Generated documents — no filler
Experimental report commands can write a report to docs/vectalon/ in your project. Below are all 44 documents — committed samples generated against the demo app and rendered exactly as written. Verdicts included, warts included, honest “nothing to fix” verdicts included. Regenerate any of them with the command shown.
PR Review — working-tree
- Verdict: changes-requested
- Files: 3 | Added lines: 11
- Findings: 5 (0 error(s), 0 warning(s), 2 info)
apps/website/app/agents/page.tsx
5 added line(s)
- [info] magic-number (line 204) — Extract magic numbers into named constants.
- [info] standard-tests (line 200) — Project standard (Unit tests: Jest + React Native Testing Library): jest / @testing-library/react-native present. — add or update tests for this change.
- LLM: changes-requested — The
classNameprop in thedivelement is not in kebab-case, which is a best practice in React Native. - [warning] kebab-case-rule-id (line 12) — The
classNameprop in thedivelement is not in kebab-case, which is a best practice in React Native. Suggestion: ChangeclassNametoclassName={styles.myClassName}.
apps/website/app/page.tsx
5 added line(s)
- [info] magic-number (line 62) — Extract magic numbers into named constants.
- [info] standard-tests (line 62) — Project standard (Unit tests: Jest + React Native Testing Library): jest / @testing-library/react-native present. — add or update tests for this change.
- LLM: changes-requested — The code contains a typo in the
aproperty of the first object in the array. - [error] jsx-no-typography (line 12) — The text 'The optional model-driven agent does — but the 40 deterministic commands (review, security, SOC 2, GitHub PR triage, incident command, …) need no model at all. They run offline with a report and a verdict, zero model calls, free on every tier. Deterministic means reproducible, not static: every run re-scans your project’s current state, so the results are as fresh as your last command.' contains a typo in the
aproperty. Suggestion: Correct the typo by replacing '—' with '—'
apps/website/lib/nav.ts
1 added line(s)
- [info] standard-tests (line 6) — Project standard (Unit tests: Jest + React Native Testing Library): jest / @testing-library/react-native present. — add or update tests for this change.
- LLM: approved — The
hrefprop in the navigation item is missing a key. (unsupported findings cleared by code verification)
vectalon arch — Architecture Review
- Verdict: approved
- 6 source files in src/ (/Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app)
- Findings: 0 (0 error(s), 0 warning(s), 0 info)
Modules
| Module | Files | Fan-in | Fan-out | External packages |
|---|---|---|---|---|
| __tests__ | 3 | 0 | 3 | @testing-library/react-native, react |
| hooks | 1 | 2 | 1 | react |
| screens | 1 | 1 | 1 | react, react-native |
| services | 1 | 2 | 0 | — |
Findings
No architecture issues found — the module graph is clean.
vectalon sec — Security Review
- Verdict: needs-attention
- 24 files scanned in /Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app
- Findings: 19 (0 error(s), 8 warning(s), 11 info)
Dependency audit
- 19 advisory(ies): 0 critical, 8 high, 11 moderate, 0 low
| Package | Severity | Direct | Advisories |
|---|---|---|---|
| @react-native/community-cli-plugin | high | no | 2 |
| @testing-library/react-native | high | yes | 1 |
| image-size | high | no | 2 |
| metro | high | no | 3 |
| metro-config | high | no | 1 |
| metro-transform-worker | high | no | 1 |
| postcss | high | no | 4 |
| react-native | high | yes | 1 |
| @expo/cli | moderate | no | 4 |
| @expo/config | moderate | no | 1 |
| @expo/config-plugins | moderate | no | 1 |
| @expo/metro-config | moderate | no | 2 |
| @expo/prebuild-config | moderate | no | 2 |
| expo | moderate | yes | 6 |
| expo-asset | moderate | no | 1 |
| expo-constants | moderate | no | 1 |
| jest-expo | moderate | yes | 1 |
| uuid | moderate | no | 1 |
| xcode | moderate | no | 1 |
Top recommendations
- @react-native/community-cli-plugin has 2 advisory(ies) at high severity (transitive) — Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range. (package.json:0)
Findings
[WARNING] dependency-vulnerability — package.json
@react-native/community-cli-plugin has 2 advisory(ies) at high severity (transitive)
- Target:
@react-native/community-cli-plugin· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[WARNING] dependency-vulnerability — package.json
@testing-library/react-native has 1 advisory(ies) at high severity
- Target:
@testing-library/react-native· deps - Fix: Run npm audit fix — keep dependencies patched or pin to a fixed range.
[WARNING] dependency-vulnerability — package.json
image-size has 2 advisory(ies) at high severity (transitive)
- Target:
image-size· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[WARNING] dependency-vulnerability — package.json
metro has 3 advisory(ies) at high severity (transitive)
- Target:
metro· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[WARNING] dependency-vulnerability — package.json
metro-config has 1 advisory(ies) at high severity (transitive)
- Target:
metro-config· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[WARNING] dependency-vulnerability — package.json
metro-transform-worker has 1 advisory(ies) at high severity (transitive)
- Target:
metro-transform-worker· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[WARNING] dependency-vulnerability — package.json
postcss has 4 advisory(ies) at high severity (transitive)
- Target:
postcss· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[WARNING] dependency-vulnerability — package.json
react-native has 1 advisory(ies) at high severity
- Target:
react-native· deps - Fix: Run npm audit fix — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
@expo/cli has 4 advisory(ies) at moderate severity (transitive)
- Target:
@expo/cli· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
@expo/config has 1 advisory(ies) at moderate severity (transitive)
- Target:
@expo/config· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
@expo/config-plugins has 1 advisory(ies) at moderate severity (transitive)
- Target:
@expo/config-plugins· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
@expo/metro-config has 2 advisory(ies) at moderate severity (transitive)
- Target:
@expo/metro-config· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
@expo/prebuild-config has 2 advisory(ies) at moderate severity (transitive)
- Target:
@expo/prebuild-config· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
expo has 6 advisory(ies) at moderate severity
- Target:
expo· deps - Fix: Run npm audit fix — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
expo-asset has 1 advisory(ies) at moderate severity (transitive)
- Target:
expo-asset· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
expo-constants has 1 advisory(ies) at moderate severity (transitive)
- Target:
expo-constants· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
jest-expo has 1 advisory(ies) at moderate severity
- Target:
jest-expo· deps - Fix: Run npm audit fix — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
uuid has 1 advisory(ies) at moderate severity (transitive)
- Target:
uuid· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
[INFO] dependency-vulnerability — package.json
xcode has 1 advisory(ies) at moderate severity (transitive)
- Target:
xcode· deps - Fix: Run npm audit fix and update the direct dependency that pulls it in — keep dependencies patched or pin to a fixed range.
vectalon build-fix — Build Fix Diagnosis
- Build system: metro (auto-detected)
- Verdict: changes-requested
- Findings: 3 (1 error(s), 2 warning(s))
Fix plan
- Module resolution failure: The import path is wrong or the package is missing: check the specifier (extension, /index) in the failing file,
npm installthe package, add the directory towatchFoldersin metro.config.js for monorepos, thennpx react-native start --reset-cache. - Asset resolution failure: The referenced image/font file does not exist at the given path (case matters): fix the require/import path, verify the file is committed, and for custom fonts check the fontFamily name matches the file registered in the app config.
- Syntax / transform error: The failing file does not parse under Metro's Babel pipeline: fix the syntax, or align the transform — check babel.config.js presets (babel-preset-expo / @react-native/babel-preset) and that the file extension matches its syntax (TS in .ts/.tsx, JSX in .jsx/.tsx).
Findings
[ERROR] module-resolution — log line 1
Root cause: Module resolution failure at log line 1.
- Class: Module resolution failure · metro
- Fix: The import path is wrong or the package is missing: check the specifier (extension, /index) in the failing file,
npm installthe package, add the directory towatchFoldersin metro.config.js for monorepos, thennpx react-native start --reset-cache.
[WARNING] asset-not-found — log line 10
Corroborating failure: Asset resolution failure at log line 10.
- Class: Asset resolution failure · metro
- Fix: The referenced image/font file does not exist at the given path (case matters): fix the require/import path, verify the file is committed, and for custom fonts check the fontFamily name matches the file registered in the app config.
[WARNING] syntax-error — log line 12
Corroborating failure: Syntax / transform error at log line 12.
- Class: Syntax / transform error · metro
- Fix: The failing file does not parse under Metro's Babel pipeline: fix the syntax, or align the transform — check babel.config.js presets (babel-preset-expo / @react-native/babel-preset) and that the file extension matches its syntax (TS in .ts/.tsx, JSX in .jsx/.tsx).
Log evidence (tail)
Metro has encountered an error: Unable to resolve module `./services/CreateLoginScreenEmailPasswordApi` from `src/hooks/useCreateLoginScreenEmailPassword.ts`.
None of these files exist:
* src/services/CreateLoginScreenEmailPasswordApi(.native|.ios.ts|.native.ts|.ts|.tsx)
* src/services/CreateLoginScreenEmailPasswordApi/index(.native|.ios.ts|.native.ts|.ts|.tsx)
1 | import { useState, useCallback } from 'react';
2 | import { createLoginScreenEmailPasswordApi } from '../services/CreateLoginScreenEmailPasswordApi';
> 3 | import { createLoginScreenEmailPasswordApi } from '../services/CreateLoginScreenEmailPasswordApi';
4 |
error: bundling failed: Error: Unable to resolve module `../services/CreateLoginScreenEmailPasswordApi` from `src/hooks/useCreateLoginScreenEmailPassword.ts`
Metro has encountered an error: Invalid asset name: `./assets/logo.png`
(node:1234) [DEP0040] DeprecationWarning
Failed to construct transformer: TransformError SyntaxError: /src/screens/CreateLoginScreenEmailPasswordScreen.tsx: Unexpected token
info Metro waiting for the packager on port 8081, press Ctrl-C to exitvectalon test-repair — Test Fix Diagnosis
- Test framework: jest (auto-detected)
- Verdict: changes-requested
- Findings: 2 (1 error(s), 1 warning(s))
Fix plan
- Assertion failure: The assertion failed — read the Expected vs Received diff at the failing line: the code under test returns something other than the test expects. Fix the implementation, the fixture, or the expectation (one of the three is wrong).
- Missing global in test environment: The test references a global Jest does not provide (fetch, localStorage, matchMedia…): define it in a setup file (jest.setup) or mock it per test with jest.fn().
Findings
[ERROR] assertion-failure — log line 4
Root cause: Assertion failure at log line 4.
- Class: Assertion failure · jest
- Fix: The assertion failed — read the Expected vs Received diff at the failing line: the code under test returns something other than the test expects. Fix the implementation, the fixture, or the expectation (one of the three is wrong).
[WARNING] missing-global — log line 13
Corroborating failure: Missing global in test environment at log line 13.
- Class: Missing global in test environment · jest
- Fix: The test references a global Jest does not provide (fetch, localStorage, matchMedia…): define it in a setup file (jest.setup) or mock it per test with jest.fn().
Log evidence (tail)
FAIL src/hooks/__tests__/useCreateLoginScreenEmailPassword.test.ts
● CreateLoginScreenEmailPassword hook › run() resolves data
expect(received).toBe(expected) // Object.is equality
Expected: "login-created"
Received: null
at Object.<anonymous> (src/hooks/__tests__/useCreateLoginScreenEmailPassword.test.ts:24:27)
● CreateLoginScreenEmailPassword hook › run() surfaces errors
ReferenceError: fetch is not defined
at src/services/CreateLoginScreenEmailPasswordApi.ts:18:12
Tests: 1 failed, 1 passed, 2 total
Test Suites: 1 failed, 1 totalvectalon refactor — Refactor Opportunities
- Verdict: needs-attention
- 11 source files scanned in /Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app
- Findings: 3 (1 warning(s), 2 info)
Top opportunities
- Import React (from react) is never used — Remove the React specifier — dead imports confuse readers and trip noUnusedLocals in strict TS projects. (src/__tests__/CreateLoginScreenEmailPassword.tsx:4)
- console.log left in source — Remove it or route through a logger (console.warn/error for real problems) — stray logs leak state to production consoles. (gen-fixtures.js:39)
- String "src/screens/LoginScreen.tsx" is repeated 4 times — Hoist it to a named constant (or an i18n key) so the text and its changes live in one place. (gen-fixtures.js:15)
Findings
[WARNING] unused-import — src/__tests__/CreateLoginScreenEmailPassword.tsx:4
Import React (from react) is never used
- Target:
React· dead-code - Refactor: Remove the React specifier — dead imports confuse readers and trip noUnusedLocals in strict TS projects.
[INFO] console-log — gen-fixtures.js:39
console.log left in source
- Target:
console.log· logging - Refactor: Remove it or route through a logger (console.warn/error for real problems) — stray logs leak state to production consoles.
[INFO] duplicated-string — gen-fixtures.js:15
String "src/screens/LoginScreen.tsx" is repeated 4 times
- Target:
src/screens/LoginScreen.tsx· duplication - Refactor: Hoist it to a named constant (or an i18n key) so the text and its changes live in one place.
vectalon deps — Dependency Upgrade Plan
- Verdict: needs-attention
- 18 direct dependencies in /Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app
- Findings: 12 (0 error(s), 12 warning(s), 0 info)
Dependency audit
- 19 advisory(ies): 0 critical, 8 high
Top upgrade paths
- @vectalon-dev/telemetry, @vectalon-dev/core, @vectalon-dev/rn, @vectalon-dev/website declare different versions of @types/node (^26.1.2 vs ^20.14.0). — Align to one version at the workspace root (or one catalog) so native builds resolve a single copy — upgrade the older holders to the newest range.
- @vectalon-dev/telemetry, @vectalon-dev/core, @vectalon-dev/rn, @vectalon-dev/website declare different versions of typescript (^5.4.0 vs ^5.5.0). — Align to one version at the workspace root (or one catalog) so native builds resolve a single copy — upgrade the older holders to the newest range.
- @vectalon-dev/website, @vectalon-dev/rn declare different versions of @vectalon-dev/core (workspace:* vs workspace:^). — Align to one version at the workspace root (or one catalog) so native builds resolve a single copy — upgrade the older holders to the newest range.
Findings
[WARNING] duplicate--types-node — @types/node (^26.1.2 vs ^20.14.0)
@vectalon-dev/telemetry, @vectalon-dev/core, @vectalon-dev/rn, @vectalon-dev/website declare different versions of @types/node (^26.1.2 vs ^20.14.0).
- Category: duplicates
- Upgrade path: Align to one version at the workspace root (or one catalog) so native builds resolve a single copy — upgrade the older holders to the newest range.
[WARNING] duplicate-typescript — typescript (^5.4.0 vs ^5.5.0)
@vectalon-dev/telemetry, @vectalon-dev/core, @vectalon-dev/rn, @vectalon-dev/website declare different versions of typescript (^5.4.0 vs ^5.5.0).
- Category: duplicates
- Upgrade path: Align to one version at the workspace root (or one catalog) so native builds resolve a single copy — upgrade the older holders to the newest range.
[WARNING] duplicate--vectalon-dev-core — @vectalon-dev/core (workspace:* vs workspace:^)
@vectalon-dev/website, @vectalon-dev/rn declare different versions of @vectalon-dev/core (workspace:* vs workspace:^).
- Category: duplicates
- Upgrade path: Align to one version at the workspace root (or one catalog) so native builds resolve a single copy — upgrade the older holders to the newest range.
[WARNING] duplicate-ts-jest — ts-jest (^29.4.12 vs ^29.1.0)
@vectalon-dev/website, @vectalon-dev/core, @vectalon-dev/rn declare different versions of ts-jest (^29.4.12 vs ^29.1.0).
- Category: duplicates
- Upgrade path: Align to one version at the workspace root (or one catalog) so native builds resolve a single copy — upgrade the older holders to the newest range.
[WARNING] vulnerability — @react-native/community-cli-plugin (declared range)
@react-native/community-cli-plugin has a high advisory (transitive).
- Category: vulnerability
- Upgrade path: Run npm audit fix and upgrade the direct dependency that pulls it in — then re-run this scan to confirm the tree is clean.
[WARNING] vulnerability — @testing-library/react-native (declared range)
@testing-library/react-native has a high advisory.
- Category: vulnerability
- Upgrade path: Run npm audit fix — then re-run this scan to confirm the tree is clean.
[WARNING] vulnerability — image-size (declared range)
image-size has a high advisory (transitive).
- Category: vulnerability
- Upgrade path: Run npm audit fix and upgrade the direct dependency that pulls it in — then re-run this scan to confirm the tree is clean.
[WARNING] vulnerability — metro (declared range)
metro has a high advisory (transitive).
- Category: vulnerability
- Upgrade path: Run npm audit fix and upgrade the direct dependency that pulls it in — then re-run this scan to confirm the tree is clean.
[WARNING] vulnerability — metro-config (declared range)
metro-config has a high advisory (transitive).
- Category: vulnerability
- Upgrade path: Run npm audit fix and upgrade the direct dependency that pulls it in — then re-run this scan to confirm the tree is clean.
[WARNING] vulnerability — metro-transform-worker (declared range)
metro-transform-worker has a high advisory (transitive).
- Category: vulnerability
- Upgrade path: Run npm audit fix and upgrade the direct dependency that pulls it in — then re-run this scan to confirm the tree is clean.
[WARNING] vulnerability — postcss (declared range)
postcss has a high advisory (transitive).
- Category: vulnerability
- Upgrade path: Run npm audit fix and upgrade the direct dependency that pulls it in — then re-run this scan to confirm the tree is clean.
[WARNING] vulnerability — react-native (declared range)
react-native has a high advisory.
- Category: vulnerability
- Upgrade path: Run npm audit fix — then re-run this scan to confirm the tree is clean.
vectalon a11y — Accessibility Review
- Verdict: approved
- 3 component files scanned in /Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app
- Findings: 0 (0 error(s), 0 warning(s))
Findings
No accessibility issues found — the component tree is screen-reader friendly.
vectalon release-ready — Release Readiness
- Verdict: changes-requested
- Version: 1.0.0 | Last tag: rn-v0.7.0-core-v0.1.0
- Checks: 8 (1 error(s), 3 warning(s), 4 info)
Before you ship
- package.json version 1.0.0 is not newer than the last tag rn-v0.7.0-core-v0.1.0. Bump the version (semantic-release style: feat → minor, fix → patch) so the release publishes a new version.
- No CHANGELOG.md found. Keep a changelog — releases without release notes are invisible to users.
- 20 uncommitted change(s) — a release should ship from a clean tree. Commit (or stash) the outstanding changes so the release maps to a known revision.
Checklist
- ✖ Version: package.json version 1.0.0 is not newer than the last tag rn-v0.7.0-core-v0.1.0. — Bump the version (semantic-release style: feat → minor, fix → patch) so the release publishes a new version.
- ▲ Changelog: No CHANGELOG.md found. — Keep a changelog — releases without release notes are invisible to users.
- ▲ Working tree: 20 uncommitted change(s) — a release should ship from a clean tree. — Commit (or stash) the outstanding changes so the release maps to a known revision.
- ▲ CI: No .github/workflows directory — nothing runs tests or publishes on push. — Add CI (tests + typecheck) and a publish workflow before releasing.
- ✓ Lockfile: Dependencies are locked.
- ✓ Tests: A test script / jest config is configured.
- ✓ Secrets hygiene: No .env file in the tree.
- ✓ Open markers: 0 TODO/FIXME marker(s) across 11 source files.
Not ready — address the errors and warnings above.
vectalon bug-fix — Autonomous Bug Fix
Scanned /Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app — 1 findings, 1 auto-fixable, 0 applied, 0 refused (dirty tree).
Verdict: needs-attention
Fix plan
[WARN] unused-import (auto)
- File:
src/__tests__/CreateLoginScreenEmailPassword.tsx:4 - Target:
React - Message: Import React (from react) is never used
- Fix: Remove the React specifier — dead imports trip noUnusedLocals in strict TS projects.
-import React from 'react';
+vectalon crash — Crash Intelligence
Platform: javascript · Verdict: changes-requested Exception: Cannot read properties of null (reading 'email') Message: Cannot read properties of null (reading 'email')
Root cause: null-reference
Accessing a property on a nullish value
Standard fix
Add optional chaining / default values at the nullish access, verify async data loads before render, and align the API response type with the consumer.
Investigation steps
- Add optional chaining or default values
- Verify async data is loaded before render
- Check the API response shape matches the expected types
- Investigate the top in-app frames from the report:
- - renderForm — src/screens/CreateLoginScreenEmailPasswordScreen.tsx:41
- - CreateLoginScreenEmailPasswordScreen — src/screens/CreateLoginScreenEmailPasswordScreen.tsx:19
- - useCreateLoginSession — src/hooks/useCreateLoginScreenEmailPassword.ts:12
Top frames
renderForm — src/screens/CreateLoginScreenEmailPasswordScreen.tsx:41CreateLoginScreenEmailPasswordScreen — src/screens/CreateLoginScreenEmailPasswordScreen.tsx:19useCreateLoginSession — src/hooks/useCreateLoginScreenEmailPassword.ts:12
vectalon arch-score — Mobile Architecture Scorecard
91/100 — grade A (approved)
| Dimension | Score | Weight | Detail |
|---|---|---|---|
| Circular dependencies | 100 | 30% | No cycles detected |
| Layer boundaries | 80 | 20% | 1 shared→feature import(s) |
| Module coupling | 100 | 15% | avg 1.8 imports per module (6 modules) |
| Module cohesion | 100 | 15% | largest module has 3 file(s) across 4 module(s) |
| Test coverage presence | 50 | 10% | 3 of 6 source files have a test sibling (50%) |
| Nesting depth | 100 | 10% | deepest file sits 3 levels under src/ |
Top improvements
- Move the 1 shared→feature import(s): features depend on shared, never the reverse.
vectalon cicd — CI/CD Intelligence
Systems: none detected · Files: 0 · Verdict: approved
No CI anti-patterns found.
vectalon app-store — Store Readiness
Platforms: none · Verdict: approved
[INFO] shared
No ios/ or android/ directories found
Fix: Run this check in the native project root (or add the native folders) — store readiness only applies to native builds.
vectalon soc2 — SOC2 Readiness
Score: 27% (1 pass, 4 partial, 6 fail) · Verdict: changes-requested
This is a repository-evidence self-assessment, not an audit. A passing
score means the in-repo evidence exists; the audit itself needs process and
personnel evidence.
⚠️ [Security] Authentication & authorization library in use — partial
- Evidence: no auth/credential library declared
- Next step: Adopt a credential/session library (expo-secure-store, react-native-keychain, jose) and document the auth flow.
❌ [Security] Secrets excluded from version control — fail
- Evidence: .env not found in .gitignore
- Next step: Add .env (and .env.*) to .gitignore so secrets never enter the repository.
✅ [Security] Dependencies locked for reproducible builds — pass
- Evidence: package-lock.json committed
- Next step: Commit a lockfile (package-lock.json / yarn.lock / pnpm-lock.yaml) for reproducible, auditable dependency sets.
❌ [Availability] CI pipeline with tests — fail
- Evidence: no CI workflows found
- Next step: Add CI that runs tests on every push — SOC2 expects automated regression coverage.
⚠️ [Processing Integrity] Automated tests in the repository — partial
- Evidence: no test files detected
- Next step: Add unit/integration tests for core flows — processing integrity needs verifiable behavior.
⚠️ [Confidentiality] Encrypted communication (TLS) — partial
- Evidence: no explicit TLS configuration found
- Next step: Ensure every API endpoint uses HTTPS and ATS is not disabled.
❌ [Privacy] Privacy policy documented — fail
- Evidence: no privacy policy document found
- Next step: Document data collection, retention, and deletion — required for the Privacy criterion.
⚠️ [Security] Structured logging for audit trails — partial
- Evidence: no structured logging library declared
- Next step: Adopt a structured logger and log auth events, admin actions, and errors with timestamps.
❌ [Availability] Data backup strategy in place — fail
- Evidence: no backup strategy found in the repo
- Next step: Document and automate database/state backups with recovery-time objectives (RTO/RPO).
❌ [Security] Incident response runbook — fail
- Evidence: no incident response runbook found
- Next step: Write an INCIDENT.md runbook: severity levels, on-call, containment steps, postmortem template.
❌ [Security] Dependency vulnerability scanning — fail
- Evidence: npm audit / dependabot / renovate configured
- Next step: Run
npm auditin CI (or enable Dependabot) so vulnerable dependencies are caught continuously.
vectalon tokens — Design Token Sync
Token file: none · Tokens: 0 · Verdict: approved
[INFO] orphan-token
No design-token file found (tokens.json / design-tokens.json / theme.json).
Fix: Create a style-dictionary-style token file so this agent can check drift.
vectalon team-stats — Team Productivity Analytics
Commits: 308 · Authors: 3 · Bus factor: 1 · Cadence: 18.1/day · Verdict: needs-attention
Authors
| Author | Commits | Share |
|---|---|---|
| Bhishak Sanyal | 289 | 94% |
| vectalon-benchmark[bot] | 12 | 4% |
| dependabot[bot] | 7 | 2% |
Categories
- added: 142
- changed: 99
- fixed: 35
- removed: 2
- security: 8
- performance: 0
- deprecated: 0
- other: 22
Findings
[WARN] bus-factor
Bus factor 1: Bhishak Sanyal owns 94% of commits
Suggestion: Pair on critical modules and rotate ownership so a single departure cannot stall the project.
vectalon perms — Agent Permissions Audit
Config files: 0 · Verdict: approved
No agent/MCP config files found — nothing to audit.
Engineering Dashboard
Overall: changes-requested · 38 agents, 96 findings (3 errors, 54 warnings)
| Agent | Verdict | Errors | Warnings | Info |
|---|---|---|---|---|
| a11y | approved | 0 | 0 | 0 |
| app-store | approved | 0 | 0 | 1 |
| arch | approved | 0 | 0 | 0 |
| arch-score | approved | 0 | 0 | 0 |
| audit | approved | 0 | 0 | 1 |
| bug-fix | needs-attention | 0 | 1 | 0 |
| build-fix | approved | 0 | 0 | 0 |
| cicd | approved | 0 | 0 | 0 |
| cost | approved | 0 | 0 | 1 |
| dataset | approved | 0 | 0 | 1 |
| deps | needs-attention | 0 | 12 | 0 |
| dx | changes-requested | 0 | 0 | 0 |
| evals | changes-requested | 0 | 1 | 0 |
| figma | approved | 0 | 0 | 1 |
| gh-ci | approved | 0 | 0 | 0 |
| gh-issue | approved | 0 | 0 | 0 |
| gh-pr | changes-requested | 0 | 17 | 6 |
| gh-sec | changes-requested | 0 | 1 | 0 |
| governance | needs-attention | 0 | 2 | 6 |
| incident | changes-requested | 0 | 0 | 0 |
| lora | changes-requested | 1 | 0 | 0 |
| monitor | needs-attention | 0 | 0 | 0 |
| observability | needs-attention | 0 | 5 | 0 |
| perms | approved | 0 | 0 | 0 |
| play-store | changes-requested | 1 | 0 | 0 |
| refactor | needs-attention | 0 | 1 | 2 |
| release-predict | needs-attention | 0 | 0 | 2 |
| release-ready | changes-requested | 1 | 3 | 4 |
| repos | approved | 0 | 0 | 1 |
| review | changes-requested | 0 | 0 | 0 |
| search | approved | 0 | 0 | 0 |
| sec | needs-attention | 0 | 8 | 11 |
| sentry | approved | 0 | 0 | 0 |
| soc2 | changes-requested | 0 | 0 | 0 |
| team-stats | needs-attention | 0 | 1 | 0 |
| test-repair | approved | 0 | 0 | 0 |
| tokens | approved | 0 | 0 | 1 |
| train | changes-requested | 0 | 2 | 0 |
Needs action: lora, play-store, release-ready
vectalon figma — Figma-to-code Sync
Design file: none · Colors: 0 · Components: 0 · Verdict: approved
[INFO] missing-token —
No Figma design export found (figma.json / design-export.json / design.json).
Fix: Export the design file as JSON and drop it at the repo root so this agent can check design↔code drift.
vectalon sentry — Sentry Intelligence
Telemetry files: 2 · Events: 47 · Crash classes: 7 · Verdict: approved
[CRITICAL] Error
Events: 41 · Users: 0 · Releases: 1.0.0
Bucket: unknown
Probable cause: Error: Attempted to use an object of type View as an RCTView
Investigation:
- Check what changed in release 1.0.0 — the crash is attributed to it
- Reproduce the issue locally
- Capture logs and stack traces
- Trace recent changes that could relate
- Investigate the top in-app frames from the report:
- - (anonymous) — src/screens/LoginScreen.tsx:88
[INFO] sentry-1786785284868-l7w11o
Events: 1 · Users: 0 · Releases: unknown
Bucket: unknown
Probable cause: Could not automatically classify this issue
Investigation:
- Reproduce the issue locally
- Capture logs and stack traces
- Trace recent changes that could relate
[INFO] sentry-1786785284868-ptu0dm
Events: 1 · Users: 0 · Releases: unknown
Bucket: unknown
Probable cause: Could not automatically classify this issue
Investigation:
- Reproduce the issue locally
- Capture logs and stack traces
- Trace recent changes that could relate
[INFO] sentry-1786785284868-um1wp2
Events: 1 · Users: 0 · Releases: unknown
Bucket: unknown
Probable cause: Could not automatically classify this issue
Investigation:
- Reproduce the issue locally
- Capture logs and stack traces
- Trace recent changes that could relate
[INFO] sentry-1786785284868-0zcryl
Events: 1 · Users: 0 · Releases: unknown
Bucket: unknown
Probable cause: Could not automatically classify this issue
Investigation:
- Reproduce the issue locally
- Capture logs and stack traces
- Trace recent changes that could relate
[INFO] sentry-1786785284868-qwke20
Events: 1 · Users: 0 · Releases: unknown
Bucket: unknown
Probable cause: Could not automatically classify this issue
Investigation:
- Reproduce the issue locally
- Capture logs and stack traces
- Trace recent changes that could relate
[INFO] sentry-1786785284868-9o6qyb
Events: 1 · Users: 0 · Releases: unknown
Bucket: unknown
Probable cause: Could not automatically classify this issue
Investigation:
- Reproduce the issue locally
- Capture logs and stack traces
- Trace recent changes that could relate
vectalon observability — Mobile Observability
Traces scanned: 0 · Slow traces: 0 · Verdict: needs-attention
[WARN] no-sentry-init
Sentry init not detected in any source file
Fix: Wire up sentry init so crashes and performance data actually reach your observability backend.
[WARN] no-crash-handler
Crash handler not detected in any source file
Fix: Wire up crash handler so crashes and performance data actually reach your observability backend.
[WARN] no-analytics-sdk
Analytics SDK not detected in any source file
Fix: Wire up analytics sdk so crashes and performance data actually reach your observability backend.
[WARN] no-network-breadcrumb
Network breadcrumbs not detected in any source file
Fix: Wire up network breadcrumbs so crashes and performance data actually reach your observability backend.
[WARN] no-performance-tracing
Performance tracing not detected in any source file
Fix: Wire up performance tracing so crashes and performance data actually reach your observability backend.
vectalon governance — Enterprise Governance
Checks: 9 · Verdict: needs-attention
| Check | Status | Evidence |
|---|---|---|
| License file | ❌ fail | no LICENSE file at repo root |
| Security policy | ❌ fail | no SECURITY.md (or .github/SECURITY.md) |
| Contributing guide | ⚠️ warn | no CONTRIBUTING.md |
| CODEOWNERS | ⚠️ warn | no CODEOWNERS (or .github/CODEOWNERS) |
| PR template | ⚠️ warn | no PR template |
| Lockfile | ✅ pass | package-lock.json |
| SBOM | ⚠️ warn | no SBOM (sbom.json / cyclonedx) |
| Dependabot | ⚠️ warn | no .github/dependabot.yml |
| CI workflows | ⚠️ warn | no .github/ directory |
Findings
[WARN] missing-license
License file is missing: Add a LICENSE so downstream consumers know their rights.
Fix: Add a LICENSE so downstream consumers know their rights.
[WARN] missing-security-policy
Security policy is missing: Document how to privately report a vulnerability.
Fix: Document how to privately report a vulnerability.
[INFO] missing-contributing
Contributing guide not found: Add a contributing guide so external contributors know the workflow.
Fix: Add a contributing guide so external contributors know the workflow.
[INFO] missing-codeowners
CODEOWNERS not found: Add CODEOWNERS so the right people review sensitive paths.
Fix: Add CODEOWNERS so the right people review sensitive paths.
[INFO] missing-pr-template
PR template not found: Add a PR template with checklist + test instructions.
Fix: Add a PR template with checklist + test instructions.
[INFO] missing-sbom
SBOM not found: Generate an SBOM (e.g. syft dir:. -o cyclonedx-json) for supply-chain visibility.
Fix: Generate an SBOM (e.g. syft dir:. -o cyclonedx-json) for supply-chain visibility.
[INFO] missing-dependabot
Dependabot not found: Add Dependabot config so dependency advisories land as PRs.
Fix: Add Dependabot config so dependency advisories land as PRs.
[INFO] missing-ci
CI workflows not found: Add CI so every PR is tested before merge.
Fix: Add CI so every PR is tested before merge.
vectalon audit — Org-wide Audit Trail
Entries: 0 · Files: 0 · Verdict: approved
Findings
[INFO] no-trail
No audit trail found (.vectalon/audit or audit).
Fix: Have agents append JSONL audit entries (seq, timestamp, actor, action) so the org has an immutable trail.
vectalon repos — Multi-repository Memory
Manifest: none · Repos: 0 · Verdict: approved
Findings
[INFO] no-manifest
No workspace manifest at .vectalon/repos.json.
Fix: Create .vectalon/repos.json with {"repos":[{"name","path"}]} listing sibling checkouts.
vectalon release-predict — Release Prediction
Risk: high · Score: 44/100 · Window: 14d (263 commits) · Verdict: needs-attention
High risk — require a code freeze, full regression pass, and a slow staged rollout with rollback ready.
Factors
| Factor | Value | Weight | Direction |
|---|---|---|---|
| release-window-commits | 263 | 20% | lower = safer |
| fix-density | 0.194 | 35% | lower = safer |
| refactor-density | 0.091 | 15% | lower = safer |
| hours-since-last-commit | 9.2 | 10% | lower = safer |
| breaking-changes | 0 | 10% | lower = safer |
| authors-in-window | 2 | 10% | higher = safer |
Findings
[INFO] release-risk
Predicted release risk high (score 44/100) for the 14-day window: High risk — require a code freeze, full regression pass, and a slow staged rollout with rollback ready.
Suggestion: Add release-gate checks: code freeze, full suite on the release candidate, smoke test on staging, staged rollout.
[INFO] fix-density
51 of 263 window commit(s) are fixes/rollbacks (19%)
Suggestion: Investigate the root causes instead of stacking fixes — recurring fix commits predict an unstable release.
vectalon play-store — Deep Play Store Readiness
Checks: 1 · Verdict: changes-requested
| Check | Status | Detail |
|---|---|---|
| AndroidManifest.xml | ❌ fail | No AndroidManifest.xml found under android/ |
Findings
[ERROR] manifest
No AndroidManifest.xml found under android/
Fix: Create the manifest in android/app/src/main/ — Play submission requires it.
vectalon dataset — Fine-tuning Dataset
Files: 0 · Examples: 0 · Verdict: approved
[INFO] no-dataset
No dataset directory found (.vectalon/dataset, dataset, or training-data).
Fix: Export training examples as JSONL into one of those directories so this agent can validate the dataset.
vectalon lora — LoRA Training Readiness
Checks: 1 · Verdict: changes-requested
| Check | Status | Detail |
|---|---|---|
| Training config | ❌ fail | No .vectalon/lora/config.json (or YAML) found |
Findings
[ERROR] config
No .vectalon/lora/config.json (or YAML) found
Fix: Create the config with dataset path, base model, r/alpha, and output dir.
vectalon gh-pr — GitHub PR Triage
Source: gh-cli · PRs: 13 · Verdict: changes-requested
| # | PR | Author | Age | Size | Review | CI | Mergeable | Verdict |
|---|---|---|---|---|---|---|---|---|
| 12 | chore(deps-dev): bump typescript from 5.9.3 to 7.0.2 | app/dependabot | 15d | 59136 | failing (test, comment, coverage, bench) | CONFLICTING | changes-requested | |
| 7 | chore(deps-dev): bump eslint from 8.57.1 to 10.8.0 | app/dependabot | 15d | 59270 | failing (test, comment, coverage, bench) | CONFLICTING | changes-requested | |
| 20 | chore(deps): bump actions/upload-artifact from 4 to 7 | app/dependabot | 9d | 41211 | passing | CONFLICTING | changes-requested | |
| 19 | chore(deps): bump @babel/parser from 7.29.8 to 8.0.4 | app/dependabot | 9d | 81239 | failing (test, Analyze (javascript), comment, coverage, bench) | CONFLICTING | changes-requested | |
| 18 | chore(deps): bump codecov/codecov-action from 5 to 7 | app/dependabot | 9d | 81209 | failing (test, comment, coverage, bench) | CONFLICTING | changes-requested | |
| 28 | chore(deps-dev): bump @typescript-eslint/eslint-plugin from 7.18.0 to 8.67.0 | app/dependabot | 1d | 171 | failing (test, validate) | MERGEABLE | changes-requested | |
| 26 | chore(deps-dev): bump tailwindcss from 3.4.19 to 4.3.3 | app/dependabot | 1d | 270 | failing (test, validate, comment, bench) | MERGEABLE | changes-requested | |
| 24 | chore(deps): bump react-dom and @types/react-dom | app/dependabot | 1d | 51 | failing (test, validate, comment, bench) | MERGEABLE | changes-requested | |
| 21 | chore(deps): bump github/codeql-action from 4.37.3 to 4.37.6 | app/dependabot | 9d | 6 | passing | MERGEABLE | approved | |
| 30 | chore(deps-dev): bump @typescript-eslint/parser from 7.18.0 to 8.67.0 | app/dependabot | 1d | 130 | passing | MERGEABLE | approved | |
| 29 | chore(deps): bump ws from 8.21.2 to 8.21.3 | app/dependabot | 1d | 12 | passing | MERGEABLE | approved | |
| 27 | chore(deps-dev): bump @types/node from 20.19.43 to 26.2.0 | app/dependabot | 1d | 193 | passing | MERGEABLE | approved | |
| 25 | chore(deps-dev): bump turbo from 2.10.8 to 2.10.9 | app/dependabot | 1d | 60 | passing | MERGEABLE | approved |
Findings
[WARN] pr-ci-failing (PR #28)
PR #28 CI is failing (test, validate).
Suggestion: Fix the failing checks or the merge is blocked by the CI gate.
[WARN] pr-ci-failing (PR #26)
PR #26 CI is failing (test, validate, comment, bench).
Suggestion: Fix the failing checks or the merge is blocked by the CI gate.
[WARN] pr-ci-failing (PR #24)
PR #24 CI is failing (test, validate, comment, bench).
Suggestion: Fix the failing checks or the merge is blocked by the CI gate.
[WARN] pr-huge (PR #20)
PR #20 touches 41211 lines (38601+/2610-) — a review will miss defects at this size.
Suggestion: Split into reviewable chunks of a few hundred lines each.
[WARN] pr-conflict (PR #20)
PR #20 has merge conflicts with its base branch.
Suggestion: Re-base on the latest base branch and resolve conflicts.
[INFO] pr-idle (PR #20)
PR #20 has had no activity in 8 days.
Suggestion: Nudge the author or reassign to keep the change moving.
[WARN] pr-huge (PR #19)
PR #19 touches 81239 lines (63497+/17742-) — a review will miss defects at this size.
Suggestion: Split into reviewable chunks of a few hundred lines each.
[WARN] pr-ci-failing (PR #19)
PR #19 CI is failing (test, Analyze (javascript), comment, coverage, bench).
Suggestion: Fix the failing checks or the merge is blocked by the CI gate.
[WARN] pr-conflict (PR #19)
PR #19 has merge conflicts with its base branch.
Suggestion: Re-base on the latest base branch and resolve conflicts.
[INFO] pr-idle (PR #19)
PR #19 has had no activity in 8 days.
Suggestion: Nudge the author or reassign to keep the change moving.
[WARN] pr-huge (PR #18)
PR #18 touches 81209 lines (63467+/17742-) — a review will miss defects at this size.
Suggestion: Split into reviewable chunks of a few hundred lines each.
[WARN] pr-ci-failing (PR #18)
PR #18 CI is failing (test, comment, coverage, bench).
Suggestion: Fix the failing checks or the merge is blocked by the CI gate.
[WARN] pr-conflict (PR #18)
PR #18 has merge conflicts with its base branch.
Suggestion: Re-base on the latest base branch and resolve conflicts.
[INFO] pr-idle (PR #18)
PR #18 has had no activity in 8 days.
Suggestion: Nudge the author or reassign to keep the change moving.
[INFO] pr-stale (PR #12)
PR #12 has been open 15 days.
Suggestion: Confirm it still targets the current trunk before it goes stale.
[WARN] pr-huge (PR #12)
PR #12 touches 59136 lines (55452+/3684-) — a review will miss defects at this size.
Suggestion: Split into reviewable chunks of a few hundred lines each.
[WARN] pr-ci-failing (PR #12)
PR #12 CI is failing (test, comment, coverage, bench).
Suggestion: Fix the failing checks or the merge is blocked by the CI gate.
[WARN] pr-conflict (PR #12)
PR #12 has merge conflicts with its base branch.
Suggestion: Re-base on the latest base branch and resolve conflicts.
[INFO] pr-idle (PR #12)
PR #12 has had no activity in 8 days.
Suggestion: Nudge the author or reassign to keep the change moving.
[INFO] pr-stale (PR #7)
PR #7 has been open 15 days.
Suggestion: Confirm it still targets the current trunk before it goes stale.
[WARN] pr-huge (PR #7)
PR #7 touches 59270 lines (55323+/3947-) — a review will miss defects at this size.
Suggestion: Split into reviewable chunks of a few hundred lines each.
[WARN] pr-ci-failing (PR #7)
PR #7 CI is failing (test, comment, coverage, bench).
Suggestion: Fix the failing checks or the merge is blocked by the CI gate.
[WARN] pr-conflict (PR #7)
PR #7 has merge conflicts with its base branch.
Suggestion: Re-base on the latest base branch and resolve conflicts.
vectalon gh-issue — GitHub Issue Triage
Source: gh-cli · Open: 0 · Stale: 0 · Unassigned: 0 · Verdict: approved
| # | Title | Author | Age | Labels | Assignees | Verdict |
|---|
Findings
vectalon gh-ci — GitHub Workflow Reliability
Source: gh-cli · Workflows: 8 · Runs: 0 · Flaky: 0 · Verdict: approved
| Workflow | Runs | Pass | Fail | Fail rate | Flaky | Avg |
|---|---|---|---|---|---|---|
| CI | 0 | 0 | 0 | 0% | no | 4m |
| CodeQL | 0 | 0 | 0 | 0% | no | 2m |
| Publish Packages | 0 | 0 | 0 | 0% | no | 2m |
| Nightly Smoke | 0 | 0 | 0 | 0% | no | 2m |
| Benchmark leaderboard (nightly) | 0 | 0 | 0 | 0% | no | 26m |
| PR leaderboard comment | 0 | 0 | 0 | 0% | no | 4m |
| PR Validation | 0 | 0 | 0 | 0% | no | 4m |
| Dependabot Updates | 0 | 0 | 0 | 0% | no | 2m |
Findings
vectalon gh-sec — GitHub Security Posture
Source: none · Dependabot: 0 open (0 critical/high) · Secrets: 0 · Protection: off · Verdict: changes-requested
Findings
[WARN] no-data ((all))
No GitHub security data available — gh is missing, unauthenticated, or this is not a GitHub repo.
Suggestion: Install and auth the GitHub CLI, or pass --file with a gh-sec export (dependabot, secretScanning, branchProtection).
vectalon monitor — Observability Dashboard
Crash classes: 7 · Telemetry events: 0 · Verdict: needs-attention
| Surface | Verdict | Summary |
|---|---|---|
| Crash classes (Sentry) | approved | 7 crash class(es) ranked |
| Observability audit | needs-attention | 5 instrumentation/trace finding(s) |
| Crash intelligence | no-data | No crash report yet |
| Engineering dashboard | no-data | No dashboard report yet |
Findings
vectalon evals — Model Evaluation
Cases: 0 · Pass: 0/0 (0%) · Verdict: changes-requested
| Case | Mode | Result | Note |
|---|
Findings
[WARN] no-cases
No eval cases found at /Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app/.vectalon/evals/cases.json (or the file is invalid).
Suggestion: Create .vectalon/evals/cases.json with { cases: [{ id, input, expected, actual, mode }] }.
vectalon search — "login"
Files scanned: 8 · Hits: 18 · 1ms
src/__tests__/CreateLoginScreenEmailPassword.tsx
1// TDD test suite for CreateLoginScreenEmailPassword — written before implementation.2// Runnpm test CreateLoginScreenEmailPasswordto verify the implementation satisfies these requirements.6import { CreateLoginScreenEmailPasswordScreen } from '../screens/CreateLoginScreenEmailPasswordScreen';
src/__tests__/useCreateLoginScreenEmailPassword.ts
1// TDD test suite for useCreateLoginScreenEmailPassword — written before implementation.4import { useCreateLoginScreenEmailPassword } from '../hooks/useCreateLoginScreenEmailPassword';6describe('useCreateLoginScreenEmailPassword', () => {
src/hooks/useCreateLoginScreenEmailPassword.ts
2import { createLoginScreenEmailPasswordApi } from '../services/CreateLoginScreenEmailPasswordApi';4interface UseCreateLoginScreenEmailPasswordState {10export function useCreateLoginScreenEmailPassword(): UseCreateLoginScreenEmailPasswordState & { run: () => Promise<void> } {
src/screens/CreateLoginScreenEmailPasswordScreen.tsx
3import { useCreateLoginScreenEmailPassword } from '../hooks/useCreateLoginScreenEmailPassword';5export function CreateLoginScreenEmailPasswordScreen(): React.JSX.Element {6const { run, loading, error, data } = useCreateLoginScreenEmailPassword();
src/__tests__/CreateLoginScreenEmailPasswordApi.ts
1// TDD test suite for CreateLoginScreenEmailPasswordApi — written before implementation.3import { createLoginScreenEmailPasswordApi } from '../services/CreateLoginScreenEmailPasswordApi';5describe('CreateLoginScreenEmailPasswordApi', () => {
src/services/CreateLoginScreenEmailPasswordApi.ts
1export class CreateLoginScreenEmailPasswordApi {7export const createLoginScreenEmailPasswordApi = new CreateLoginScreenEmailPasswordApi();
App.tsx
9<Text style={styles.title}>login-app</Text>
Findings
vectalon incident — Incident Brief
Platform: unknown · Root cause: no-data · Verdict: changes-requested
Root cause
No crash log or prior crash report available.
Next steps
- Run vectalon crash --log <path> with the crash log, or run vectalon crash first so an incident can reuse its report.
vectalon train — Release Train (dry-run)
Repos: 1 · Verdict: changes-requested · Read-only: nothing was modified
login-app
Version: 1.0.0 · Last tag: rn-v0.7.0-core-v0.1.0 · Suggested bump: minor · Changelog: ✗ · Clean tree: ✗
- [WARNING] No CHANGELOG section for the current version. — Add release notes under the version heading.
- [WARNING] Working tree is not clean. — Commit or stash changes before cutting the release.
Findings
[WARNING] changelog (login-app)
No CHANGELOG section for the current version.
Suggestion: Add release notes under the version heading.
[WARNING] dirty (login-app)
Working tree is not clean.
Suggestion: Commit or stash changes before cutting the release.
vectalon cost — Spend Estimate
Estimates, not invoices — rates below are explicit assumptions.
Total: $0/mo · Verdict: approved
| Item | Amount | Basis |
|---|
Assumptions
- GPU hour: $1.2 (spot-class instance)
- Tokens: $1/1M input tokens (mid-range hosted model)
- Data processing: $0.2/GB
Findings
[INFO] no-cost-surfaces
No cost surfaces found — no LoRA config, dataset, or eval cases.
Suggestion: Add .vectalon/lora/config.json, datasets, or eval cases to get a spend estimate.
vectalon dx — Developer Experience Score
Score: 34/100 (D) · Verdict: changes-requested
| Axis | Score | Weight | Note |
|---|---|---|---|
| README | 0/100 | 10% | No README — new devs start blind |
| Contributing guide | 0/100 | 8% | No contributing guide |
| Docs directory | 100/100 | 8% | docs/ populated |
| CI workflows | 0/100 | 12% | No CI workflows |
| Test setup | 0/100 | 12% | No test setup |
| Lockfile | 100/100 | 6% | Lockfile committed |
| Lint config | 0/100 | 6% | No lint config |
| Format config | 0/100 | 4% | No editor config |
| TypeScript strict | 100/100 | 8% | strict mode on |
| Changelog | 0/100 | 8% | No changelog |
| Onboarding assets | 0/100 | 6% | No onboarding artifacts |
| Source complexity | 99/100 | 12% | avg 20 lines/file, no giant-file sprawl |
Top improvements
- CI workflows (+12pts): No CI workflows
- Test setup (+12pts): No test setup
- README (+10pts): No README — new devs start blind
- Contributing guide (+8pts): No contributing guide
- Changelog (+8pts): No changelog
vectalon archive — Build Archive
Verdict: approved · Project: login-app · Flavor: production Build: #1 (1.0.0) · android · release · apk · 35 B SHA-256: cd0ff5ada27562d2e2c8e0277a8438087cca22caac9c9db50f3f0f70d1a344e6 Git: d2da6c8e0eb6d7008cfca2d4200bffe456087615 on main (tag rn-v0.10.0-core-v0.1.0) · built by sanyalbishak93@gmail.com Stored: /Users/bhishaksanyal/Documents/Github/Vectalon/apps/website/demo/login-app/.vectalon/builds/login-app/production/release/1.0.0/1/android/app.apk
Planned build command (skipped — artifact provided): eas build --platform android --profile production --non-interactive
Flavors
- production (default)
vectalon distribute — Distribution
Target: play-store · Verdict: approved (dry-run) Build: #1 (1.0.0) · android · production · release · apk · 8d46cafa-d48a-40a1-be02-3c71ee1a8cb9
Plan
- No credential provider detected — dry run, nothing to execute (track: internal).
- No credential provider detected. To distribute to the Play Store, either:
- Install Fastlane and run
fastlane initin your android/ directory, or - Set GOOGLE_PLAY_SERVICE_ACCOUNT to a service-account JSON path for direct API access.
Dry run — no side effects. Remove --dry-run to execute for real (credentials are never stored).vectalon portal — Build Portal
Verdict: approved · Output: /tmp/vectalon-demo/portal · Builds: 1 · Files: 5
- Domain: builds.login-app.dev
- Deploy:
vectalon portal --deploy vercel(or netlify / static)
44 committed samples demonstrate report format, not universal customer-workflow qualification · synced with scripts/sync-reports.mjs