Technical Debt Calculator
Measure debt through change cost and release risk, not line count, and reduce the output to the first three cleanup priorities.
0 OSV · 0 SARIF · SBOM — · COVERAGE — · OUTDATED — · HOTSPOTS —
Coverage, outdated-dependency and git-hotspot evidence replace only their matching self-report dimensions. SBOM is inventory. OSV/SARIF risk pressure remains separate.
Open Evidence Lab →PDF / human · MD / repo · JSON / automation
Technical Debt Calculator
48/100 · self 48/100 · observed 0 · risk +0
Self-reported values remain visible. LCOV/Cobertura replaces only testCoverage, npm outdated replaces only outdatedDeps, and git churn hotspot evidence replaces only hotspots. OSV/SARIF risk pressure is added separately. SBOM is inventory; an outdated dependency is not automatically a vulnerability; hotspot classification is not proof of a defect.
Executive brief
Findings and decision points
Deploy friction
+9.6 self-reported pressure
Change hotspots
+9.0 self-reported pressure
Test confidence
+8.4 self-reported pressure
Documentation
+8.0 self-reported pressure
Dependencies
+7.5 self-reported pressure
Incident frequency
+5.0 self-reported pressure
Evidence ledger
User-reported operational metric.
User-reported operational metric.
User-reported operational metric.
User-reported operational metric.
User-reported operational metric.
User-reported operational metric.
Method, assumptions and boundaries
- —
- • Coverage describes only the files and test execution represented by the report; it does not prove test quality or production correctness.
- • npm outdated reports update state; being outdated alone is not a vulnerability or an automatic upgrade requirement.
- • Git hotspot count is a heuristic for files in the upper quartile of both change frequency and line churn within the imported history window; it is not proof of defects or architectural failure.
- • An SBOM is not a vulnerability scan. DORA and actual code-ownership signals are not yet used in this calculation.