Date: 2026-08-26 · Audited revision: ec4c481 (main)
Scope: whole repository, 102 tracked files — 75 production, 27 tests (audited as meta), 0 vendored.
Coverage: 47/47 lib/ files read line by line · exe/, bench/, examples/ (3/3) · both GitHub workflows · all 5 gemfiles/ · 12 of the 14 root files.
Not read, no audit surface: LICENSE.txt, CODE_OF_CONDUCT.md. README.md was read selectively (~330 lines out of 1060: CLI, Docker, TLS, requirements, examples, authentication sections), not in full — the documentation-drift findings cover those sections only.
bin/appraisal, bin/rubocop, bin/stree are Bundler-generated binstubs (role: generated); only bin/rake was read.
86 findings: 4 CRITICAL, 22 HIGH, 38 MEDIUM, 17 LOW, 5 NIT.