Repository Analyses

Nightly hotspot reports for popular open-source repositories. Each report ranks functions by activity-weighted risk — complexity × recent commit frequency — and labels the antipatterns driving the score.

portainer/portainer typescript

portainer's Kubernetes and API layer — 5 high-activity-risk functions to address first

Five functions in portainer/portainer sit in the 'fire' quadrant right now — structurally complex and touched within the last week. Any engineer shipping changes to the Kubernetes ingress UI or the endpoint/registry update handlers this week is working inside the highest-risk surface in the codebase.

exit_heavygod_function
Jun 4 Read →
NervJS/taro typescript

NervJS/taro's transformer layer carries the highest structural debt — 5 functions to fix

The riskiest code in NervJS/taro isn't what's changing right now — it's what stopped changing 133 days ago and was already too complex to reason about when it did. Five functions in the transformer and convertor packages have accumulated cyclomatic complexity scores between 55 and 88, nesting depths up to 10, and fan-out counts as high as 163, with zero commits in the last 30 days and no active owners visible in the data.

complex_branchingdeeply_nested
Jun 3 Read →
outline/outline typescript

outline/outline's editor and WebSocket queue carry the highest activity risk — 5 hotspots

A Hotspots analysis of outline/outline at commit 7e252f0, surfacing the top functions by activity-weighted risk score.

complex_branchingdeeply_nested
Jun 2 Read →
supabase/supabase typescript

supabase's type parser and storage explorer are the highest risks — all 5 touched today

Every function in supabase's top-five hotspot list was touched in the last day. Two of them share a single file in the docs layer. One has fan-out into 173 distinct callees. The structural debt isn't theoretical — it's actively compounding.

exit_heavycomplex_branching
Jun 2 Read →
RSSNext/Folo typescript

Folo's UI and integration layer has the highest activity risk — 5 functions to address

Across 3,823 functions in RSSNext/Folo, the five highest-risk functions are all fire-quadrant — structurally complex and actively changing at the same time, not backlog items. The most striking case is a JSON tokenizer duplicated across two packages with a cyclomatic complexity of 47, sitting in the fire quadrant alongside a keyboard-simulation function carrying a CC of 61.

exit_heavycomplex_branching
Jun 1 Read →
Kong/insomnia typescript

Kong/insomnia's rendering and sync layer carries the highest activity risk — 5 functions to address first

Five functions in Kong/insomnia are both structurally complex and actively changing right now — the top-ranked `clientAction` carries an activity-weighted risk score of 18.66 with a cyclomatic complexity of 63, and it was touched 9 days ago. For any engineer shipping against this codebase this week, that combination is a live regression risk, not a backlog item.

complex_branchingdeeply_nested
May 31 Read →
elysiajs/elysia typescript

elysiajs/elysia's core index carries the highest activity risk — 5 functions to address first

Across 282 functions in elysiajs/elysia, I found 12 in the 'fire' quadrant — structurally complex and actively changing right now — with the worst concentrated inside a single file. If you're shipping code against this repo this week, `src/index.ts` is where regressions are most likely to originate.

long_functioncomplex_branching
May 30 Read →
remotion-dev/remotion typescript

Remotion's compositor and media-parser carry the highest activity risk — two to fix first

The two highest-risk functions in remotion-dev/remotion were both modified yesterday and together exhibit cyclomatic complexity scores of 53 and 118 — meaning each one branches across dozens of independent execution paths while still actively receiving changes. That combination is a live regression risk, not a backlog item.

complex_branchingexit_heavy
May 30 Read →
novuhq/novu typescript

novuhq/novu's framework layer carries the highest activity risk — 2 functions to address first

The two highest-scoring functions in novu's codebase aren't application code at all — they're vendored library internals bundled directly into packages/framework/src/jsonSchemaFaker.js, and they're being attributed commit activity right now. That conflation of third-party complexity with first-party churn is itself the finding worth unpacking.

complex_branchingdeeply_nested
May 29 Read →
appsmithorg/appsmith typescript

appsmith's bundled ECharts tops activity risk — 5 functions to address first

Four of appsmith's five top-ranked hotspots live inside a single bundled third-party file. The fifth — evaluateTree, in the data evaluation worker — is genuine application logic that will move to rank one after the ECharts bundle is excluded. For the four bundle entries, the action isn't a refactoring sprint; it's an exclusion rule and a package-manager migration.

complex_branchingcyclic_hub
May 28 Read →
trpc/trpc typescript

trpc/trpc's HTTP core carries the highest structural debt — 5 functions to address first

The most structurally risky code in trpc/trpc isn't in active churn right now — it's sitting untouched for nearly two months while accumulating the kind of fan-out and branching complexity that makes the next change to it a genuine regression risk. Of 1,438 functions analyzed, 50 landed in the critical band, and the top two haven't been touched in 59 days.

god_functionlong_function
May 27 Read →
koajs/koa javascript

koajs/koa's response layer carries the highest structural risk — 5 functions to address first

Koa's response pipeline is carrying the most structural weight: the respond function in lib/application.js has accumulated god-function complexity with 26 independent execution paths and hasn't been touched in over seven months — meaning the next change there arrives against a high-complexity backdrop with no recent test pressure. Meanwhile, the set function in lib/response.js was modified today, making it the only live regression risk in the repository right now.

complex_branchingexit_heavy
May 26 Read →
sudheerj/reactjs-interview-questions javascript

reactjs-interview-questions' coding-exercise carries the highest risk — 2 functions first

The coding-exercise module in reactjs-interview-questions has quietly accumulated structural debt in two functions that haven't been touched in months — one of them for over 750 days. When development next reaches this corner of the repo, the blast radius will be wider than the file size suggests.

exit_heavy
May 25 Read →
twentyhq/twenty typescript

twentyhq/twenty sandbox and rendering hotspots — 5 functions to address first

Two critical-band functions — a spreadsheet recalculation engine buried inside a sandbox script and a halftone canvas renderer with 140 distinct callees — are both structurally complex and were touched just three days ago, making them live regression risks rather than backlog cleanup items. With 647 critical functions across 16,560 total, Twenty's codebase is actively scaling, and these two hotspots sit at the intersection of structural complexity and ongoing churn.

complex_branchinggod_function
May 25 Read →
calcom/cal.com typescript

cal.com's booking layer carries the highest activity risk — 5 functions to address first

Three of cal.com's top five hotspots are named `handler` — all in the booking layer. One has a cyclomatic complexity of 243.

complex_branchingexit_heavy
May 24 Read →
chakra-ui/chakra-ui typescript

chakra-ui's codemod layer carries the highest activity risk — 2 functions to address first

Chakra-ui's codemod layer is where structural complexity and live commit activity collide: two functions in that package hold critical-band risk scores and were each touched within the past month, making them live regression risks rather than backlog items. If you're shipping codemod tooling for a major migration, these are the two functions that deserve a closer look before the next release.

complex_branchingdeeply_nested
May 24 Read →
typescript-cheatsheets/react typescript

typescript-cheatsheets/react's tooling layer carries the highest activity risk — 2 functions to address first

Even documentation-focused repos accumulate structural and operational risk in their tooling. In typescript-cheatsheets/react, the readme generator and the homepage component are the two functions most worth watching right now — both touched within the last day, and both carrying fan-out that means changes ripple into several downstream dependencies.

long_function
May 24 Read →
go-gorm/gorm go

go-gorm/gorm's schema debt leads the risk list — 5 functions to address first

gorm's highest-risk functions are mostly quiet right now, but they carry heavy structural debt: schema field setup, condition building, association saving, schema parsing, and create-value conversion all combine high branching with deep nesting or broad fan-out. The next change in these paths will inherit months of dormancy plus dense control flow.

complex_branchingdeeply_nested
May 23 Read →
rustfs/rustfs rust

rustfs storage and protocol hotspots — 5 functions to address first

In rustfs, the highest-priority functions are not concentrated in one subsystem: storage healing, Swift request handling, scanner traversal, lifecycle evaluation, and object listing all appear in the top five. The common theme is structural density — every listed function combines complex branching, deep nesting, exit-heavy flow, god-function scope, and long-function shape.

complex_branchingdeeply_nested
May 23 Read →
google/langextract python

langextract's batch provider and extraction carry the highest activity risk — 5 hotspots

langextract's core extraction and OpenAI batch provider are both structurally overloaded and actively changing right now — a combination that puts live regression risk on the table, not just future cleanup. With 72 critical-band functions across 348 total, the codebase has meaningful structural debt concentrated in exactly the modules users interact with most.

exit_heavygod_function
May 22 Read →
sudheerj/javascript-interview-questions javascript

javascript-interview-questions' deepMerge carries the highest risk — 1 function to address first

A repository built to demonstrate JavaScript mastery has one function quietly accumulating structural debt: deepMerge, untouched for over five months, carries every quality signal worth watching before the next contributor opens it up.

May 21 Read →
abhigyanpatwari/GitNexus typescript

GitNexus's ingestion core carries the highest activity risk — 2 functions to address first

At the heart of GitNexus's ingestion pipeline, two functions are simultaneously the most structurally complex and the most actively changed code in the entire codebase — a combination that turns every commit into a live regression risk. With 544 critical-band functions across 3,612 total, the scope of structural debt here is significant, but two functions demand attention right now.

complex_branchingdeeply_nested
May 20 Read →
ajeetdsouza/zoxide rust

zoxide's import layer carries the highest activity risk — 3 functions to address first

zoxide's import subsystem is live regression territory right now: two actively changing functions carry cyclomatic complexity of 16–19 while a utility god-function hasn't been touched in 606 days but carries a blast radius of 14 distinct callees.

exit_heavycomplex_branching
May 19 Read →
labstack/echo go

echo's binding layer carries the highest activity-weighted risk — 5 functions to address

echo's request binding owns the top two risk slots — `bindData` calls 41 distinct functions while `bindValue` branches across 29 execution paths, both in actively committed code across a framework trusted by thousands of Go services.

exit_heavygod_function
May 19 Read →