Evidence captured at orders.service.ts:7
Your cloud isn’t expensive. Your code is.
Vellox parses JavaScript, TypeScript, and Python locally, finds query loops and async patterns that collapse under load, and analyzes SQL down to the exact file and line. No daemon, database connection, account, or invented savings.
A red dashboard isn’t an answer. Your team needs the query, the root cause, and the fix — before the bill arrives.
From project to evidence.
Resolve imports, aliases, barrels, classes, and call chains across JS/TS and Python, then inspect SQL, schemas, and PostgreSQL plans without executing the application.
From finding to action.
Trace hidden N+1 work to the database, distinguish proven bounds from dangerous fan-out, and keep every recommendation reviewable.
One scan. Inspectable evidence.
Vellox turns structural JavaScript, TypeScript, Python, and SQL patterns into deterministic findings your team can inspect, baseline, and gate.
- export async function getOrders(userId) {
- const orders = await prisma.order.findMany({
- where: { userId },
- });
- for (const order of orders) {
- order.items = await prisma.item.findMany({
- where: { orderId: order.id },
- });
- }
- return orders;
- }
Fetch or mutate the records in bulk.
Remove the N+1 database round trips.From source to CI evidence.
One local pipeline from deterministic scan to a machine-readable gate.
Inspect the project where it already lives.
Vellox reads supported source and schema files locally. It does not execute code, connect to a database, or upload the project.
Make every finding auditable.
Each result carries a rule, severity, exact location, redacted evidence, recommendation, and stable fingerprint.
Suggest the action. Keep humans in control.
Code findings receive guidance; eligible schema findings can produce dialect-aware SQL suggestions. Nothing runs automatically.
Block only what your policy forbids.
Budgets and baselines let CI fail on new critical, high-severity, or secret findings without inventing a financial score.
npx vellox scan .
One finding. Every claim traceable.
HIGHrule
sequential asyncEVIDENCEawait prisma.item.findMany
inside loopfingerprint
stable SHA-256source line
orders.ts:7
A concrete next step, not fabricated code.
await database work
inside an iterationBatch the operation
or use bounded parallelismVellox does not edit this file.
The engineer chooses the implementation.Real exit code. Explicit threshold.
Deep enough for engineers. Clear enough for everyone.
See scaling risks across the architecture.
A monorepo-aware call graph follows ESM, CommonJS, Python modules, workspace packages, nested aliases, classes, and constructor injection to expose N+1 calls and query fan-out across files.
Your source stays on your machine.
The CLI reads files and writes a local report. No daemon, account, database connection, container, or code execution.
Use the same truth everywhere.
Pretty output, JSON, Markdown, SARIF, baselines, and CI all consume the same findings.
Scan the paths that shape throughput.
Project call graphs, request-to-query dataflow, and conservative query/schema index evidence with explicit fallback.
Stop new risks before deploy.
Fail pull requests on policy violations or incomplete analysis, with every skipped and fallback file reported.
Evidence in. Evidence out.
The scanner, reports, migrations, CI gate, and SARIF output now share one inspectable finding contract.
Workflow, framework fixtures, query/schema indexes, SQL syntax, measured plans, and a 142-case labelled precision corpus across JavaScript, TypeScript, Python, and SQL.
AST and CST parsers connect imports, wrappers, callbacks, DI, functions, classes, async boundaries, and ORM calls across the project.
Every supported signal has an inspectable ID, severity, confidence, evidence, and action.
Compare median execution time, buffers, node executions, disk spills, and plan findings from exported PostgreSQL measurements.
Scan. Adopt. Protect.
Stop after the first command for a local diagnosis. Continue when the findings are reviewed and your team is ready to guard every pull request.
See the risks.
Scan the current project and save an inspectable report. No account, upload, database connection, or code execution.
npx --yes velloxAdopt without noise.
Record only the current findings your team reviewed, so rollout starts by protecting new code instead of blocking old debt.
npx --yes vellox baselineStop regressions.
Create a GitHub Actions gate with SARIF evidence while preserving workflows that already belong to your repository.
npx --yes vellox ci