ArchSetu Blog
Technical, engine-level writing - real formulas, real bugs we found and fixed, real numbers from running ArchSetu against large open-source codebases. No marketing case studies.
How the Health Score Is Actually Computed
The exact rule weights behind the single number on every report - and a real bug a 1,136-complexity function in the Linux kernel exposed.
Read postThe Heuristics Behind the Security Risk Scanner
What counts as a hardcoded secret or unsafe dynamic execution - and two real false-positive bugs found by testing against authelia and gitea.
Read postUndeclared Dependencies: The Bug That Hides Until a Lockfile Changes
Why an import that "just happens to work" is a ticking time bomb - and the bug that produced 15,886 false findings on rust-lang/rust.
Read postComing next
Building a 47-language call graph without an LLM
Why ArchSetu parses real syntax trees instead of asking a model to summarize your code, and what that trade-off costs.
Blast radius, explained with a real outage
How reverse-dependency tracing catches a break before a merge, not after a page.
Bus factor: the git-history metric most teams never compute
Ownership concentration and churn, and why it predicts risk better than commit count alone.
Why the same repo produces the same report, every time
A look at what "deterministic" actually means for a static analysis engine, and why that’s harder than it sounds.
Want to know when new posts go live? Join the ArchSetu community on WhatsApp.
