Technology
Local-first. Deterministic. Dependency-light.
Quantum Core is a C++20 pipeline: file selection, rule matching, finding normalisation, crypto-domain classification and report generation. It is one binary with no runtime dependencies, and it never sends code anywhere.
A local repository path.
File extensions, ignored directories and file-size limits.
Substring and token-boundary rules with a context-driven confidence model.
Every match is graded high, medium or low. Comments, generic terms and strings sitting alone in data tables are demoted and held in a Likely Noise section rather than dropped silently.
Weakness rules carry a CWE and describe classical defects. Inventory rules carry NIST references and describe migration work.
Markdown, JSON and SARIF 2.1.0 with stable fingerprints for alert deduplication, plus a CycloneDX 1.6 CBOM checked against the official schema.
Path rules in .qcoreignore, inline qcore:ignore comments, and a baseline file so that only new findings gate a build.
Seven end-to-end tests cover scoring, suppression, SARIF and CBOM output, and run on every change.