All posts
riskhow-to

Risk-next hotspots and how to act on them

Jordan Gilchrist·August 18, 2026

SonarQube grades the code as it is. Risk Radar predicts where it breaks next.

Each file gets a 0-100 risk-next score fusing four signals that defect-prediction research (and our own data) agree on: severity-weighted issue density, churn, single-author ownership, and complexity. Files cluster their defects — the top of this list is where your next incident most likely originates.

How to use it:

  1. Sort by risk, work top-down — don't spread effort evenly.
  2. Read the "why this scored" factors; they point at the lever (tests, ownership, size).
  3. Fix, re-scan, and watch the Outcome Ledger reconcile the prediction.

It's the decision tool for "where should the team spend this sprint's hardening budget?"

Want to see this on your own codebase?

Analyze a repo free
Risk-next hotspots and how to act on them