Sign in

Source code analysis

Repository evidence without giving us access to the target's source: how the air-gapped extract works and what it produces.

Updated September 3, 2026
3 min read
analysis
api
security

Where the target agrees to it, the assessment can include evidence drawn from their repositories: contributors, commit history, dependencies, licenses and known vulnerabilities. In a project it lives under Evidence → Software Analysis, beside the documents and notes the rest of the assessment stands on.

We do not hold the source

This is the part worth understanding before you ask a target for it, because it is usually their first objection.

Analysis runs against an extract, produced in isolation from the platform. The extract contains the measurements — contributor statistics, commit metadata, dependency manifests, license findings, file and language counts — and the key extracted data is then handed into the project. Percomb does not clone the repository, does not need credentials to the target's systems, and does not store their source code.

A target that will not grant a third party live access to their repositories can usually still agree to this, which is why the assessment can reach the code at all.

What it produces

AreaEvidence
ContributorsWho commits, how often, and where knowledge is concentrated
ActivityCommit history over time, by area of the codebase
DependenciesWhat is used, how current it is, and its license
VulnerabilitiesKnown advisories against those dependencies, with detail
CompositionLanguages, size, test and documentation presence

Key person risk

The contributor data is what makes this finding evidenced rather than anecdotal: a component with a single maintainer and no second owner is visible in the commit history. Report it as key person risk and name the component and the dependency — never the developer slang for it, which does not belong in a document an investment committee reads.

Read the extract's date, not today's date

An extract is a snapshot. Every figure it produces is as of the extract date, and the report says so. "No commits in the last quarter" means no commits in the quarter before the extract — which may not be the quarter you are reading in. If the deal timeline has moved, take a fresh extract rather than aging the numbers in your head.

Availability

Source code analysis is part of the plans that include it, and requires the target's cooperation to produce the extract. Without it, the review areas that depend on code evidence rely on documents alone and say so.

Next

Was this article helpful?

Votes are read: an article that keeps failing gets rewritten.