Technology

Local-first. Deterministic. Dependency-light.

Quantum Core is a C++20 pipeline: file selection, rule matching, finding normalisation, crypto-domain classification and report generation. It is one binary with no runtime dependencies, and it never sends code anywhere.

Quantum Core field modelt = live
3329
f: files → findingsseverity × categoryΣ riskᵢdeterministic sort
C++20engine
Localprivacy
7/7tests pass
Input

A local repository path.

Selection

File extensions, ignored directories and file-size limits.

Matching

Substring and token-boundary rules with a context-driven confidence model.

Confidence

Every match is graded high, medium or low. Comments, generic terms and strings sitting alone in data tables are demoted and held in a Likely Noise section rather than dropped silently.

Classification

Weakness rules carry a CWE and describe classical defects. Inventory rules carry NIST references and describe migration work.

Output

Markdown, JSON and SARIF 2.1.0 with stable fingerprints for alert deduplication, plus a CycloneDX 1.6 CBOM checked against the official schema.

Suppression

Path rules in .qcoreignore, inline qcore:ignore comments, and a baseline file so that only new findings gate a build.

Tests

Seven end-to-end tests cover scoring, suppression, SARIF and CBOM output, and run on every change.