Free report · Public repos

How much maintenance debt is hiding in your repos?

Tidra's free maintenance report scans every public repository in a GitHub organization and quantifies its maintenance debt: open CVEs by severity, dependencies a major version or more behind, end-of-life runtimes, and CI configuration drift, totaled into engineer-weeks of remediation effort. No installation, no account, and no repository access required. Provide a public GitHub organization URL and an email address, and the report arrives in your inbox.

Maintenance debt is the operational slice of technical debt: the accumulated dependency upgrades, security patches, runtime migrations, and CI fixes a team has deferred.

Get your report

Paste a public GitHub org URL and tell us where to send it.

To get your free report, enter your public GitHub organization URL and the work email where we should send it, then submit the form.

SOC 2 certified

Every report is reviewed by a Tidra engineer before it goes out.

Mostly private repos? Book a demo and we'll run the same analysis against your actual org.

What's in the report

A one page maintenance effort report covering every public repo in scope:

Known CVE exposure

Every open advisory across the repos, broken out by severity, with the triage-and-patch time each one carries.

Dependency drift

How many dependencies are a major version or more behind, the total majors behind, and how many repos are affected.

End-of-life runtimes

Language runtimes and base images already past end-of-support, plus the ones approaching it.

CI & config drift

Outdated action pins, deprecated runners, legacy CI configs, and dependencies fragmented across repos.

Per-repo breakdown

The highest-impact finding in each repository, ranked by the engineering effort to resolve it.

The bottom line

Total engineer-weeks to clear the backlog, with a line-by-line ledger of how every hour is counted.

Frequently asked questions

How do you calculate maintenance effort?

We scan every public repo in the org for open security advisories, dependencies a major version or more behind, runtimes past end-of-support, and CI configuration drift. Each finding gets a conservative estimate of the engineer-hours to triage, fix, test, and ship it, and we total those into engineer-weeks. The report shows the per-line-item math, so the figure is something you can defend internally.

Are the numbers actually realistic?

Conservative on purpose. Every dependency is counted once, and a CVE only adds the time to triage and verify it on top of the upgrade that already fixes it, so nothing is double-counted. If the estimate is off, it is more likely low than high. You can argue with the per-fix rates; the findings themselves are real.

Why only public repositories?

Public repos are everything we can analyze without you handing us access to anything. For most companies they are a small slice of the real footprint, so read the number as a floor, not a ceiling. Want the same breakdown across your private repos? Start a trial or book a demo and we will run it against your actual org.

How long until I get the report?

We review each one before it goes out, so it lands in your inbox within a few hours rather than instantly.

What will you do with my email?

We use it to send you the report, and someone from Tidra may follow up once to see whether it was useful. No drip campaign, and you can unsubscribe in one click.

Why is this free?

The backlog the report surfaces is the exact work Tidra automates, so it doubles as our pitch. Either way you walk away with a real number for the maintenance load your team is carrying, which is useful whether or not you ever talk to us.

What is maintenance debt?

Maintenance debt is the operational slice of technical debt: the accumulated dependency upgrades, security patches, runtime migrations, and CI fixes a team has deferred. Unlike feature debt, it compounds quietly — each skipped upgrade widens the gap to the next one, and open CVEs accumulate until something forces a triage sprint. The report gives you the total in engineer-weeks so you can see the real size of the backlog before deciding how to tackle it.

How do you measure technical debt in engineer-weeks?

We assign a conservative estimate of engineer-hours to each finding: time to triage, implement the fix, write or update tests, and ship the change. A dependency upgrade on a well-tested package is different from patching a CVE in a critical runtime, so the rates vary by finding type. We total all findings across every public repo in the org and convert to engineer-weeks. The report shows the per-line-item math, so the figure is auditable rather than a black box.

See the tax, then make it disappear

The work the report surfaces is exactly what Tidra ships for you. Plan each change once, and Tidra drives the PRs to merge across every repo.