RELEASES
v2.0.2 — released 8 September 2026 — encoded payloads and a faster, stricter Agent Scan: a second pass decodes base64, hex and compressed literals and rates hidden AI code that the file executes CRITICAL · the rogue-agent pattern is CRITICAL in every scanned language · Ruby and C# false CRITICALs removed · agent scan start-up 25 s → 0.1 s on a 115 MB tree, a 100,000-character line 85 s → 0.5 s · Metrics + Agent Scan runs from the GUI again · every demo opens an in-tool source page verified against a frozen baseline · the scan window stays put · what’s new v2.0.1 — released 3 September 2026 — the definitions moved, so the numbers are not comparable with 1.9: a moved statement is MOV, not churn, at both levels · closing-brace lines are never logical lines · unclassified text is out of the totals · JavaScript-family comment split corrected · shebang scripts classified by interpreter, symlinks reported not followed · 114 known-answer fixtures behind the engine, every headless mode licence-gated, the GitHub Action reads its gate rules from the base branch · pinned, checksummed, gate-verified build v1.9.9 — released 31 August 2026 — security release: the threat-detection instruments sharpened by their first large-scale use — AI-BOM provider canonicalisation (one provider however the code spells it, with a seen_as evidence list; frameworks reported separately from providers) · the agent map folds the same way, red jurisdictions never lost in the merge · agent-scan JSON now carries committed credentials (redacted), the build surface with hook and fetcher lists, and the AI-vs-exec-only flag split — automation no longer needs the HTML v1.9.8 — released 30 August 2026 — Code Delta threat detection and code security tool portfolio expanded and upgraded: committed-credentials detection — API keys and private keys found by documented vendor format, shown redacted, named to file and line · three opt-in merge gates fail the build on a committed credential, a NEW install hook or a NEW remote-fetching build file · build files that fetch remote content flagged first, with the download-URL delta on every change · Agents mode in the Code Browser: every AI-calling file with its signals and providers, and the 3-D agent map as a first-class view · pie charts on the Code Browser Overview v1.9.7 — released 28 August 2026 — multi-core engine: scans use every processor core, results byte-identical, large scans roughly halved (73s → 39s on a 1.65M-SLOC pair) · Code Browser gains inheritance (Extends / Inherited by, base classes drawn solid blue), a sortable Complexity view, and a density dial on the class visualiser — fewer / more / show all / expand · one findable Code Browser tab with its own icon · mismatched-pair gate stops wrong-folder scans before they start v1.9.6 — released 27 August 2026 — build-file alerts: every scan that compares two versions now lists the build/CI/packaging files that changed — ADDED / MODIFIED / DELETED, install hooks flagged first (code that runs on install), dependency manifests as a quieter line · shown in the GUI, the agent report and the CI pull-request comment, with a standing Build & Deployment Surface inventory in every agent report · two new GUI modes: Churn + Agent Scan and Metrics + Agent Scan v1.9.5 — released 22 August 2026 — the Code Browser: diff viewer and single-project structure view unified in one page — Changes, Overview, Files, Classes and Visualiser tabs, directory tree, class index with methods at file:line and talks-to evidence, 3D include map and class ego view · per-function churn with steppers · engine fixes: backslash-spliced comments, C++ raw strings, comment-only edits now count as changed · Agent Map in the agent-scan report v1.9.4 — released 17 August 2026 — the audited diff: rebuilt diff viewer where every counter is a claim you can click, walk and cite — steppers, evidence Ledger, moves as connected pairs, cross-file moves (XMOV) · git overlays: AI provenance, age of destroyed code, per-author People table · comment-parser fix recovers undercounted C-family LLOC (10,553 statements on a neovim-scale scan) v1.9.3 — released 1 August 2026 — TRUE_CHURN file count fixed in PR comments: the “came from N generated files” count now includes only generated files that churned in the PR, not every generated file in the tree — the number is traceable to the diff v1.9.2 — released 1 August 2026 — TRUE_CHURN now reported in CI: the pull-request comment shows authored churn beside the total, so a lockfile can no longer masquerade as development · per-file generated classification in the CSV and the GitHub Security tab · new paper measuring 80.1% generated churn in a real npm/cli release v1.9.1 — released 30 July 2026 — TRUE_CHURN — separating authored code from generated code: lockfiles, minified bundles and codegen detected deterministically, their churn subtotalled, and TRUE_CHURN = the statements your developers actually wrote · Agent Infrastructure — agent workspaces, rogue-agent residue and committed agent credentials found in the tree · Bedrock, Azure OpenAI, MCP and RU-provider detection · every result tile clicks through to its report FREE TO EVALUATE UNTIL 31 OCTOBER 2026 — full, unlocked functionality on every platform. The GitHub Action has the licence built in; desktop apps need the free licence file — one click, below v1.9.0 — released 27 July 2026 — all non-specified programming languages (no LLOC support) churned as U_LOC · TOTAL LOC — every line, matches wc -l exactly · spreadsheet-style report columns (drag to resize, double-click to fit) · per-directory skip-dir accounting — nothing silently dropped v1.8.9 — released 26 July 2026 — data metrics: churn split into working code vs data, element churn, whole-tree data composition · tooltips on every metric tile · beta designation retired v1.8.8 — released 26 July 2026 — Erlang/OTP support incl. the term-file family · 55 languages, 27 with logical statements · file coverage stated on every run · megastatement (64KB+) fix v1.8.7 — released 16 July 2026 — Dart support · churn_agent becomes the Action default PLATFORMS — Windows x64 · macOS Apple silicon · Linux x86-64 (AppImage or tar.gz) · Docker/GHCR · GitHub Action · GitLab CI v2.0.2 — released 8 September 2026 — encoded payloads and a faster, stricter Agent Scan: a second pass decodes base64, hex and compressed literals and rates hidden AI code that the file executes CRITICAL · the rogue-agent pattern is CRITICAL in every scanned language · Ruby and C# false CRITICALs removed · agent scan start-up 25 s → 0.1 s on a 115 MB tree, a 100,000-character line 85 s → 0.5 s · Metrics + Agent Scan runs from the GUI again · every demo opens an in-tool source page verified against a frozen baseline · the scan window stays put · what’s new v2.0.1 — released 3 September 2026 — the definitions moved, so the numbers are not comparable with 1.9: a moved statement is MOV, not churn, at both levels · closing-brace lines are never logical lines · unclassified text is out of the totals · JavaScript-family comment split corrected · shebang scripts classified by interpreter, symlinks reported not followed · 114 known-answer fixtures behind the engine, every headless mode licence-gated, the GitHub Action reads its gate rules from the base branch · pinned, checksummed, gate-verified build v1.9.9 — released 31 August 2026 — security release: the threat-detection instruments sharpened by their first large-scale use — AI-BOM provider canonicalisation (one provider however the code spells it, with a seen_as evidence list; frameworks reported separately from providers) · the agent map folds the same way, red jurisdictions never lost in the merge · agent-scan JSON now carries committed credentials (redacted), the build surface with hook and fetcher lists, and the AI-vs-exec-only flag split — automation no longer needs the HTML v1.9.8 — released 30 August 2026 — Code Delta threat detection and code security tool portfolio expanded and upgraded: committed-credentials detection — API keys and private keys found by documented vendor format, shown redacted, named to file and line · three opt-in merge gates fail the build on a committed credential, a NEW install hook or a NEW remote-fetching build file · build files that fetch remote content flagged first, with the download-URL delta on every change · Agents mode in the Code Browser: every AI-calling file with its signals and providers, and the 3-D agent map as a first-class view · pie charts on the Code Browser Overview v1.9.7 — released 28 August 2026 — multi-core engine: scans use every processor core, results byte-identical, large scans roughly halved (73s → 39s on a 1.65M-SLOC pair) · Code Browser gains inheritance (Extends / Inherited by, base classes drawn solid blue), a sortable Complexity view, and a density dial on the class visualiser — fewer / more / show all / expand · one findable Code Browser tab with its own icon · mismatched-pair gate stops wrong-folder scans before they start v1.9.6 — released 27 August 2026 — build-file alerts: every scan that compares two versions now lists the build/CI/packaging files that changed — ADDED / MODIFIED / DELETED, install hooks flagged first (code that runs on install), dependency manifests as a quieter line · shown in the GUI, the agent report and the CI pull-request comment, with a standing Build & Deployment Surface inventory in every agent report · two new GUI modes: Churn + Agent Scan and Metrics + Agent Scan v1.9.5 — released 22 August 2026 — the Code Browser: diff viewer and single-project structure view unified in one page — Changes, Overview, Files, Classes and Visualiser tabs, directory tree, class index with methods at file:line and talks-to evidence, 3D include map and class ego view · per-function churn with steppers · engine fixes: backslash-spliced comments, C++ raw strings, comment-only edits now count as changed · Agent Map in the agent-scan report v1.9.4 — released 17 August 2026 — the audited diff: rebuilt diff viewer where every counter is a claim you can click, walk and cite — steppers, evidence Ledger, moves as connected pairs, cross-file moves (XMOV) · git overlays: AI provenance, age of destroyed code, per-author People table · comment-parser fix recovers undercounted C-family LLOC (10,553 statements on a neovim-scale scan) v1.9.3 — released 1 August 2026 — TRUE_CHURN file count fixed in PR comments: the “came from N generated files” count now includes only generated files that churned in the PR, not every generated file in the tree — the number is traceable to the diff v1.9.2 — released 1 August 2026 — TRUE_CHURN now reported in CI: the pull-request comment shows authored churn beside the total, so a lockfile can no longer masquerade as development · per-file generated classification in the CSV and the GitHub Security tab · new paper measuring 80.1% generated churn in a real npm/cli release v1.9.1 — released 30 July 2026 — TRUE_CHURN — separating authored code from generated code: lockfiles, minified bundles and codegen detected deterministically, their churn subtotalled, and TRUE_CHURN = the statements your developers actually wrote · Agent Infrastructure — agent workspaces, rogue-agent residue and committed agent credentials found in the tree · Bedrock, Azure OpenAI, MCP and RU-provider detection · every result tile clicks through to its report FREE TO EVALUATE UNTIL 31 OCTOBER 2026 — full, unlocked functionality on every platform. The GitHub Action has the licence built in; desktop apps need the free licence file — one click, below v1.9.0 — released 27 July 2026 — all non-specified programming languages (no LLOC support) churned as U_LOC · TOTAL LOC — every line, matches wc -l exactly · spreadsheet-style report columns (drag to resize, double-click to fit) · per-directory skip-dir accounting — nothing silently dropped v1.8.9 — released 26 July 2026 — data metrics: churn split into working code vs data, element churn, whole-tree data composition · tooltips on every metric tile · beta designation retired v1.8.8 — released 26 July 2026 — Erlang/OTP support incl. the term-file family · 55 languages, 27 with logical statements · file coverage stated on every run · megastatement (64KB+) fix v1.8.7 — released 16 July 2026 — Dart support · churn_agent becomes the Action default PLATFORMS — Windows x64 · macOS Apple silicon · Linux x86-64 (AppImage or tar.gz) · Docker/GHCR · GitHub Action · GitLab CI
Downloads · GitHub · Windows · macOS · Linux · Docker

Get

Download and test on your code today!

Every platform is available now. Run it on your pull requests with the GitHub Action, or install the desktop app on Windows, macOS or Linux — free and fully unlocked until 31 October 2026*.

* Desktop apps need the free licence file to run — download it below and drop it in place. The GitHub Action has it built in.

GitHub
Action · any repo
Add to workflow
Windows
x64 · 10/11
Download (.zip)
macOS
Apple silicon
Download (.dmg)
Linux
x86-64 · AppImage / tar.gz
Download (.AppImage)

GitHub Action — run on your pull requests

Two lines, and it runs entirely inside your own runner — your source never leaves GitHub. Fully unlocked — the free licence is built into the Action, nothing to install. (Public repos: code-delta-app/action · releases.)

# .github/workflows/codedelta.yml
- uses: actions/checkout@v4
  with: { fetch-depth: 0 }
- uses: code-delta-app/action@v1
  1. Add the workflow file

    Create .github/workflows/codedelta.yml in your repo with the snippet above — the free licence is built into the Action, nothing to add.

  2. Open a pull request

    Within a minute you get a CodeDelta comment on the PR — churn + AI findings — plus the Security tab and the merge gate. Full details on the CLI / CI page.

To keep using it past 31 October 2026 — or to bring your own licence sooner — add a CODEDELTA_LICENSE secret (request one below); it overrides the built-in licence automatically.

Not on GitHub? The same engine runs anywhere Docker runs — GitLab, Jenkins, or a laptop: see Docker below.

Desktop app — Windows

The Windows desktop build (x64, Windows 10/11) is available as a direct download. It ships as a password-protected zip — password code-delta — so it downloads cleanly through the corporate gateways and mail filters that block plain installers.

We use your details only to contact you about CodeDelta and never share them.

Password-protected zip (opens with Windows' built-in extractor) — password code-delta. The installer is unsigned, so Windows may show an "unknown publisher" warning: click More info → Run anyway. Needs the free licence file to run — download it here (valid to 31 October 2026), or request your own.

Desktop app — macOS

The macOS desktop build (Apple silicon) is available as a direct download — signed and notarized by Apple, so it opens without security warnings.

We use your details only to contact you about CodeDelta and never share them.

Open the .dmg, drag CodeDelta to Applications, and launch it — no security warnings (Apple-notarized). Needs the free licence file to run — download it here (valid to 31 October 2026), or request your own.

Desktop app — Linux

The Linux desktop build (x86-64) is available as a single-file AppImage — download one file, make it executable, run. Prefer a terminal? A .tar.gz bundle (engine + GUI) is offered on the thank-you page.

We use your details only to contact you about CodeDelta and never share them.

chmod +x CodeDelta-x86_64.AppImage then run it. Needs the free licence file to run — download it here into ~/.codedelta/ (valid to 31 October 2026), or request your own.

Docker — for locked-down CI

For environments that won't allow local installs but do allow pulling approved images — most hardened corporate CI. The image is public on GitHub Container Registry; the same engine runs identically on GitLab, Jenkins, a self-hosted box or a laptop.

# pull once, run anywhere — nothing installed on the host
docker run --rm -v "$PWD:/work" -e CODEDELTA_LICENSE_B64 \
  ghcr.io/code-delta-app/codedelta scan /work/new /work/old

Needs the free licence file to run — download it here (valid to 31 October 2026), then pass it in: export CODEDELTA_LICENSE_B64=$(base64 -w0 codedelta.lic). Full recipes on the CLI / CI page.

CLOC — free cross-check utility

CLOC is a free, GPL-licensed, command-line code-counting tool that also offers churn for SLOC (CodeDelta has an equivalent, superior, headless engine). We found CLOC useful for cross-checking CodeDelta’s results — on identical file sets the two agree on physical lines to the exact line. It doesn’t offer language-specific logical statement diffs (changed_LLOC), data element detection, an SQL database, embedded AI agent detection and all the other good stuff that makes CodeDelta unique, but it’s a great way to validate the size of codebases and verify CodeDelta output! It supports 395 languages — where “support” means it knows each language’s comment syntax and file extensions. That list should help you decide which languages you’d like incorporated into CodeDelta: incorporation means we strip comments via language-specific syntax and detect logical statements and data elements using the same dedicated language specification.

We use your details only to contact you about CodeDelta and never share them.

v2.10 — a password-protected zip (password code-delta, same as our Windows download — passes corporate gateways) holding the single Perl script (its own source) and the licence text.

Third-party software by Al Danial and contributors, redistributed unmodified under the GPL-2.0 licence (full text) — not a CodeDelta product and no endorsement implied; copyright notices are preserved in the script itself, which is its own source. Why statement-level measurement matters: Why LLOC is what really counts →

The licence key — the desktop app needs this file to run. Free, ready to use, valid to 31 October 2026: Download codedelta.lic and put it where the app looks: macOS: ~/Library/Application Support/CodeDelta/  ·  Windows: the folder CodeDelta installed to  ·  Linux / CLI: ~/.codedelta/

Getting started

  1. Download & install

    Pick your platform above. The binary is self-contained; the GUI runs locally in your browser.

  2. Install the licence file

    Save the free codedelta.lic above (or your own) via the Install License screen, or drop it in CodeDelta's config folder. See the Licensing Guide for desktop and GitHub CI install steps.

  3. Run an analysis

    Point CodeDelta at two snapshots: codedelta ./old ./new -o report.html — or use the GUI.

  4. Inspect the report

    Open the per-file, per-line report and verify the classifications against your own expectations.

Every download is the full product — every feature, no restrictions. The free licence runs to 31 October 2026; when a licence expires, analysis is disabled until a new one is installed.

Buy CodeDelta

For a licence that runs past 31 October 2026 — corporate, trial extension or academic — email us. A human replies, usually the same day. No forms, no payment details on the site.

Buy now — email us →

Or use the chat in the corner. We use your details only to reply about CodeDelta.