Skip to main content

RepoCure

Diagnose your repository. Cure what matters.

RepoCure is a fast, local-first Python CLI that scans a software project, assigns a health score, and produces actionable findings without uploading source code.

Features

  • Security checks for likely secrets, private keys, unsafe eval, and shell execution.
  • Dependency, documentation, tests, Git, Docker, and Python performance checks.
  • Text, JSON, Markdown, standalone HTML, and SARIF reports.
  • CI-friendly score thresholds and analyzer selection.
  • Offline by default: source code never leaves your machine.

Quick start

pip install repocure
repocure scan .

Generate a shareable report:

repocure scan . --format html --output repocure-report.html

Fail CI when the score is below 80:

repocure scan . --fail-under 80

Run one analyzer:

repocure scan . --analyzer security

Status

RepoCure findings are review signals and may include false positives; they are not proof of a vulnerability.

Contributing

See CONTRIBUTING.md. Security reports should follow SECURITY.md.

License

MIT

Metadata

Release files for repocure 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for repocure 1.0.0
File Size Uploaded
repocure-1.0.0.tar.gz 13.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for repocure 1.0.0
File Interpreter ABI Platform
repocure-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 26.1 kB

Release files / repocure-1.0.0.tar.gz

Download URL repocure-1.0.0.tar.gz
Size 13.1 kB
Tags Source
SHA-256 checksum
How to use checksums
357d1503824af34799ad4b12c317ced66d87e6a16783574b61663e2172af7a4c
BLAKE2b-256 checksum
How to use checksums
4952b988dccc9432e2025d81d16753d47fb16b0f99e0d322f5405d30a1ec71ad
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / repocure-1.0.0-py3-none-any.whl

Download URL repocure-1.0.0-py3-none-any.whl
Size 13.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
82997e55717058c4f506de557d8caef77d086d268babdc5e6b9b177c3b914957
BLAKE2b-256 checksum
How to use checksums
f36f98c59fc72f4dd20b1c0528ed4ab6af02a1abc8287c8ea58bd89bfa30b20e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page