Every commit scored for change-risk against this repo's own history, so 'elevated' means elevated here rather than on some global curve.
Needs review
9 commits sit in this repo's top risk tercile, which is 33% of the 27scored. The cut is drawn against this codebase's own history rather than a global curve, so a quiet repo still fills its top band, and here it starts at 3.6 out of 10. What pushes a commit up is size and spread together: a large change confined to one area scores below a smaller one scattered across a dozen files.
Commit categories over time, read off the subject line. Fixes carry the accent because that is the series this chart exists to show.
Consistently other-driven across its history.
Ranked by change-risk, highest first. Priority is a tercile of this repo's own distribution, so a quiet repo still fills its top band.
| # | Commit | Author | When | Lines | Risk | Top driver |
|---|---|---|---|---|---|---|
| 1 | 9d3b6363first commit | Salah Alkwhalni | 7y ago | +512 -0 | 98%Elevated | more lines added than baseline |
| 2 | ede4c902fix: restore graham-campbell/security parity (BC follow-up for #7) (#8) | Ahmed Bally | 3mo ago | +285 -30 | 94%Elevated | more lines added than baseline |
| 3 | 30d1f968feat: support Laravel 11/12/13 and switch backend to voku/anti-xss (#7) | Ahmed Bally | 3mo ago | +231 -71 | 91%Elevated | more lines added than baseline |
| 4 | 07e65399fix: security hardening — null-safety, strict comparison, class validation, test key format (#9) | devin-ai-integration[bot]devinautonomous | 2mo ago | +130 -3 | 87%Elevated | more lines added than baseline |
| 5 | d9e11068enhance skip check | Salah Alkwhalni | 7y ago | +14 -2 | 83%Elevated | more lines added than baseline |
| 6 | c6879d60add scrutinizer ci | Salah Alkwhalni | 7y ago | +11 -0 | 78%Elevated | more focused than baseline |
| 7 | cf7e3e6fApply fixes from StyleCI | Salah Alkhwlani | 7y ago | +12 -12 | 78%Elevated | more scattered than baseline |
| 8 | a05e59d1support ignore fields from filter | Salah Alkwhalni | 7y ago | +11 -2 | 72%Elevated | more subsystems than baseline |
| 9 | a8b0c87bUpdate README.md | Salah Alkhwlani | 5y ago | +8 -1 | 69%Elevated | fewer lines added than baseline |
| 10 | e9d44bd5wip (#4) | Osaigbovo Emmanuel | 3y ago | +6 -7 | 65%Typical | fewer lines added than baseline |
| 11 | 0806dc19upgrade to graham-campbell/security 9.0 | ossycodes | 5y ago | +5 -5 | 61%Typical | fewer lines added than baseline |
| 12 | 4b098b39Update Readme | Salah Alkwhalni | 7y ago | +5 -5 | 56%Typical | fewer lines added than baseline |
| 13 | 1277c0f7Update Readme | Salah Alkwhalni | 7y ago | +5 -5 | 56%Typical | fewer lines added than baseline |
| 14 | d31de575chore(composer): updated dependencies for supporting laravel 10 (#6) | Alexey Livadnyi | 3y ago | +4 -3 | 50%Typical | fewer lines added than baseline |
| 15 | 93cd7283Update Readme | Salah Alkwhalni | 7y ago | +4 -3 | 46%Typical | fewer lines added than baseline |
| 16 | 88d0033aApply fixes from StyleCI | Salah Alkhwlani | 4y ago | +2 -3 | 39%Typical | fewer lines added than baseline |
| 17 | 49b2281bApply fixes from StyleCI | Salah Alkhwlani | 5y ago | +2 -2 | 39%Typical | fewer lines added than baseline |
| 18 | d3a3fe3ffix failing tests | ossycodes | 5y ago | +2 -2 | 39%Typical | fewer lines added than baseline |
| 19 | 8ddcbc9fAdd php constraints (#5) | Osaigbovo Emmanuel | 3y ago | +1 -2 | 30%Below typical | fewer lines added than baseline |
| 20 | f6f97d6afix config registering & publishing (#3) | Ahmed Bally | 4y ago | +1 -10 | 30%Below typical | fewer lines added than baseline |
| 21 | 99904db6Revise upgrade guide for v4.1 changes | Salah Alkhwlani | 3mo ago | +1 -1 | 13%Below typical | fewer lines added than baseline |
| 22 | 0b4b878bSupport Laravel 10 | Salah Alkhwlani | 3y ago | +1 -0 | 13%Below typical | fewer lines added than baseline |
| 23 | fe702bdbUpdate README.md | Salah Alkhwlani | 3y ago | +1 -0 | 13%Below typical | fewer lines added than baseline |
| 24 | ff61b348Update README.md | Salah Alkhwlani | 5y ago | +1 -1 | 13%Below typical | fewer lines added than baseline |
| 25 | aff21f62Apply fixes from StyleCI | Salah Alkhwlani | 7y ago | +1 -1 | 13%Below typical | fewer lines added than baseline |
| 26 | 8ae684aafix travis link | Salah Alkwhalni | 7y ago | +1 -1 | 13%Below typical | fewer lines added than baseline |
| 27 | 712df540Update Readme | Salah Alkwhalni | 7y ago | +1 -1 | 13%Below typical | fewer lines added than baseline |
Two views of the same model: where the cuts fall, and what commit shape lands you above them.
Every scored commit, binned on the raw 0 to 10 score rather than the percentile. Percentile ranks are uniform by construction, so that axis has no shape to draw. The dashed lines are the tercile cuts behind each row's priority pill.
The 27 most recent commits, on their own recency sample rather than the feed above: that defaults to risk-sorted, so reusing it would plot only the top tercile and call it the spread. Big and scattered is what the model penalises. Click a dot to open it.
Repowise tracks change history across 10 files in salkhwlani/laravel-xss-middlware. In the last 90 days 10 files were touched, 19 times in total, most often ServiceProvider.php. Every commit is scored for change risk from its size, spread and the history of the files it touches.