LATEST
ENCODED PAYLOADS AND A FASTER, STRICTER AGENT SCANv2.0.2: a second pass decodes base64, hex and compressed literals and rates hidden AI code that the file executes CRITICAL · the rogue-agent pattern is CRITICAL in every scanned language · Ruby and C# false CRITICALs removed · agent scan start-up 25 s → 0.1 s on a 115 MB tree · Metrics + Agent Scan runs from the GUI again · every demo opens an in-tool source page verified against a frozen baseline · download VERSION 2.0.1v2.0.1: the metric definitions moved (a move is not churn, braces never count, unclassified text out of the totals) so 1.9 and 2.0 numbers are not comparable · 114 known-answer fixtures behind the engine · every headless mode licence-gated · the Action reads its gate rules from the base branch · download SECURITY RELEASEv1.9.9: AI-BOM provider counts made exact (one provider however the code spells it; frameworks reported separately) · the agent map folds to match · committed credentials, build surface and the AI-vs-exec-only split now in the machine-readable JSON · download CODE DELTA THREAT DETECTION AND CODE SECURITY TOOL PORTFOLIO — EXPANDED AND UPGRADEDv1.9.8: committed credentials found and shown redacted · merge gates for credentials, new install hooks and new remote-fetching build files · download-URL deltas on fetching build files · Agents mode in the Code Browser with the 3-D agent map as a first-class view · download MULTI-CORE ENGINE — new in v1.9.7: scans use every core with byte-identical results — large scans roughly halved — plus Code Browser inheritance, a sortable class-complexity view and a density dial on the class visualiser · download BUILD-FILE ALERTS — new in v1.9.6: a scan that compares two versions now flags every build/CI/packaging file that changed — the xz-utils entry route — install hooks first, in the GUI, the agent report and the PR comment · download THE CODE BROWSER — new in v1.9.5: the diff and the whole project's structure in one page — Changes, Overview, Files, Classes and Visualiser tabs, a directory tree, a class index with methods at file:line, a 3D include map and a class ego view coloured by this scan's churn · download THE AUDITED DIFF — new in v1.9.4: a rebuilt diff (now the Code Browser’s Changes tab) where every counter is a claim you can click, walk and cite — plus moves tracked across files and git overlays showing AI provenance, age of destroyed code and per-author churn · download TRACEABLE NUMBERSv1.9.3 fixes the PR comment’s generated-file count: it now counts only the generated files that churned in your PR, so the number traces to the diff · download TRUE_CHURN IN CI — new in v1.9.2: pull-request comments now separate authored churn from generated churn — in a real npm/cli release, 80.1% of the churn came from one lockfile · read the paper TRUE_CHURN — new in v1.9.1: separating authored code from generated code — lockfile and codegen churn subtotalled, TRUE_CHURN = what your developers actually wrote · plus Agent Infrastructure: rogue agents and committed agent credentials found in your tree · download NEW PAPER — why LLOC is what really counts: a 35-line file holds 5 working statements, and a 12-line churn was really 1 · read the paper NEW MEASUREMENT — 28.4% of NVIDIA’s open GPU driver tree is data, not code — single statements up to 3MB · read how it was found NEW REPORT — six and a half years of Erlang/OTP, measured statement by statement — and what a line counter misses · read the report WE SCANNED CHROMIUM — 43.5 million lines of code, one command, one laptop · read the report NEW PAPER — AI-assisted development barely edits code, it replaces it: established projects rework 1 statement in 6, agent-built code 1 in 500 · read Paper C v1.9.0 released — all non-specified programming languages churned as U_LOC · TOTAL LOC · spreadsheet report columns · full coverage accounting · download LIVE DEMO — watch CodeDelta report on a real pull request · view on GitHub BUSINESS LANGUAGE BUNDLE added for the finance industry — COBOL, JCL, PL/I · see the languages FREE TO TEST until 31 October 2026 — two lines in a workflow, no signup · run it in CI ENCODED PAYLOADS AND A FASTER, STRICTER AGENT SCANv2.0.2: a second pass decodes base64, hex and compressed literals and rates hidden AI code that the file executes CRITICAL · the rogue-agent pattern is CRITICAL in every scanned language · Ruby and C# false CRITICALs removed · agent scan start-up 25 s → 0.1 s on a 115 MB tree · Metrics + Agent Scan runs from the GUI again · every demo opens an in-tool source page verified against a frozen baseline · download VERSION 2.0.1v2.0.1: the metric definitions moved (a move is not churn, braces never count, unclassified text out of the totals) so 1.9 and 2.0 numbers are not comparable · 114 known-answer fixtures behind the engine · every headless mode licence-gated · the Action reads its gate rules from the base branch · download SECURITY RELEASEv1.9.9: AI-BOM provider counts made exact (one provider however the code spells it; frameworks reported separately) · the agent map folds to match · committed credentials, build surface and the AI-vs-exec-only split now in the machine-readable JSON · download CODE DELTA THREAT DETECTION AND CODE SECURITY TOOL PORTFOLIO — EXPANDED AND UPGRADEDv1.9.8: committed credentials found and shown redacted · merge gates for credentials, new install hooks and new remote-fetching build files · download-URL deltas on fetching build files · Agents mode in the Code Browser with the 3-D agent map as a first-class view · download MULTI-CORE ENGINE — new in v1.9.7: scans use every core with byte-identical results — large scans roughly halved — plus Code Browser inheritance, a sortable class-complexity view and a density dial on the class visualiser · download BUILD-FILE ALERTS — new in v1.9.6: a scan that compares two versions now flags every build/CI/packaging file that changed — the xz-utils entry route — install hooks first, in the GUI, the agent report and the PR comment · download THE CODE BROWSER — new in v1.9.5: the diff and the whole project's structure in one page — Changes, Overview, Files, Classes and Visualiser tabs, a directory tree, a class index with methods at file:line, a 3D include map and a class ego view coloured by this scan's churn · download THE AUDITED DIFF — new in v1.9.4: a rebuilt diff (now the Code Browser’s Changes tab) where every counter is a claim you can click, walk and cite — plus moves tracked across files and git overlays showing AI provenance, age of destroyed code and per-author churn · download TRACEABLE NUMBERSv1.9.3 fixes the PR comment’s generated-file count: it now counts only the generated files that churned in your PR, so the number traces to the diff · download TRUE_CHURN IN CI — new in v1.9.2: pull-request comments now separate authored churn from generated churn — in a real npm/cli release, 80.1% of the churn came from one lockfile · read the paper TRUE_CHURN — new in v1.9.1: separating authored code from generated code — lockfile and codegen churn subtotalled, TRUE_CHURN = what your developers actually wrote · plus Agent Infrastructure: rogue agents and committed agent credentials found in your tree · download NEW PAPER — why LLOC is what really counts: a 35-line file holds 5 working statements, and a 12-line churn was really 1 · read the paper NEW MEASUREMENT — 28.4% of NVIDIA’s open GPU driver tree is data, not code — single statements up to 3MB · read how it was found NEW REPORT — six and a half years of Erlang/OTP, measured statement by statement — and what a line counter misses · read the report WE SCANNED CHROMIUM — 43.5 million lines of code, one command, one laptop · read the report NEW PAPER — AI-assisted development barely edits code, it replaces it: established projects rework 1 statement in 6, agent-built code 1 in 500 · read Paper C v1.9.0 released — all non-specified programming languages churned as U_LOC · TOTAL LOC · spreadsheet report columns · full coverage accounting · download LIVE DEMO — watch CodeDelta report on a real pull request · view on GitHub BUSINESS LANGUAGE BUNDLE added for the finance industry — COBOL, JCL, PL/I · see the languages FREE TO TEST until 31 October 2026 — two lines in a workflow, no signup · run it in CI

CodeDeltaTrue Churn
for the AI era!

Your diffs got enormous, your tools count lines, and machines now write half the code. CodeDelta measures what actually changed — every statement added, deleted, or repaired, from one pull request to forty-three million lines of Chromium.

  keep scrolling  
43,500,000
lines of Chromium — a year of the world's browser codebase, measured in one command on a laptop
80.1%
of one real release's "churn" came from a single generated file — TRUE_CHURN separates authored work from tool noise
1 in 6  vs  1 in 500
statements repaired in place: hand-maintained code vs an agent-built codebase — the AI signature, measured not guessed

Everything in the box

Statement-level churnadded / deleted / edited in place — LLOC, SLOC, files
Code Browserside-by-side diff; every change classified and coloured
TRUE_CHURNgenerated files subtotalled out, rule by named rule
Longitudinal trend databaseevery release measured against the last
Baselines & merge gatesblock PRs on new findings or policy breaches
Agent ScanAI SDKs, model calls, exec-on-model-output — file & line
AI Bill of Materialsnative or CycloneDX, from the same scan
Data metricsworking code split from data; REWORK without the noise
GUI + reportschurn, AI audit and agent reports, CSV/JSON/SARIF
CLI & CIGitHub Action, GitLab CI, Jenkins, Docker, MCP server
55 languagesparsed as written, coverage stated on every run
Runs where you runyour machine, your CI — nothing leaves your repo

New to the terms? The Management Brief — every term in 60 seconds, printable →

Command line
The same scan, headless — run it in a terminal, in CI, or on a schedule.
One command compares two snapshots, prints the churn summary — changed, deleted, added and total churn for LLOC and SLOC — then writes the full HTML report and the Code Browser.
GUI report
The report CodeDelta produces from the run. Click play to watch it build.
CodeDelta — report
v1.7 v1.8 · 7 files · 242 SLOC · 153 LLOC
The HTML report: per-file CHG / DEL / ADD / CRN and REP_CHURN with churn bars — every figure inspectable, all local.
SLOC physical lines · LLOC logical (statement) lines — reformatting doesn't inflate LLOC.   CHG changed · DEL deleted · ADD added · CRN churn = CHG + DEL + ADD · REP_CHURN = (ADD + DEL) / CRN, 0–1 — how much of the change was wholesale replacement.

Built on 20 years of churn-measurement heritage. Its predecessor was used by

AMD  ·  Cisco  ·  IBM  ·  Lockheed Martin  ·  Raytheon  ·  Nokia  ·  Ericsson  ·  Siemens  ·  Sony  ·  General Dynamics
Two instruments in one

Changed-LLOC churn measurement and AI agent detection, on the same codebase.

CodeDelta does two things from a single analysis: it measures exactly what changed between two versions — changed LLOC, SLOC and files — and it scans that same code for where it uses AI, flagging the risky patterns. Both run locally, both produce verifiable per-file reports.

CHURNTwo-snapshot measurement

Quantifies added, deleted, changed, and unchanged lines between two versions of a project — per file and in aggregate.

CHURNPhysical & logical

Counts both SLOC (physical) and LLOC (statement-level) with per-language tokenizers, so reformatting doesn't inflate the result.

CHURNVerifiable output

Every classification is inspectable in a per-line report. The numbers can be audited, not just trusted.

AIDetects AI-generated code

Audits added and changed code for stylometric signals consistent with machine generation, and reports how much of a change is likely AI-written.

AIPer-file, flagged

Flags individual files and reports the proportion of new code matching machine-generation signals — surfacing where to focus human review.

AIHonest signals

Reported as signals for review, with the method and its limits documented in an open technical paper — not presented as infallible proof.

BOTH55 languages

C/C++, Java, C#, Python, JavaScript/TypeScript, Go and more, detected automatically by extension. See all 36 →

BOTHLocal & offline

Runs entirely on your machine. No source code leaves your environment. Results accumulate in a local store for trend analysis.

BOTHOne report

Churn metrics and AI-audit findings appear together in a single per-file HTML report you can inspect and share internally.

Built for your pipeline

Integrates where your team already works.

CodeDelta is a command-line instrument first. It reads straight from git, runs headless in CI, gates merges on churn or new AI findings, and exposes itself to AI coding agents — so its deterministic numbers land in the tools your developers and reviewers already use, not in a separate dashboard nobody opens.

GITScan straight from git

Compare any two refs — --git v1.7..v1.8 or HEAD~10..HEAD — with no working-copy juggling. Snapshot dates come from commit history, so a whole release timeline backfills in one pass.

DIFFSee every change, classified

The Code Browser’s side-by-side diff colours every statement by what happened to it — added, deleted, edited in place — so a review starts from the change map, not a wall of green and red.

CIGate every pull request

A drop-in GitHub Action (code-delta-app/action@v1) wires CodeDelta into any repo in a dozen lines. Builds branch on its exit codes — fail on excess churn, on AI percentage, or only on findings newer than a committed baseline — and results post as SARIF plus a PR summary, inline on the diff and in the code-scanning tab.

TRUEChurn without the noise

TRUE_CHURN subtotals generated files — lockfiles, bundles, generator output — out of the headline number, rule by named rule, so the figure describes what your team wrote.

GOVAI Bill of Materials

Export an inventory of every AI provider, endpoint and jurisdiction your code reaches — native or CycloneDX — and gate the build on policy: block egress to foreign-hosted models or unapproved providers. The artifact auditors and AI-governance programmes ask for.

GOVShadow-AI & rogue agents

Agent Scan inventories the agent infrastructure in your tree — workspaces, MCP configs, rogue-agent residue, committed credentials — each a named path in the report and AI-BOM. Produced from source, offline; gate the build on it only if your policy says so.

AGENTSAI agents call the engine

An MCP server lets Claude Code, Cursor and other assistants run CodeDelta directly — so "how much churn since v1.7?" returns the tool's reproducible numbers, not an improvised guess.

DATARaw output for tooling

Every analysis exports CSV and JSON beside the HTML report — feed trend dashboards, spreadsheets, or your own scripts. Nothing is locked inside the report.

TRENDExecutive summary

Runs accumulate in a local database; a one-page summary charts churn and AI% across releases for the people who approve the work, not only those who run the scan.

In your pipeline

Most teams never open the app — it runs in CI, or on a schedule.

CodeDelta is a command-line engine first. Drop the GitHub Action into a repo and every pull request gets churn and AI findings posted back as a comment — with an optional gate that blocks the merge. Or run the same binary from cron for a nightly trend. Nothing is installed on a developer's machine, and the code never leaves your runner.

.github/workflows/codedelta.yml
name: CodeDelta on: pull_request jobs: codedelta: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: { fetch-depth: 0 } - uses: code-delta-app/action@v1 with: mode: churn_agent # the default: churn + Agent Scan (both adds the ML audit) fail-on-new: "true" # block merge on new findings gate: "true" # block egress to CN/RU/KP/IR bom: ai-bom.json # write an AI Bill of Materials
cron / batch — same engine, no GitHub
# nightly: diff the last commit, append to a trend DB $ codedelta --git HEAD~1..HEAD --db trend.db --csv churn.csv
What it posts back on the pull request
CodeDelta's comment on a pull request — churn, AI audit and agent scan — with the merge gate
The comment on every pull request. Churn (with REP_CHURN), AI audit and agent scan posted inline — plus the merge gate, which blocks on new findings when you turn it on.
CodeDelta running as a job in CI — fetch engine, run on the diff, post comment, all steps green
…and the job that posts it. CodeDelta running inside the pipeline — fetch engine, run on the PR diff, post the comment — every step green, 18 seconds.
The output

What CodeDelta produces.

A single run generates a per-file HTML report covering churn, the AI code scan and the agent scan, plus the Code Browser (tree, classes, and a side-by-side diff) — all inspectable, all local. Every figure below is real output from the tool.

CodeDelta desktop app — analysis modes and Try-It demos
The desktop app. Pick an analysis mode, point it at two snapshots or a single project, and read churn, the AI code scan and the agent scan in one local window — no code leaves your machine.
CodeDelta churn results for FFmpeg 6.0 to 7.0 — 131,142 statements of churn across 8,580 files and 2.08M lines, with TRUE_CHURN, generated churn and data share tiles
A real release pair, measured. FFmpeg 6.0 → 7.0 — 8,580 files, 2.08M lines: 131,142 statements of churn, TRUE_CHURN separating the 27 generated statements, every tile defined on hover. One scan, one laptop.
CodeDelta churn report — 1,000 files, 170 changed, REP_CHURN 0.46
Churn report. 1,000 files, 170 changed — per-file CHG / DEL / ADD across SLOC & LLOC, with REP_CHURN (the share of change that was wholesale replacement) at 0.46.
CodeDelta AI Code Scan — 1,000 files, 1 HIGH, 395 ELEVATED, ~39% generated-code characteristics
AI Code Scan. 1,000 files scored — 1 HIGH, 395 ELEVATED, ~39% of flagged code showing generated-code characteristics. A review aid, never an authorship verdict.
CodeDelta Code Browser — 170 changed files, side-by-side SLOC/LLOC view
Code Browser. Every changed file side by side — toggle SLOC / LLOC and full-file / changes-only; each line classified changed, added or deleted.
CodeDelta Code Browser — class ego view, 2,000 classes, folly at the centre
Class ego view. One class at the centre (here folly, across 51 files), its methods round it — red where this scan churned them — and the classes its code mentions as satellites; every link cites the file and line of the mention. A pointer for review, not a resolved call graph.
CodeDelta Agent Scan — 3 HIGH, 7 ELEVATED, governance roll-up flagging data egress to a non-allied jurisdiction
Agent Scan. Where code actually calls AI — SDK imports, raw endpoints, exec-on-model-output. Here 3 HIGH / 7 ELEVATED, with a governance roll-up flagging 3 files that send data to a non-allied jurisdiction.
CodeDelta flagged source — rogue_executor.py, AIS 100, exec() on model output
Every flag is inspectable. Click a flagged file to read the exact lines — here rogue_executor.py (AIS 100), with exec() on model output caught as the rogue-agent pattern.
CodeDelta scan results — project metric tiles, AI Code Scan 1 HIGH / 395 ELEVATED / 39% AI, Agent Scan all clear
Live scan results. Project metric tiles the moment a scan finishes — then the AI Code Scan (1 HIGH, 395 ELEVATED, ~39% AI) and Agent Scan verdicts with one-click reports.
CodeDelta class visualiser — OpenCV's dnn drawn at expanded density, churned methods in red and amber, connected classes ringed around it
Dial the detail. OpenCV’s dnn from a real 4.8 → 4.10 churn scan — 240 of its 770 methods drawn, ranked by churn then size, red and amber where this release changed them, the classes it mentions ringed around. Step the density up or down; every dot names itself on hover.

Real output from CodeDelta — every figure above is produced by the tool from an actual scan, not a mock-up.

Method

Two methods, documented openly.

Churn: CodeDelta reports changed, added and deleted logical lines (LLOC), physical lines (SLOC) and files between two snapshots. It aligns each file pair with a longest-common-subsequence algorithm — once over physical lines, once over a logical-statement token stream — with a second pass disambiguating repeated tokens using scope-qualified anchors, so reformatting never inflates the count.

Agent Scan: the same code is scanned for where it calls AI — agent-SDK imports, model endpoints, exec-on-model-output and prompt-injection patterns — and rolled into an AI Bill of Materials covering every provider, endpoint and jurisdiction. Findings are flagged for security review, not asserted as malicious.

The churn algorithm and the AI detection methods — with their limits — are documented in open technical papers written to be independently verifiable.

Read the technical papers →

  • CHG

    Changed

    Logical (LLOC) and physical (SLOC) lines modified in place between two snapshots — the core signal.

  • ADD

    Added

    New logical and physical lines, and newly-added files, in the later snapshot.

  • DEL

    Deleted

    Logical and physical lines, and whole files, removed from the earlier snapshot.

  • CRN

    Total churn

    Changed + added + deleted — per file and across the whole project, in both LLOC and SLOC.

  • REP

    Replacement churn

    How much of the change was wholesale replacement rather than edits in place — (added + deleted) ÷ total churn, bounded 0–1. A high ratio can indicate AI-generated code, where whole blocks are regenerated rather than edited.

  • AGENT

    AI agent scan

    Finds where code calls AI — SDK imports, model endpoints, exec-on-model-output — and inventories it as an AI Bill of Materials.

At a glance
2
Instruments: churn + AI agent scan
36
Languages auto-detected
100%
Local — no code uploaded
Mac / Win / Linux
Cross-platform

Evaluate it on your own codebase.

Download a time-limited trial license and run CodeDelta locally. No source code is transmitted.

Try CodeDelta