Public-interest software inspection versioned methodology

A public record of software health.

Bridges, elevators, and food have condition records kept in public. The software underneath all three does not. This is that record: maintainability, engineering quality, security posture, ecosystem adoption, and governance, measured the same way for every repository.

01Evidence attached02Results independent of payment03Method versioned

Request a scan

Free for high public-value repositories. Private and niche repositories follow the documented certification route.

Public queue operational
Reproducible evidenceEvery published result links to inspectable source evidence and methodology.
Independent resultsPayment, sponsorship, and vendor alignment cannot alter a published result.
Signals, not warrantiesResults inform review and procurement; they do not replace expert judgement.
Live catalogue

The record, as it stands.

Every repository admitted so far, searchable and rankable, each entry opening on a full report with its evidence.

Indexed repositories
67,510
Monthly downloads under inspection
592B
Median health index
60 Moderate
67,510 recordsRanked by popularity · browse by tag · record statistics
13Criticalhealth index
goller/telegraf
The plugin-driven server agent for collecting & reporting metrics.
Go★ 0Jul 26, 2026
MITJul 26, 2026 · metrics 2.10.0
Go
29At Riskhealth index
goloop/app
A small lifecycle kernel for Go services: ordered start, signal-aware wait, graceful shutdown - standard library only.
Go★ 0Sep 10, 2026
MITSep 10, 2026 · metrics 2.10.0
Go
35Weakhealth index
goloop/argon2id
Memory-hard Argon2id password hashing for Go (RFC 9106) - standard library only, zero dependencies.
Go★ 0Aug 22, 2026
MITAug 22, 2026 · metrics 2.10.0
Go
33At Riskhealth index
goloop/auth
Authentication primitives for Go: password hashing, access tokens, bearer middleware and refresh-token rotation.
Go★ 0Sep 10, 2026
MITSep 10, 2026 · metrics 2.10.0
Go
34At Riskhealth index
goloop/jwt
Compact JSON Web Tokens for Go, deliberately limited to HS256 - standard library only.
Go★ 0Sep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
Go
29At Riskhealth index
goloop/mail
Build and send RFC 5322/MIME email over SMTP, with drop-in dev and test transports - standard library only.
Go★ 0Sep 10, 2026
MITSep 10, 2026 · metrics 2.10.0
Go
39Weakhealth index
goloop/middlewares
Production-ready net/http middleware for Go: request ID, real IP, panic recovery, logging, timeout, compression, throttling, CORS and security headers.
Go★ 0Aug 22, 2026
MITAug 22, 2026 · metrics 2.10.0
Go
36Weakhealth index
goloop/mistral
Go client for the Mistral API on the goloop/ai interface
Go★ 0Jul 31, 2026
MITJul 31, 2026 · metrics 2.10.0
Go
38Weakhealth index
goloop/mux
A small, predictable routing layer over net/http.ServeMux: method helpers, prefix groups, middleware chains and an error-returning handler.
Go★ 0Sep 10, 2026
MITSep 10, 2026 · metrics 2.10.0
Go
36Weakhealth index
golovanov-dev/traceloom-go
Go implementation of Traceloom: JSONL event timelines grouped by trace_id. Thread-safe API with functional options, kernel file locks (flock / LockFileEx) with no staleness heuristics, crash-consistent shards, secret masking, payload budgets. Zero dependencies.
Go★ 0Sep 8, 2026
MITSep 8, 2026 · metrics 2.10.0
npm
20At Riskhealth index
golproductions/check
The anti-hallucination layer for AI agents.
Mixed★ 0↓ 2,728/moSep 5, 2026
Custom licenseSep 5, 2026 · metrics 2.10.0
Go
47Weakhealth index
gomatic/cirql
A JSON pipeline/query language: Parse compiles a query string into a Pipeline that runs over a decoded JSON value
Go · Makefile★ 0Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
48Weakhealth index
gomatic/go-app
urfave/cli/v3 application framework and run harness for gomatic CLIs
Makefile · Go★ 0Jul 18, 2026
MITJul 18, 2026 · metrics 2.10.0
Go
59Moderatehealth index
gomatic/go-archive
Stream-oriented tar.gz archiving (create/list/extract) with zip-slip protection — stdlib-only
Makefile · Go★ 0Aug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
Go
44Weakhealth index
gomatic/go-clock
Injectable time source: Clock interface, System (UTC), Fake for tests
Makefile★ 0Jul 20, 2026
No licenseJul 20, 2026 · metrics 2.10.0
Go
51Moderatehealth index
gomatic/go-cry
SSH-keyed age stream encryption: Encrypt/Decrypt/ParseIdentities
Makefile · Go★ 0Jul 21, 2026
MITJul 21, 2026 · metrics 2.10.0
Go
48Weakhealth index
gomatic/go-depgraph
Dependency-free generic topological sort for Go
Makefile · Go★ 0Jul 20, 2026
MITJul 20, 2026 · metrics 2.10.0
Go
42Weakhealth index
gomatic/go-domainsec
Sender-domain SPF/DKIM/DMARC assessment with a gateable security floor
Makefile · Go★ 0Jul 20, 2026
No licenseJul 20, 2026 · metrics 2.10.0
Go
42Weakhealth index
gomatic/go-envelope
Envelope (hybrid) encryption and signing: AES-GCM per-message keys wrapped to RSA, ed25519 signatures, Argon2id key bundles
Go · Makefile★ 0Jul 20, 2026
No licenseJul 20, 2026 · metrics 2.10.0
Go
48Weakhealth index
gomatic/go-error
Constant/sentinel error helper for Go: errs.Const is a string newtype implementing error, with a %w-wrapping .With() that stays matchable via errors.Is
Makefile · Go★ 0Jul 20, 2026
MITJul 20, 2026 · metrics 2.10.0
Go
60Moderatehealth index
gomatic/go-ghkeys
Fetch a GitHub user's SSH public keys as age recipients
Makefile · Go★ 0Aug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
Go
62Moderatehealth index
gomatic/go-git
Git repository facts for Go behind an injected runner
Makefile · Go★ 0Aug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
Go
51Moderatehealth index
gomatic/go-httpserver
Minimal, stdlib-only HTTP server lifecycle wrapper with context-driven graceful shutdown
Makefile · Go★ 0Jul 24, 2026
MITJul 24, 2026 · metrics 2.10.0
Go
33At Riskhealth index
gomatic/go-json
Dynamic, JSON-compatible value model with typed constant-error accessors
Makefile · Go★ 0↓ 0/moJul 14, 2026
MITJul 14, 2026 · metrics 2.10.0
Go
33At Riskhealth index
gomatic/go-lines
Line-oriented text processing for Go: pure per-line primitives plus a streaming, context-aware line Processor.
Makefile · Go★ 0↓ 0/moJul 14, 2026
MITJul 14, 2026 · metrics 2.10.0
Go
48Weakhealth index
gomatic/go-log
Thin log/slog configuration layer: flag-bindable Level and Format value types producing a *slog.Logger
Makefile · Go★ 0Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
62Moderatehealth index
gomatic/go-module
Parse a git remote URL into a Go module Path, Name, Identifier, and EnvPrefix — pure string logic, no I/O
Makefile · Go★ 0Jul 27, 2026
MITJul 27, 2026 · metrics 2.10.0
Go
60Moderatehealth index
gomatic/go-optional
Generic functional-options implementation for type-safe, friendly Go constructor APIs
Makefile · Go★ 0Jul 27, 2026
MITJul 27, 2026 · metrics 2.10.0
Go
48Weakhealth index
gomatic/go-output
Encode any value to an io.Writer as JSON or YAML through a small format registry, with an ErrUnsupportedFormat sentinel
Makefile · Go★ 0Jul 20, 2026
MITJul 20, 2026 · metrics 2.10.0
Go
44Weakhealth index
gomatic/go-pgpool
Tuned pgx v5 connection pools + health checker (libpq env fallback)
Makefile · Go★ 0Jul 20, 2026
No licenseJul 20, 2026 · metrics 2.10.0