symbol, which correctly references the current values context.",
"is_bot": false,
"headline": "Fix app.kubernetes.io labels to use $ instead of . in vaultwarden cha…",
"author_name": "Łukasz Żarnowiecki",
"author_login": "dolohow",
"committed_at": "2024-02-23T02:21:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b809862e6ca431c196a2ea8394bd44c660991f5",
"body": "Every time I upgrade this helm chart I got this error\r\n```\r\nError: UPGRADE FAILED: cannot patch \"vaultwarden\" with kind StatefulSet: StatefulSet.apps \"vaultwarden\" is invalid: spec: Forbidden: updates to statefulset spec for fields other than 'replicas', 'ordinals', 'template', 'updateStrategy', 'pe\n[…]\nn/issues/58\r\n\r\n* Update charts/vaultwarden/Chart.yaml\r\n\r\nCo-authored-by: Nicholas Santiago \u003cnicholas.santiago@gmail.com>\r\n\r\n---------\r\n\r\nCo-authored-by: Nicholas Santiago \u003cnicholas.santiago@gmail.com>",
"is_bot": false,
"headline": "Do not update forbidden fields for statefulset (#75)",
"author_name": "Łukasz Żarnowiecki",
"author_login": "dolohow",
"committed_at": "2024-02-21T02:15:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ca9c62754f7558b827e25de7555d1df54088838",
"body": "* allow multiple ingress hostnames\r\n\r\n* fix: make default for ingress.additionalHostnames blank array\r\n\r\n* fix: update default values to shrink diff on PR to upstream\r\n\r\n* fix: increment chart version to expose feature add\r\n\r\n* docs: provide example of ingress.additionalHostnames in README",
"is_bot": false,
"headline": "feat: allow multiple ingress hostnames (#74)",
"author_name": "Nicholas Santiago",
"author_login": "santiagon610",
"committed_at": "2024-02-18T11:24:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2fc77ef40c830beed9d268568b864b93821758dd",
"body": "This release includes the following:\r\n\r\n- Update the application version to `1.30.3`\r\n- Add support for multiple features\r\n- Reorganize values to follow vaultwarden's environment vars template\r\n\r\n---------\r\n\r\nSigned-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "feat: update app, add more options, reorg docs (#73)",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2024-02-17T14:40:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3f30ca3899160fe9004df21eef72ffb6bc700831",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "feat: add support for more configuration options (#72)",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2024-02-17T11:48:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3737ec0d1085d227ecd86e5e8f1ed180a7948525",
"body": null,
"is_bot": false,
"headline": "Allow configuring experimental client feature flags (#67)",
"author_name": "Philipp Kolberg",
"author_login": "PKizzle",
"committed_at": "2024-02-14T00:07:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cac4707e8f2cd293ac699c0b4fa2349f1c89312",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "feat: add support for Yubikey OTP authentication",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-12-22T14:09:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "358c4b1450b63e60225a1a859f98a1df428dc243",
"body": null,
"is_bot": false,
"headline": "docs: update values.yaml annotations",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-12-22T14:09:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c6a5b02e8fb034694863bf1ebe057fd418530fd",
"body": "The default initialDelaySeconds for the liveness and startup probes are too high for how quickly vaultwarden boots",
"is_bot": false,
"headline": "Reduce the initialDelaySeconds values (#62)",
"author_name": "Philipp Kolberg",
"author_login": "PKizzle",
"committed_at": "2023-12-17T16:27:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "67b5a64890a5073055cc81d8e1cf6c11846ca43c",
"body": null,
"is_bot": false,
"headline": "Improved security configuration (#63)",
"author_name": "Göran Pöhner",
"author_login": "groundhog2k",
"committed_at": "2023-12-17T12:57:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e87e33f87e4617f31a80643ec060cf0146b612aa",
"body": "…alling the deployment (#60)",
"is_bot": false,
"headline": "Improved PVC configuration to optionally keep the volume after uninst…",
"author_name": "Göran Pöhner",
"author_login": "groundhog2k",
"committed_at": "2023-12-17T08:12:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba5ff95484d4f560321ad03e1a720428c8b90827",
"body": null,
"is_bot": false,
"headline": "feat: Automatically use Deployment instead of StatefulSet (#59)",
"author_name": "Philipp Kolberg",
"author_login": "PKizzle",
"committed_at": "2023-12-09T05:49:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05c1a351dc80b7cc3418ed14323f98189b648f8b",
"body": null,
"is_bot": false,
"headline": "fix statefulset mountpaths",
"author_name": "Santi",
"author_login": "0xsanti",
"committed_at": "2023-11-15T03:50:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "539f821ef203b406ec1d1521927b84c240c6ee3d",
"body": null,
"is_bot": false,
"headline": "fix: fix param in sts",
"author_name": "Adrien Chauve",
"author_login": "achauve",
"committed_at": "2023-11-15T03:05:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9ce6fe702fae918d08fd0d7fd208f573d1f0853b",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "fix: sts annotations",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-05T10:36:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dcb1ca1cfd4fd5d50ebe8eb42852273c545add3d",
"body": "- allow disabling the admin token\n- minor fix to writing initContainers in template\n- update example for signupDomains\n- add support for push notifications\n- rework storage variable and add support for custom attachments dir\n- Makefile for testing\n- fix logging configuration\n- use alpine image\n- move resource config to values.yml\n- add readiness probe\n- add funding button for repo\n\nSigned-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "feat: multiple features",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-05T10:02:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f58bd50e900dac2cf263c4264e713b49cb4b08f3",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "feat: add podAnnotations on StatefulSet",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-05T04:46:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "90f8d57e8483b49cd64ec9b86086a3fd3a13e7f1",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "chore: artifactoryhub",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-04T16:52:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9e9b563107e51a1fdad584af57256fa3b5df35b",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "docs: add dco to contributing guide",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-03T14:30:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71e49f68d078930daf255906d074be304187bdd3",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "docs: update Helm badge",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-03T10:56:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83447c98845b1a966bb66e3a2a60b0a780e2efc5",
"body": "Signed-off-by: Lester Guerzon \u003cguerzon@proton.me>",
"is_bot": false,
"headline": "chore: bump default img tag, update documentation (#50)",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-03T10:53:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dc5751168668ee45e9c3e7a0482238ff1f4338fb",
"body": null,
"is_bot": false,
"headline": "ci: fix linting errors, bump chart version (#49)",
"author_name": "Lester Guerzon",
"author_login": "guerzon",
"committed_at": "2023-11-03T10:21:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eb26711cafc4e515ef36b8988693b4d7a88a344a",
"body": "…torageClass (#34)\n\nCo-authored-by: vasilykraev \u003cgithub@vkraev.ru>",
"is_bot": false,
"headline": "fix PVC: instead using storageClass with name 'default' use default s…",
"author_name": "Vasily Kraev",
"author_login": "vasilykraev",
"committed_at": "2023-11-03T09:59:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09dec4a92a0387d564d6af98f410f411c8e5ef70",
"body": "Some options:\r\n INVITATION_ORG_NAME\r\n ICON_BLACKLIST_NON_GLOBAL_IPS\r\n IP_HEADER\r\n\r\nCo-authored-by: Vitali Khlebko \u003cvitali.khlebko@vetal.ca>",
"is_bot": false,
"headline": "Allow Signup domains not to be set (#38)",
"author_name": "Vitali Khlebko",
"author_login": "Vetal-ca",
"committed_at": "2023-11-03T09:45:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d250cc024bf25ece5b9d02bd2961333e7a08960b",
"body": "Co-authored-by: Michel Wilson \u003cmichel@teqplay.nl>",
"is_bot": false,
"headline": "Fix labels to enable upgrading by changing the image tag (#47)",
"author_name": "Michel Wilson",
"author_login": "michelwilson",
"committed_at": "2023-11-03T09:34:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "152dfeb6d7dd85493329dd6c7f47910385519712",
"body": "… (#43)\n\n* Create ci-helm-lint-test.yml - adds a linter that runs on all new PRs\r\n\r\n* Update .github/workflows/ci-helm-lint-test.yml - add --set=domain arg to ct install",
"is_bot": false,
"headline": "Create ci-helm-lint-test.yml - adds a linter that runs on all new PRs…",
"author_name": "JesseBot",
"author_login": "jessebot",
"committed_at": "2023-11-03T08:35:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe8769ffed2329a4a71967c25437521db7a31a66",
"body": "This was causing this section to be rendered even if conditional was not met.",
"is_bot": false,
"headline": "Update configmap.yaml - fix quoting of conditional (#45)",
"author_name": "JesseBot",
"author_login": "jessebot",
"committed_at": "2023-11-03T08:35:41Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 93,
"commits_last_year": 35,
"latest_release_at": "2026-07-25T06:32:40Z",
"latest_release_tag": "v0.44.0",
"releases_from_tags": false,
"days_since_last_push": 9,
"active_weeks_last_year": 16,
"days_since_latest_release": 9,
"mean_days_between_releases": 3.9
},
"artifacts": {
"collected": true,
"structure": [
"tree.helm",
"tree.k8s"
],
"declarations": []
},
"community": {
"has_readme": true,
"has_license": true,
"readme_badges": {
"hosts": [
"shields.io"
],
"total": 2,
"header": 2,
"collected": true,
"has_inspect_badge": false
},
"has_description": true,
"has_contributing": true,
"health_percentage": 57,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 114,
"stars": 341,
"watchers": 6,
"fork_history": {
"days": [
{
"date": "2022-04-28",
"count": 1
},
{
"date": "2022-05-14",
"count": 1
},
{
"date": "2022-05-26",
"count": 1
},
{
"date": "2022-06-13",
"count": 1
},
{
"date": "2022-09-30",
"count": 1
},
{
"date": "2022-10-26",
"count": 1
},
{
"date": "2022-11-23",
"count": 1
},
{
"date": "2023-02-23",
"count": 1
},
{
"date": "2023-03-07",
"count": 1
},
{
"date": "2023-03-09",
"count": 1
},
{
"date": "2023-03-18",
"count": 1
},
{
"date": "2023-03-24",
"count": 1
},
{
"date": "2023-04-03",
"count": 1
},
{
"date": "2023-04-08",
"count": 1
},
{
"date": "2023-04-12",
"count": 1
},
{
"date": "2023-04-22",
"count": 1
},
{
"date": "2023-05-31",
"count": 1
},
{
"date": "2023-06-01",
"count": 1
},
{
"date": "2023-06-11",
"count": 2
},
{
"date": "2023-06-14",
"count": 1
},
{
"date": "2023-06-23",
"count": 1
},
{
"date": "2023-06-30",
"count": 1
},
{
"date": "2023-07-14",
"count": 1
},
{
"date": "2023-07-18",
"count": 1
},
{
"date": "2023-07-31",
"count": 1
},
{
"date": "2023-08-17",
"count": 1
},
{
"date": "2023-08-22",
"count": 1
},
{
"date": "2023-08-30",
"count": 1
},
{
"date": "2023-09-12",
"count": 1
},
{
"date": "2023-09-13",
"count": 1
},
{
"date": "2023-09-21",
"count": 1
},
{
"date": "2023-09-28",
"count": 1
},
{
"date": "2023-11-07",
"count": 2
},
{
"date": "2023-11-09",
"count": 1
},
{
"date": "2023-11-10",
"count": 1
},
{
"date": "2023-11-13",
"count": 1
},
{
"date": "2023-12-01",
"count": 1
},
{
"date": "2023-12-25",
"count": 2
},
{
"date": "2024-01-17",
"count": 1
},
{
"date": "2024-03-01",
"count": 1
},
{
"date": "2024-03-05",
"count": 1
},
{
"date": "2024-03-09",
"count": 1
},
{
"date": "2024-03-16",
"count": 1
},
{
"date": "2024-03-25",
"count": 1
},
{
"date": "2024-03-28",
"count": 1
},
{
"date": "2024-04-10",
"count": 1
},
{
"date": "2024-05-13",
"count": 1
},
{
"date": "2024-05-29",
"count": 1
},
{
"date": "2024-06-05",
"count": 1
},
{
"date": "2024-06-29",
"count": 1
},
{
"date": "2024-07-09",
"count": 1
},
{
"date": "2024-07-16",
"count": 1
},
{
"date": "2024-08-19",
"count": 1
},
{
"date": "2024-08-23",
"count": 1
},
{
"date": "2024-08-29",
"count": 1
},
{
"date": "2024-10-03",
"count": 1
},
{
"date": "2024-10-11",
"count": 1
},
{
"date": "2024-10-28",
"count": 1
},
{
"date": "2024-11-05",
"count": 1
},
{
"date": "2024-11-16",
"count": 1
},
{
"date": "2024-11-17",
"count": 1
},
{
"date": "2024-11-22",
"count": 1
},
{
"date": "2024-11-29",
"count": 1
},
{
"date": "2025-01-08",
"count": 2
},
{
"date": "2025-01-12",
"count": 1
},
{
"date": "2025-01-14",
"count": 1
},
{
"date": "2025-01-16",
"count": 3
},
{
"date": "2025-02-05",
"count": 1
},
{
"date": "2025-02-24",
"count": 1
},
{
"date": "2025-03-11",
"count": 1
},
{
"date": "2025-05-05",
"count": 1
},
{
"date": "2025-05-08",
"count": 1
},
{
"date": "2025-05-10",
"count": 1
},
{
"date": "2025-06-06",
"count": 1
},
{
"date": "2025-07-10",
"count": 1
},
{
"date": "2025-07-13",
"count": 1
},
{
"date": "2025-07-14",
"count": 1
},
{
"date": "2025-07-20",
"count": 1
},
{
"date": "2025-07-27",
"count": 1
},
{
"date": "2025-07-29",
"count": 1
},
{
"date": "2025-07-31",
"count": 1
},
{
"date": "2025-09-09",
"count": 1
},
{
"date": "2025-09-22",
"count": 1
},
{
"date": "2025-10-12",
"count": 1
},
{
"date": "2025-11-19",
"count": 1
},
{
"date": "2025-12-02",
"count": 1
},
{
"date": "2025-12-31",
"count": 1
},
{
"date": "2026-01-07",
"count": 1
},
{
"date": "2026-01-15",
"count": 1
},
{
"date": "2026-01-29",
"count": 1
},
{
"date": "2026-02-06",
"count": 1
},
{
"date": "2026-02-09",
"count": 1
},
{
"date": "2026-02-20",
"count": 1
},
{
"date": "2026-02-22",
"count": 1
},
{
"date": "2026-03-16",
"count": 1
},
{
"date": "2026-03-29",
"count": 1
},
{
"date": "2026-04-03",
"count": 1
},
{
"date": "2026-04-06",
"count": 1
},
{
"date": "2026-04-07",
"count": 1
},
{
"date": "2026-05-02",
"count": 1
},
{
"date": "2026-05-25",
"count": 1
},
{
"date": "2026-05-26",
"count": 1
},
{
"date": "2026-06-12",
"count": 1
},
{
"date": "2026-06-29",
"count": 1
},
{
"date": "2026-07-01",
"count": 1
},
{
"date": "2026-07-02",
"count": 1
},
{
"date": "2026-07-13",
"count": 1
},
{
"date": "2026-07-22",
"count": 1
}
],
"complete": true,
"collected": 114,
"total_forks": 114
},
"star_history": null,
"open_issues_and_prs": 16
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": null,
"source_files_sampled": 0,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"requirements.txt"
],
"advisories": {
"error": "No resolved dependencies carried a version and a supported ecosystem",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 2,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "yamale",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "yamllint",
"direct": false,
"version": null,
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 2,
"direct_count": 0,
"indirect_count": 2
}
},
"maintainership": {
"issues": {
"open_prs": 13,
"merged_prs": 110,
"open_issues": 3,
"closed_ratio": 0.961,
"closed_issues": 73,
"closed_unmerged_prs": 33
},
"bus_factor": 2,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "guerzon",
"commits": 54,
"avatar_url": "https://avatars.githubusercontent.com/u/44284609?v=4"
},
{
"type": "User",
"login": "CameronMunroe",
"commits": 11,
"avatar_url": "https://avatars.githubusercontent.com/u/53840354?v=4"
},
{
"type": "User",
"login": "klauserber",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/9998995?v=4"
},
{
"type": "User",
"login": "dolohow",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/1408564?v=4"
},
{
"type": "User",
"login": "jessebot",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/2389292?v=4"
},
{
"type": "User",
"login": "PKizzle",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/39984529?v=4"
},
{
"type": "User",
"login": "santiagon610",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/7259149?v=4"
},
{
"type": "User",
"login": "jaywor1",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/103755136?v=4"
},
{
"type": "User",
"login": "paimonsoror",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/935046?v=4"
},
{
"type": "User",
"login": "niklasfrick",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/19509178?v=4"
}
],
"contributors_sampled": 43,
"top_contributor_share": 0.429
},
"quality_signals": {
"has_ci": true,
"has_tests": false,
"ci_workflows": [
"ci-helm-lint-test.yml",
"release.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 9,
"reason": "25 out of 27 merged PRs checked by a CI test -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 5,
"reason": "Found 16/27 approved changesets -- score normalized to 5",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 4 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "15 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "5cd6a96af9a80c201cccaeda2739bd4a6b861a5b",
"ran_at": "2026-08-03T17:04:52Z",
"aggregate_score": 5.4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"recent_prs": {
"merged_7d": 0,
"decided_7d": 0,
"merged_30d": 1,
"authors_30d": 1,
"decided_30d": 1,
"sample_size": 60,
"window_days": 30,
"sample_exhausted": false,
"authors_probed_30d": 1,
"newcomer_merged_30d": 0,
"bot_prs_excluded_30d": 0,
"newcomer_authors_30d": 0,
"newcomer_decided_30d": 0
},
"ci_last_run_at": "2026-07-25T06:37:51Z",
"oldest_open_prs": [
{
"number": 12,
"created_at": "2023-03-08T19:34:55Z",
"last_comment_at": "2023-06-06T21:02:33Z",
"last_comment_author": "guerzon"
},
{
"number": 13,
"created_at": "2023-03-09T16:00:18Z",
"last_comment_at": "2025-06-17T20:20:10Z",
"last_comment_author": "pb4162"
},
{
"number": 46,
"created_at": "2023-08-22T12:40:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 142,
"created_at": "2025-01-16T16:51:00Z",
"last_comment_at": "2025-01-19T12:52:34Z",
"last_comment_author": "guerzon"
},
{
"number": 148,
"created_at": "2025-01-27T03:21:55Z",
"last_comment_at": "2025-01-28T07:38:33Z",
"last_comment_author": "kmichailg"
},
{
"number": 175,
"created_at": "2025-09-10T13:02:02Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 178,
"created_at": "2025-10-12T00:29:10Z",
"last_comment_at": "2025-10-12T10:39:40Z",
"last_comment_author": "spwoodcock"
},
{
"number": 179,
"created_at": "2025-10-12T10:50:33Z",
"last_comment_at": "2025-10-12T10:51:15Z",
"last_comment_author": "spwoodcock"
},
{
"number": 190,
"created_at": "2026-02-06T10:38:01Z",
"last_comment_at": "2026-02-06T10:38:20Z",
"last_comment_author": "lkvrsfld"
},
{
"number": 234,
"created_at": "2026-07-02T08:25:27Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 236,
"created_at": "2026-07-13T14:37:54Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 239,
"created_at": "2026-07-22T22:07:38Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 242,
"created_at": "2026-07-29T18:03:58Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-25T06:17:16Z",
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": [
{
"number": 192,
"created_at": "2026-02-10T00:34:48Z",
"last_comment_at": "2026-06-21T07:05:12Z",
"last_comment_author": "guerzon"
},
{
"number": 235,
"created_at": "2026-07-13T14:28:27Z",
"last_comment_at": "2026-07-13T14:46:22Z",
"last_comment_author": "Brawdunoir"
},
{
"number": 243,
"created_at": "2026-07-30T06:06:55Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/guerzon/vaultwarden",
"host": "github.com",
"name": "vaultwarden",
"owner": "guerzon"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": "The weighted overall 60 is calibrated to 65 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 60,
"calibrated": 65,
"calibration": "2026-08-02"
}
}
],
"value": 65,
"inputs": {
"security": 54,
"vitality": 74,
"community": 66,
"governance": 65,
"calibration": "2026-08-02",
"engineering": 45,
"ai_readiness": 25,
"weighted_overall_raw": 60
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 74,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"commits_last_year": 35,
"human_commit_share": 1,
"days_since_last_push": 9,
"active_weeks_last_year": 16
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 9 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 9
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "16/52 weeks with commits",
"points": 11.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 16
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "35 commits in the last year",
"points": 14,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 35
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "15 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 93,
"latest_release_tag": "v0.44.0",
"releases_from_tags": false,
"days_since_latest_release": 9,
"mean_days_between_releases": 3.9
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "93 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 93
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 9 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 9
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~3.9 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 3.9
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 10,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 10 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 10
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 66,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"forks": 114,
"stars": 341,
"watchers": 6,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "341 stars",
"points": 41.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 341
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "114 forks",
"points": 17.1,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 114
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "6 watchers",
"points": 3.9,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 6
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": 2,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"readme_badge_services": [
"shields.io"
],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 65,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "moderate",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 43,
"top_contributor_share": 0.429
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 43% of commits",
"points": 12.8,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 43
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "43 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 43
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 4 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 82,
"inputs": {
"merged_prs": 110,
"open_issues": 3,
"closed_issues": 73,
"prs_merged_7d": 0,
"prs_decided_7d": 0,
"prs_merged_30d": 1,
"prs_decided_30d": 1,
"issue_closed_ratio": 0.961,
"closed_unmerged_prs": 33,
"first_time_authors_30d": 0,
"first_time_prs_merged_30d": 0,
"first_time_prs_decided_30d": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "96% of issues closed",
"points": 40.4,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 96
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "110/143 decided PRs merged",
"points": 23.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 110,
"decided": 143
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 16/27 approved changesets -- score normalized to 5",
"points": 7.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 52,
"inputs": {
"followers": 23,
"owner_type": "User",
"is_verified": null,
"owner_login": "guerzon",
"public_repos": 18,
"account_age_days": 2845
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "23 followers of guerzon",
"points": 9.9,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 23,
"login": "guerzon"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "18 public repos, account ~7 yr old",
"points": 21.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 18
}
},
{
"code": "account_age_years",
"params": {
"years": 7
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "weak",
"name": "Engineering Quality",
"value": 45,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "weak",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 42,
"inputs": {
"has_ci": true,
"has_tests": false,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "25 out of 27 merged PRs checked by a CI test -- score normalized to 9",
"points": 18,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [
"helm",
"helm-charts",
"vaultwarden",
"kubernetes",
"bitwarden",
"docker"
],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "6 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 6
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 54,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 54,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 5.4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "25 out of 27 merged PRs checked by a CI test -- score normalized to 9",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 16/27 approved changesets -- score normalized to 5",
"points": 3.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 4 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "15 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 10
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 25,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "weak",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.92,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "92 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 92,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 22,
"inputs": {
"has_nix": false,
"has_tests": false,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.02,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "2 of the last 100 commits agent-authored or agent-credited",
"points": 4,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 2,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "critical",
"name": "Code legibility for models",
"note": "Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"manageable_file_sizes"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"primary_language": "Go Template",
"largest_source_bytes": null,
"source_files_sampled": 0,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go Template without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Go Template"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "no source files detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_source_files",
"params": {}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [
"application"
],
"labels": [
"network-service"
],
"scores": {
"network-service": 8
},
"primary": "network-service",
"evidence": [
{
"tier": "structure",
"label": "network-service",
"source": "tree.helm",
"weight": 4
},
{
"tier": "structure",
"label": "network-service",
"source": "tree.k8s",
"weight": 4
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": false
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"No resolved dependencies carried a version and a supported ecosystem"
],
"report_type": "repository",
"generated_at": "2026-08-03T17:05:21.177917Z",
"schema_version": "0.30.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/guerzon/vaultwarden.svg",
"full_name": "guerzon/vaultwarden",
"license_state": "standard",
"license_spdx": "MIT"
},
"repoMeta": null,
"notFound": false,
"related": [
{
"id": 6225,
"full_name": "verdaccio/verdaccio",
"url": "https://github.com/verdaccio/verdaccio",
"description": "A lightweight Node.js private proxy registry",
"ecosystem": "npm",
"ecosystems": [
"npm"
],
"primary_language": "TypeScript",
"languages": [
"TypeScript"
],
"topics": [
"nodejs",
"npm",
"registry",
"private-npm",
"verdaccio",
"yarn",
"registry-proxy",
"docker",
"javascript",
"sponsor",
"pnpm",
"kubernetes",
"helm",
"helm-charts",
"private",
"package",
"repository",
"enterprise",
"modules",
"proxy",
"server"
],
"license_spdx": "MIT",
"license_state": "standard",
"stars": 17804,
"forks": 1473,
"watchers": 150,
"monthly_downloads": 8520439,
"latest_score": 94,
"latest_band": "exceptional",
"latest_scanned_at": "2026-08-05T05:18:23.547272Z",
"has_high_risk_jurisdiction_exposure": false,
"has_malicious_dependency": false,
"growth_authenticity": "unverified",
"abandonment_state": "maintained",
"red_flags": [],
"icon_url": "/icon/v1/verdaccio/verdaccio?v=5509b710-1",
"icon_source_type": "homepage",
"badge_url": ""
},
{
"id": 33954,
"full_name": "zarf-dev/zarf",
"url": "https://github.com/zarf-dev/zarf",
"description": "The Airgap Native Package Manager for Kubernetes",
"ecosystem": "go",
"ecosystems": [
"go",
"npm"
],
"primary_language": "Go",
"languages": [
"Go"
],
"topics": [
"k8s",
"airgap",
"cloud-native",
"helm",
"government",
"dod",
"k3s",
"kustomize",
"oci",
"cosign",
"docker",
"docker-registry",
"gitops",
"kubernetes",
"sbom",
"hacktoberfest"
],
"license_spdx": "Apache-2.0",
"license_state": "standard",
"stars": 1985,
"forks": 266,
"watchers": 24,
"monthly_downloads": null,
"latest_score": 96,
"latest_band": "exceptional",
"latest_scanned_at": "2026-07-22T08:23:42.510710Z",
"has_high_risk_jurisdiction_exposure": false,
"has_malicious_dependency": false,
"growth_authenticity": "organic",
"abandonment_state": "maintained",
"red_flags": [],
"icon_url": "",
"icon_source_type": null,
"badge_url": ""
},
{
"id": 219,
"full_name": "dani-garcia/vaultwarden",
"url": "https://github.com/dani-garcia/vaultwarden",
"description": "Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs",
"ecosystem": "crates",
"ecosystems": [
"crates",
"npm"
],
"primary_language": "Rust",
"languages": [
"Rust"
],
"topics": [
"vaultwarden",
"bitwarden",
"rust",
"docker",
"rocket",
"bitwarden-rs"
],
"license_spdx": "AGPL-3.0",
"license_state": "standard",
"stars": 64951,
"forks": 3083,
"watchers": 298,
"monthly_downloads": 78,
"latest_score": 92,
"latest_band": "excellent",
"latest_scanned_at": "2026-08-04T23:21:05.195945Z",
"has_high_risk_jurisdiction_exposure": false,
"has_malicious_dependency": false,
"growth_authenticity": "unverified",
"abandonment_state": "maintained",
"red_flags": [],
"icon_url": "/icon/v1/dani-garcia/vaultwarden?v=b060f728-1",
"icon_source_type": "avatar",
"badge_url": ""
},
{
"id": 54116,
"full_name": "podman-container-tools/podman",
"url": "https://github.com/podman-container-tools/podman",
"description": "Podman: A tool for managing OCI containers and pods.",
"ecosystem": "go",
"ecosystems": [
"go",
"pypi"
],
"primary_language": "Go",
"languages": [
"Go",
"Shell"
],
"topics": [
"containers",
"docker",
"kubernetes",
"linux",
"oci"
],
"license_spdx": "Apache-2.0",
"license_state": "standard",
"stars": 32450,
"forks": 3272,
"watchers": 218,
"monthly_downloads": null,
"latest_score": 99,
"latest_band": "exceptional",
"latest_scanned_at": "2026-08-05T07:37:12.083212Z",
"has_high_risk_jurisdiction_exposure": false,
"has_malicious_dependency": false,
"growth_authenticity": "unverified",
"abandonment_state": "maintained",
"red_flags": [],
"icon_url": "/icon/v1/podman-container-tools/podman?v=3d28aa58-1",
"icon_source_type": "homepage",
"badge_url": ""
},
{
"id": 52222,
"full_name": "IBM/mcp-context-forge",
"url": "https://github.com/IBM/mcp-context-forge",
"description": "An AI Gateway, registry, and proxy that sits in front of any MCP, A2A, or REST/gRPC APIs, exposing a unified endpoint with centralized discovery, guardrails and management. Optimizes Agent & Tool calling, and supports plugins.",
"ecosystem": "pypi",
"ecosystems": [
"pypi",
"crates",
"npm"
],
"primary_language": "Python",
"languages": [
"Python"
],
"topics": [
"agents",
"ai",
"api-gateway",
"asyncio",
"authentication-middleware",
"devops",
"docker",
"fastapi",
"federation",
"gateway",
"generative-ai",
"jwt",
"kubernetes",
"llm-agents",
"mcp",
"model-context-protocol",
"observability",
"prompt-engineering",
"python",
"tools",
"api",
"proxy",
"agentic-ai",
"multi-agent",
"json-rpc",
"sse",
"websocket",
"security",
"authentication",
"ai-control-plane",
"control-plane",
"governance"
],
"license_spdx": "Apache-2.0",
"license_state": "standard",
"stars": 4178,
"forks": 789,
"watchers": 34,
"monthly_downloads": null,
"latest_score": 98,
"latest_band": "exceptional",
"latest_scanned_at": "2026-08-03T01:15:29.723980Z",
"has_high_risk_jurisdiction_exposure": false,
"has_malicious_dependency": false,
"growth_authenticity": "unverified",
"abandonment_state": "maintained",
"red_flags": [],
"icon_url": "",
"icon_source_type": null,
"badge_url": ""
},
{
"id": 169,
"full_name": "traefik/traefik",
"url": "https://github.com/traefik/traefik",
"description": "The Cloud Native Application Proxy",
"ecosystem": "go",
"ecosystems": [
"go",
"npm",
"pypi"
],
"primary_language": "Go",
"languages": [
"Go"
],
"topics": [
"microservice",
"docker",
"marathon",
"mesos",
"consul",
"etcd",
"kubernetes",
"load-balancer",
"reverse-proxy",
"zookeeper",
"letsencrypt",
"golang",
"go",
"traefik"
],
"license_spdx": "MIT",
"license_state": "standard",
"stars": 64281,
"forks": 6117,
"watchers": 678,
"monthly_downloads": null,
"latest_score": 97,
"latest_band": "exceptional",
"latest_scanned_at": "2026-08-04T23:20:52.580081Z",
"has_high_risk_jurisdiction_exposure": false,
"has_malicious_dependency": false,
"growth_authenticity": "unverified",
"abandonment_state": "maintained",
"red_flags": [],
"icon_url": "/icon/v1/traefik/traefik?v=69ef58cf-1",
"icon_source_type": "homepage",
"badge_url": ""
}
]
}
}
Öffentliches RegisterSoftware-Gesundheitsbericht Schema 0.30.0 · Metriken 2.5.0 · 2026-08-03 17:05 UTC
Helm chart for Vaultwarden, the (unofficial) Bitwarden-compatible server written in Rust
Bewertungsbadge zur README hinzufügen Vergleichen mit …
Go Template MIT ★ 341 Sterne ⑂ 114 Forks seit März 2022 Auf GitHub ansehen ↗ guerzon/vaultwarden erreicht einen Gesundheitsindex von 65 von 100 und liegt damit im Bereich Gut. Am stärksten schneidet es bei Vitality (74/100) ab, am schwächsten bei AI Readiness (25/100). Zuletzt vor 9 Tagen aktualisiert. 2 Mitwirkende tragen den Großteil der jüngsten Arbeit.
Software-Gesundheitsindex Metriken werden auf einer standardisierten Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr gewichtetes Mittel, kalibriert auf die Verteilung des öffentlichen Registers, sodass die Stufen Perzentilbedeutung tragen; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze Gefährdet von 34.
65
Außergewöhnlich 93-100 Die Spitzengruppe des Registers (≈ obere 5 %); erfüllt im Wesentlichen alle geprüften Kriterien
Exzellent 80-92 Durchgehend stark; geringfügige Lücken
Gut 65-79 Gesund; Lücken sind begrenzt und beherrschbar
Mittel 50-64 Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Schwach 35-49 Wesentliche Schwächen in mehreren Bereichen
Gefährdet 20-34 Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch 1-19 Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
Vitalität Community & Verbreitung Nachhaltigkeit & Governance Engineering-Qualität Sicherheit AI Readiness Bewertungsprofil Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.
Der gewichtete Gesamtwert 60 wird auf der veröffentlichten Indexskala auf 65 kalibriert (Register-Kalibrierung 2026-08-02).
Eigentümerschaft 23 Follower 18 öffentliche Repos seit Okt. 2018
Dieses Repository gehört einem persönlichen Konto . Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.
Metriken nach Kategorie Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?
74 Gut · 21 % des Gesamtindex
Wie die Bewertung erfolgt 28.8/36 Push-Aktualität — letzter Push vor 9 Tagen 11.1/36 Commit-Rhythmus — 16/52 Wochen mit Commits 14/18 Commit-Volumen — 35 Commits im letzten Jahr 10/10 OpenSSF Scorecard: Maintained — 15 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
Wie die Bewertung erfolgt 27/27 Liefert Releases aus — 93 Releases veröffentlicht 36/36 Release-Aktualität — letztes Release vor 9 Tagen 27/27 Release-Rhythmus — ein Release etwa alle 3,9 Tage 0/10 OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?
66 Gut · 17 % des Gesamtindex
Wie die Bewertung erfolgt 41.1/60 Stars — 341 Stars 17.1/25 Forks — 114 Forks 3.9/15 Watcher — 6 Watcher
Verwendete Eingangsdaten
Wie die Bewertung erfolgt 22.5/22.5 README 22.5/22.5 Lizenz — anerkannte Lizenz (MIT) 18/18 CONTRIBUTING-Leitfaden 0/13.5 Verhaltenskodex 0/7.2 Issue-Vorlage 0/6.3 PR-Vorlage
Verwendete Eingangsdaten Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?
65 Gut · 23 % des Gesamtindex
Wie die Bewertung erfolgt 25.2/54 Bus-Faktor — 2 Beitragende decken die Hälfte aller Commits ab 12.8/22.5 Commit-Verteilung — wichtigste beitragende Person verfasste 43 % der Commits 13.5/13.5 Breite der Beitragenden — 43 Beitragende 10/10 OpenSSF Scorecard: Contributors — project has 4 contributing companies or organizations
Verwendete Eingangsdaten
Wie die Bewertung erfolgt 40.4/42 Issue-Lösungsquote — 96 % der Issues geschlossen 23.1/30 PR-Annahme — 110/143 entschiedene PRs gemergt 0/13 Newcomer PR acceptance — kein PR eines Erstbeitragenden in 30 Tagen entschieden 7.5/15 OpenSSF Scorecard: Code-Review — Found 16/27 approved changesets -- score normalized to 5
Verwendete Eingangsdaten Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): newcomer_pr_acceptance. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt 10/30 Organisatorische Trägerschaft — persönliches (Nutzer-)Konto 0/20 Verifizierte Domain — für Nutzerkonten nicht anwendbar 9.9/25 Reichweite des Inhabers — 23 Follower von guerzon 21.3/25 Kontohistorie — 18 öffentliche Repos, Kontoalter ca. 7 Jahre
Verwendete Eingangsdaten Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.
Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?
45 Schwach · 19 % des Gesamtindex
Wie die Bewertung erfolgt 24/24 CI-Workflows — 2 Workflow(s) 0/24 Tests vorhanden 0/16 Linter-Konfiguration 0/9.6 Pre-Commit-Hooks 0/6.4 .editorconfig 18/20 OpenSSF Scorecard: CI-Tests — 25 out of 27 merged PRs checked by a CI test -- score normalized to 9
Verwendete Eingangsdaten
Wie die Bewertung erfolgt 30/30 README 0/25 Dokumentationsverzeichnis 0/15 Dokumentations-/Homepage-Site 10/10 Repository-Beschreibung 10/10 Topics — 6 Topics 0/10 Wiki
Verwendete Eingangsdaten Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?
54 Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt 7.5/7.5 Binary-Artifacts — no binaries found in the repo 0/7.5 Branch-Protection — keine Daten 2.2/2.5 CI-Tests — 25 out of 27 merged PRs checked by a CI test -- score normalized to 9 0/2.5 CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected 3.8/7.5 Code-Review — Found 16/27 approved changesets -- score normalized to 5 2.5/2.5 Contributors — project has 4 contributing companies or organizations 10/10 Dangerous-Workflow — no dangerous workflow patterns detected 0/7.5 Dependency-Update-Tool — no update tool detected 0/5 Fuzzing — project is not fuzzed 2.5/2.5 Lizenz — license file detected 7.5/7.5 Maintained — 15 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 0/5 Packaging — keine Daten 0/5 Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 0/5 SAST — SAST tool is not run on all commits -- score normalized to 0 0/5 Security-Policy — security policy file not detected 0/7.5 Signed-Releases — Project has not signed or included provenance with any releases. 6.8/7.5 Token-Permissions — detected GitHub workflow tokens with excessive permissions 7.5/7.5 Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection, packaging. Die verbleibenden Gewichte wurden renormalisiert.
Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Trägt ein bewusst kleines Gewicht (4 %): Agenten-Tooling ist ein echtes Pflegesignal, doch ein Repository ohne jedes Signal kann weiterhin 100/100 erreichen.
25 Gefährdet · 4 % des Gesamtindex
Wie die Bewertung erfolgt 0/45 Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln 0/15 Maschinenlesbare Doku (llms.txt) 40/40 Lesbare Commit-Historie — 92 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
Wie die Bewertung erfolgt 18/18 Bootstrap mit einem Befehl — Makefile 0/22 Automatisierte Tests 0/11 Lint-/Format-Konfiguration 0/11 Statische Typprüfung 0/10 Reproduzierbare Umgebung 4/10 Belegte Agentenpraxis — 2 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben 0/8 Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet 0/10 OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
Wie die Bewertung erfolgt 0/45 Typprüfbarer Code — Go Template ohne Typprüfungs-Konfiguration 0/55 Handhabbare Dateigrößen — keine Quelldateien erkannt
Verwendete Eingangsdaten Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Handhabbare Dateigrößen. Die verbleibenden Gewichte wurden renormalisiert.
Eckdaten 341 GitHub-Sterne
43 Mitwirkende
35 Commits, letzte 12 Monate
9 Tage seit letztem Push
93 Releases
2 Bus-Faktor
3 offene Issues
PyPI Paket-Ökosysteme
Warnungen zur Datenerhebung Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token No resolved dependencies carried a version and a supported ecosystem
Weitere Details Stern- und Fork-Verlauf 0 ★ / 114 ⇿ 0 Sterne
114 Forks
91 Releases
Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.
Forks Forks/Tag Releases
Gesamt 3 Jahre Jahr 3 Monate Monat
0 20 40 60 80 100 120 114 4 2022-04 2024-06 2026-07 Major 0 Minor 37 Patch 54
Jeder Punkt umfasst 4 Tage.
OpenSSF Scorecard 5.4 / 10 5.4 Gesamtwert
Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard . Jede Prüfung honoriert eine Sicherheits-Praxis , nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt). Scorecard v5.5.0 · 2026-08-03 17:04 UTC
10 Binary-Artifacts no binaries found in the repo k. A. Branch-Protection internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md 9 CI-Tests 25 out of 27 merged PRs checked by a CI test -- score normalized to 9 0 CII-Best-Practices no effort to earn an OpenSSF best practices badge detected 5 Code-Review Found 16/27 approved changesets -- score normalized to 5 10 Contributors project has 4 contributing companies or organizations 10 Dangerous-Workflow no dangerous workflow patterns detected 0 Dependency-Update-Tool no update tool detected 0 Fuzzing project is not fuzzed 10 License license file detected 10 Maintained 15 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10 k. A. Packaging packaging workflow not detected 0 Pinned-Dependencies dependency not pinned by hash detected -- score normalized to 0 0 SAST SAST tool is not run on all commits -- score normalized to 0 0 Security-Policy security policy file not detected 0 Signed-Releases Project has not signed or included provenance with any releases. 9 Token-Permissions detected GitHub workflow tokens with excessive permissions 10 Vulnerabilities 0 existing vulnerabilities detected
Alle Abhängigkeiten 2 Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 0 direkte und 2 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.
Registry Paket Version Beziehung PyPI yamale —indirekt PyPI yamllint —indirekt
Abhängigkeits-Advisories nicht bewertet Der Advisory-Abgleich konnte für diesen Bericht nicht ausgeführt werden: No resolved dependencies carried a version and a supported ecosystem
JSON-Rohbericht maschinenlesbar