Public-interest software inspection versioned methodology

A public record of software health.

Bridges, elevators, and food have condition records kept in public. The software underneath all three does not. This is that record: maintainability, engineering quality, security posture, ecosystem adoption, and governance, measured the same way for every repository.

01Evidence attached02Results independent of payment03Method versioned

Request a scan

Free for high public-value repositories. Private and niche repositories follow the documented certification route.

Public queue operational
Reproducible evidenceEvery published result links to inspectable source evidence and methodology.
Independent resultsPayment, sponsorship, and vendor alignment cannot alter a published result.
Signals, not warrantiesResults inform review and procurement; they do not replace expert judgement.
Live catalogue

The record, as it stands.

Every repository admitted so far, searchable and rankable, each entry opening on a full report with its evidence.

Indexed repositories
73,873
Monthly downloads under inspection
621B
Median health index
60 Moderate
36,259 recordsRanked by popularity · browse by tag · record statistics
npm · Go
18Criticalhealth index
sneat-co/ext-gameboard
Public contract surface for the gameboard extension (extension-contract-repo convention): TypeSpec api4gameboard + Go backend contract module + @sneat/extension-gameboard-contract. Depends only on foundational/core — never another extension.
Go · TypeScript · TypeSpec★ 0Sep 14, 2026
AGPL-3.0Sep 14, 2026 · metrics 2.10.0
Go · npm
19Criticalhealth index
sneat-co/ext-listus
Public contract for the Sneat Listus extension
Go · TypeScript★ 0Sep 15, 2026
No licenseSep 15, 2026 · metrics 2.10.0
npm
60Moderatehealth index
TypeScript★ 0↓ 1,423/moSep 18, 2026
MITSep 18, 2026 · metrics 2.10.0
Go
41Weakhealth index
sns45/assayward
Runtime trust gate: evaluates supply-chain attestations + workload identities to decide whether a workload may run (forgeseal + svidmint trilogy)
Go★ 0Sep 12, 2026
Custom licenseSep 12, 2026 · metrics 2.10.0
Go · npm
53Moderatehealth index
sns45/forgeseal
No repository description published.
Go★ 0Sep 17, 2026
Apache-2.0Sep 17, 2026 · metrics 2.10.0
Maven
31At Riskhealth index
snuyanzin/datafaker
Brings the popular ruby faker gem to Java and Kotlin
Java★ 0Sep 13, 2026
Apache-2.0Sep 13, 2026 · metrics 2.10.0
RubyGems
71Goodhealth index
socketry/protocol-grpc
No repository description published.
Ruby★ 0Sep 18, 2026
MITSep 18, 2026 · metrics 2.10.0
RubyGems
47Weakhealth index
socketry/sus-fixtures-console
No repository description published.
Ruby★ 0Sep 11, 2026
MITSep 11, 2026 · metrics 2.10.0
Go
17Criticalhealth index
socrates-greek/gprc_pool
Connection pool for Go's grpc client with supports connection reuse.
Go★ 0Sep 13, 2026
Apache-2.0Sep 13, 2026 · metrics 2.10.0
NuGet
67Goodhealth index
soenneker/soenneker.atomics.valuelocks
Lightweight value-type synchronization with atomically published lock storage.
C#★ 0Sep 15, 2026
MITSep 15, 2026 · metrics 2.10.0
NuGet
80Excellenthealth index
soenneker/soenneker.dtos.idnamevalueindex
A minimal Record type with an Id (string), Name (string), Value (string?), and Index (string?) and maximum JSON compatibility
C#★ 0Sep 14, 2026
MITSep 14, 2026 · metrics 2.10.0
NuGet
80Excellenthealth index
soenneker/soenneker.dtos.idvaluepair
A minimal Record type with an Id (string), Value (string), and maximum JSON compatibility
C#★ 0Sep 14, 2026
MITSep 14, 2026 · metrics 2.10.0