What I audit
Repo history + the live app’s user-visible promises.
What gets published
Findings you can reproduce in one action; your stack; anonymized or named — your choice, in writing.
Where findings publish
On getbakery.dev and the Substack (thirteenthloaf.substack.com), under James’s name.
What never gets published
- Secrets, credentials, business specifics you redline
- Anything you kill before publication — you hold a pre-publish veto
What you get
- The full audit, free for now
- The write-up’s traffic, if you want the project named
- Upper Crust on Substack — a guaranteed Bake Off / project audit of your own project, without the calibration obligation below
What it costs you — required for a free audit
The anonymized commit-shape profile — counts, dates, intervals; no file contents, no commit messages, no names — becomes calibration data. Won’t allow it, no free audit, said in those words.
Upper Crust releases this. If you’re not willing to allow calibration and you’re not Upper Crust yet, that’s an honest “not yet.”
What stays yours — never the price of anything
Permission to publish, on every finding, for any reason or none; named or anonymous; anything you redline. Bundling publication into the price would be buying your embarrassment, and a veto you can only use by forfeiting the audit is not a veto.
What I also get, not required
Your one-click confirm/dispute on the record. Disputes are as useful as confirmations and get published alongside them.
How findings are produced
Findings are produced by instruments where instruments exist and by me where they don’t; the write-up says which is which.
Private repos
Private works without granting repo access — a commit-history export is enough. See the commands on the audit page.