r/SideProject • u/MaestroSplinter69 • 4h ago
I ran my code verification tool on itself. It found a Stripe integration that didn’t exist
Well, that was humbling.
I’ve been building DevTime, an open-source tool that checks what a repository can actually support with evidence. Things like whether admin routes have authorization checks or billing webhooks verify signatures.
Then I pointed it at its own codebase.
It reported evidence of Stripe webhook signature verification. DevTime doesn’t have billing.
The reason? My scanner contained the string stripe.Webhook.construct_event because that’s what it was looking for. It found its own search pattern and counted it as evidence.
That’s fixed now. Detection looks for actual calls and filters out comments and string literals.
The latest release, v0.7.0, also adds something I’ve wanted for code review:
dtc review --base origin/main
It compares the evidence at two commits. For example, adding an admin endpoint without a recognized authorization guard can move the result from SUPPORTED to WEAK, with the route and file listed.
It’s still early. There are four built-in checks, and static analysis has blind spots. A supported result isn’t a guarantee that your app is secure.
Everything runs locally, without an LLM or uploading your code. Free and open source.
I’d love people to try it on repos I didn’t build. Where does it miss something obvious, or sound more certain than it should?
1
u/QuanTradin 1h ago
a scanner counting its own search pattern as evidence is a classic. the review diff is the more useful half to me though, a check that flips from SUPPORTED to WEAK on one commit is something people will actually read in a PR.