npm Latest release ↗

Your cloud isn’t expensive. Your code is.

Vellox parses JavaScript, TypeScript, and Python locally, finds query loops and async patterns that collapse under load, and analyzes SQL down to the exact file and line. No daemon, database connection, account, or invented savings.

JSONOne evidence artifact
SARIFNative CI findings
0 execNever applies DDL
100%Advisory by default
TypeScriptJavaScriptPythonSQLPrismaSQLAlchemyNode.jsFastAPIPostgreSQLSARIF

A red dashboard isn’t an answer. Your team needs the query, the root cause, and the fix — before the bill arrives.

From project to evidence.
Resolve imports, aliases, barrels, classes, and call chains across JS/TS and Python, then inspect SQL, schemas, and PostgreSQL plans without executing the application.

From finding to action.
Trace hidden N+1 work to the database, distinguish proven bounds from dangerous fan-out, and keep every recommendation reviewable.

Local code intelligence

One scan. Inspectable evidence.

Vellox turns structural JavaScript, TypeScript, Python, and SQL patterns into deterministic findings your team can inspect, baseline, and gate.

REAL RULES / EXAMPLE SOURCE — orders.service.ts
SourceTypeScript
  1. export async function getOrders(userId) {
  2. const orders = await prisma.order.findMany({
  3. where: { userId },
  4. });
  5. for (const order of orders) {
  6. order.items = await prisma.item.findMany({
  7. where: { orderId: order.id },
  8. });
  9. }
  10. return orders;
  11. }
Scan complete1 evidence-backed finding
High
01
Database operation inside a loop

Evidence captured at orders.service.ts:7

HIGH
Scanner recommendationFetch or mutate the records in bulk.
Remove the N+1 database round trips.
How Vellox works

From source to CI evidence.

One local pipeline from deterministic scan to a machine-readable gate.

01 / SCAN

Inspect the project where it already lives.

Vellox reads supported source and schema files locally. It does not execute code, connect to a database, or upload the project.

02 / EVIDENCE

Make every finding auditable.

Each result carries a rule, severity, exact location, redacted evidence, recommendation, and stable fingerprint.

03 / REVIEW

Suggest the action. Keep humans in control.

Code findings receive guidance; eligible schema findings can produce dialect-aware SQL suggestions. Nothing runs automatically.

04 / GATE

Block only what your policy forbids.

Budgets and baselines let CI fail on new critical, high-severity, or secret findings without inventing a financial score.

Vellox / local scan pipeline
Actual CLI contract / example fixture

npx vellox scan .

INPUT
local
CODE
1 file
RULE
1 match
REPORT
JSON
0Code executed
0DB connections
1Finding
Evidence contract

One finding. Every claim traceable.

severity
HIGH
rule
sequential async
EVIDENCEawait prisma.item.findMany
inside loop
fingerprint
stable SHA-256
source line
orders.ts:7
Human-reviewable guidance

A concrete next step, not fabricated code.

Observedawait database work inside an iteration
RecommendationBatch the operation or use bounded parallelism
Safety boundaryVellox does not edit this file.
The engineer chooses the implementation.
Policy gate

Real exit code. Explicit threshold.

EXIT 11 high finding × maxHigh 0
Baseline awareSecret gateNo money score
Built for the real stack

Deep enough for engineers. Clear enough for everyone.

01 / PROJECT INTELLIGENCE

See scaling risks across the architecture.

A monorepo-aware call graph follows ESM, CommonJS, Python modules, workspace packages, nested aliases, classes, and constructor injection to expose N+1 calls and query fan-out across files.

02 / LOCAL BY DESIGN

Your source stays on your machine.

The CLI reads files and writes a local report. No daemon, account, database connection, container, or code execution.

03 / EVIDENCE CONTRACT

Use the same truth everywhere.

Pretty output, JSON, Markdown, SARIF, baselines, and CI all consume the same findings.

04 / CODE + SQL

Scan the paths that shape throughput.

Project call graphs, request-to-query dataflow, and conservative query/schema index evidence with explicit fallback.

JS / TSPythonSQLPrismaDrizzleSQLAlchemy
05 / CI GUARDRAILS

Stop new risks before deploy.

Fail pull requests on policy violations or incomplete analysis, with every skipped and fallback file reported.

PR checkCoverage gateSecret scanBaseline
Measured, not marketed

Evidence in. Evidence out.

The scanner, reports, migrations, CI gate, and SARIF output now share one inspectable finding contract.

Test suite309

Workflow, framework fixtures, query/schema indexes, SQL syntax, measured plans, and a 142-case labelled precision corpus across JavaScript, TypeScript, Python, and SQL.

Code analysisGRAPH

AST and CST parsers connect imports, wrappers, callbacks, DI, functions, classes, async boundaries, and ORM calls across the project.

Rule catalog63

Every supported signal has an inspectable ID, severity, confidence, evidence, and action.

Before / afterPROVE

Compare median execution time, buffers, node executions, disk spills, and plan findings from exported PostgreSQL measurements.

npx --yes vellox prove plans/before plans/afterMeasured comparison. Limits included. ↗
Three-command team path

Scan. Adopt. Protect.

Stop after the first command for a local diagnosis. Continue when the findings are reviewed and your team is ready to guard every pull request.

01 / ScanLocal evidence

See the risks.

Scan the current project and save an inspectable report. No account, upload, database connection, or code execution.

npx --yes vellox
02 / BaselineAfter review

Adopt without noise.

Record only the current findings your team reviewed, so rollout starts by protecting new code instead of blocking old debt.

npx --yes vellox baseline
03 / CIPull requests

Stop regressions.

Create a GitHub Actions gate with SARIF evidence while preserving workflows that already belong to your repository.

npx --yes vellox ci
Node 20+Advisory by defaultSource-available