availability obligations for qualifying modified network deployments. The Dev Ledger name, logo, and distinctive branding are addressed separately in TRADEMARKS.md.
Contributions are welcome under CONTRIBUTING.md and the Contributor License Agreement.
Dev Ledger · Your GitHub history, made legible.
JavaScript
53.3%
TypeScript
44.3%
CSS
1.5%