Public record
Software health reportschema 0.17.0 · metrics 1.13.0 · 2026-07-21 04:42 UTC

NVIDIA / TensorRT

NVIDIA® TensorRT™ is an SDK for high-performance deep learning inference on NVIDIA GPUs. This repository contains the open source components of TensorRT.

C++Apache-2.0★ 13,169 stars⑂ 2,389 forkssince May 2019View on GitHub ↗

NVIDIA/TensorRT holds a health index of 70 out of 100, placing it in the Good band. It scores highest on Community & Adoption (88/100) and lowest on Security (21/100). It was last updated 13 days ago. 3 contributors account for most of its recent work.

70
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

70
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

NVIDIA CorporationOrganization
28,173 followers769 public repossince May 2012

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
PyPIpolygraphy0.50.3211,6471254 days ago
PyPIonnx_graphsurgeon0.6.1719,0768103 days ago
PyPIpytorch_quantizationpoints to another repo — not scored2.2.1-5990 days agonvidiadeep-learningmachine-learningsupervised-learningunsupervised-learningreinforcement-learninglogging
PyPIpolygraphy_trtexec0.0.9-31062 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

76Good · 22% of overall
How it's scored
28.8/36Push recency — last push 13 days ago
12.5/36Commit cadence — 18/52 weeks with commits
12.7/18Commit volume — 25 commits in the last year
0/10OpenSSF Scorecard: Maintained — no data
Inputs used
commits_last_year25
human_commit_share
days_since_last_push13
active_weeks_last_year18

Release discipline

100Excellent
How it's scored
27/27Ships releases — 70 releases published
36/36Release recency — latest release 26 days ago
27/27Release cadence — a release every ~44.3 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count70
latest_release_tagv11.1
releases_from_tagsno
days_since_latest_release26
mean_days_between_releases44.3

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

88Excellent · 18% of overall
How it's scored
60/60Stars — 13,169 stars
25/25Forks — 2,389 forks
12.2/15Watchers — 157 watchers
Inputs used
forks2,389
stars13,169
watchers157
growth_stateorganic
growth_factor_pct100
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
79.6/80Monthly downloads — 930,723 downloads/month across pypi
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagespolygraphy, onnx_graphsurgeon, polygraphy_trtexec
dependents
ecosystemspypi
total_downloads
monthly_downloads930,723
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

81Good · 24% of overall
How it's scored
36/54Bus factor — 3 contributor(s) cover half of all commits
15/22.5Commit distribution — top contributor authored 33% of commits
13.5/13.5Contributor breadth — 83 contributors
0/10OpenSSF Scorecard: Contributors — no data
Inputs used
bus_factor3
contributors_sampled83
top_contributor_share0.334
How it's scored
40.5/46.8Issue resolution — 87% of issues closed
25.1/38.3PR acceptance — 323/492 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — no data
Inputs used
merged_prs323
open_issues560
closed_issues3,657
issue_closed_ratio0.867
closed_unmerged_prs169
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
25/25Owner reach — 28,173 followers of NVIDIA
25/25Track record — 769 public repos, account ~14 yr old
Inputs used
followers28,173
owner_typeOrganization
is_verified
owner_loginNVIDIA
public_repos769
account_age_days5,184
How it's scored
25/25Published & resolvable — 3 package(s) on pypi
35/35Publish recency — latest publish 54 days ago
20/20Version history — 12 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagespolygraphy, onnx_graphsurgeon, polygraphy_trtexec
ecosystemspypi
any_deprecatedno
min_days_since_publish54

Engineering Quality

Are baseline engineering and documentation practices in place?

74Good · 20% of overall
How it's scored
24/24CI workflows — 5 workflow(s)
24/24Tests present
16/16Linter config — .pylintrc
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

65Moderate
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://developer.nvidia.com/tensorrt
10/10Repository description
10/10Topics — 5 topics
0/10Wiki
Inputs used
topicstensorrt, nvidia, deep-learning, inference, gpu-acceleration
has_wikino
homepagehttps://developer.nvidia.com/tensorrt
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

21Critical · 16% of overall
How it's scored
0/30Security policy (SECURITY.md)
0/25Dependabot config
0/25Dependency lockfiles — published library — lockfiles are an application concern, not expected
0/20CodeQL workflow
Inputs used
sourcefile_signals
lockfiles
manifestspython/requirements.txt
has_codeql_workflowno
has_security_policyno
has_dependabot_configno
Excluded from scoring (no data or not applicable): Dependency lockfiles. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories744
affected_packages29
assessed_packages75
unassessed_packages50
affected_by_severitycritical 8, high 7, moderate 2, unknown 12
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 75 resolved dependencies against OSV. 50 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

54Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
0/40Legible commit history — no data
Inputs used
has_llms_txtno
legible_history_share
agent_instruction_files
agent_instruction_max_bytes
Excluded from scoring (no data or not applicable): Legible commit history. Remaining weights renormalized.
How it's scored
18/18One-command bootstrap — quickstart/Makefile, quickstart/SemanticSegmentation/Makefile, tools/Polygraphy/Makefile, tools/onnx-graphsurgeon/Makefile, tools/polygraphy-extension-trtexec/Makefile, tools/pytorch-quantization/docs/Makefile, tools/tensorflow-quantization/docs/Makefile
22/22Automated tests
11/11Lint / format config — .pylintrc
11/11Static type checking — C++ (statically typed)
0/10Reproducible environment
0/10Demonstrated agent practice — no data
0/8Automated maintenance — no data
0/10OpenSSF Scorecard: Pinned-Dependencies — no data
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageyes
bootstrap_filesquickstart/Makefile, quickstart/SemanticSegmentation/Makefile, tools/Polygraphy/Makefile, tools/onnx-graphsurgeon/Makefile, tools/polygraphy-extension-trtexec/Makefile, tools/pytorch-quantization/docs/Makefile, tools/tensorflow-quantization/docs/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share
toolchain_manifests
dependency_bot_commit_share
Excluded from scoring (no data or not applicable): Demonstrated agent practice, Automated maintenance. Remaining weights renormalized.
How it's scored
45/45Type-checkable code — C++ (statically typed)
44.8/55Manageable file sizes — 199/1,073 source files over 60KB
Inputs used
primary_languageC++
largest_source_bytes3,041,274
source_files_sampled1,073
oversized_source_files199
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples, notebooks, samples
Inputs used
example_dirsexamples, notebooks, samples
has_mcp_signalno
api_schema_files

Key facts

13,169GitHub stars
83contributors
25commits, last 12 months
13days since last push
70releases
3bus factor
560open issues
PyPIpackage ecosystems

Data collection warnings

  • pypi package 'pytorch_quantization' points at a different repository (https://github.com/NVIDIA); excluded from ecosystem scoring
  • Could not fetch pypi package 'tensorflow_quantization' from its registry
  • Advisory severity resolved for 120 of 422 advisories (lookup cap); the remainder are reported as unknown severity
  • OpenSSF Scorecard did not return a usable result (2026/07/21 04:41:52 Warning: PATs stored in env variables GITHUB_AUTH_TOKEN and GITHUB_TOKEN differ. Scorecard will use the former.); skipping Scorecard checks

More detail

Star and fork history 13,169 ★ / 0 ⇿
13,169Stars

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

Only the most recent history is shown — this repository exceeds the collection window, so the earliest history is not captured.

12,00012,20012,40012,60012,80013,00013,20013,169102025-102026-032026-07
All dependencies 125

Full resolved dependency set from the GitHub dependency graph: 0 direct and 125 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
PyPIabsl-pyindirect
PyPIaccelerate1.2.1indirect
PyPIapex0.9.10devindirect
PyPIargparseindirect
PyPIbuild1.0.0indirect
PyPIcoloredindirect
PyPIcolored2.3.2indirect
PyPIcontrolnet-aux0.0.6indirect
PyPIcuda-bindingsindirect
PyPIcuda-pythonindirect
PyPIcuda-python12.9.0indirect
PyPIcupy-cuda12xindirect
PyPIcupy-cuda12x13.6.0indirect
PyPIdiffusers0.35.2indirect
PyPIdocutils0.16indirect
PyPIdocutils0.18.1indirect
PyPIftfyindirect
PyPIfuro2024.8.6indirect
PyPIgcloudindirect
PyPIgoogle-cloud-storageindirect
PyPIhuggingface-hub0.11.0indirect
PyPIhuggingface-hub0.4.0indirect
PyPIimageio-ffmpegindirect
PyPImatplotlibindirect
PyPIml-dtypesindirect
PyPImpi4py4.1.1indirect
PyPImyst-parser3.0.1indirect
PyPInccl4py0.1.1indirect
PyPInltk3.9.1indirect
PyPInumbaindirect
PyPInumba-cudaindirect
PyPInumpyindirect
PyPInumpy1.23.0indirect
PyPInumpy1.23.1indirect
PyPInumpy1.26.4indirect
PyPInvidia-cutlass-dsl4.5.0indirect
PyPInvidia-modelopt0.31.0indirect
PyPInvidia-modelopt0.35.0indirect
PyPInvidia-pyindexindirect
PyPInvidia-tensorrtindirect
PyPInvtxindirect
PyPIonnxindirect
PyPIonnx1.13.1indirect
PyPIonnx1.14.0indirect
PyPIonnx1.17.0indirect
PyPIonnx1.18.0indirect
PyPIonnx1.20.0indirect
PyPIonnx1.9.0indirect
PyPIonnx-graphsurgeonindirect
PyPIonnx-graphsurgeon0.5.2indirect
PyPIonnxconverter-common1.12.2indirect
PyPIonnxmltools1.11.1indirect
PyPIonnxruntimeindirect
PyPIonnxruntime1.12.1indirect
PyPIonnxruntime1.15.0indirect
PyPIonnxruntime1.18.1indirect
PyPIonnxruntime1.19.2indirect
PyPIonnxruntime1.8.1indirect
PyPIonnxruntime-gpuindirect
PyPIonnxscriptindirect
PyPIonnxscript0.5.4indirect
PyPIopencv-python-headless4.8.0.74indirect
PyPIpeft0.17.0indirect
PyPIpillowindirect
PyPIpillow11.3.0indirect
PyPIpolygraphyindirect
PyPIpolygraphy0.49.0indirect
PyPIpolygraphy0.49.22indirect
PyPIpolygraphy0.50.1indirect
PyPIprettytableindirect
PyPIprotobufindirect
PyPIprotobuf3.20.2indirect
PyPIprotobuf3.20.3indirect
PyPIpycudaindirect
PyPIpytestindirect
PyPIpytest-console-scriptsindirect
PyPIpytest-rerunfailuresindirect
PyPIpytest-virtualenvindirect
PyPIpytest-xdistindirect
PyPIpywin32indirect
PyPIpyyamlindirect
PyPIpyyaml6.0.3indirect
PyPIrequests2.25.1indirect
PyPIrequests2.32.4indirect
PyPIrequests2.33.0indirect
PyPIscipyindirect
PyPIsentencepieceindirect
PyPIsentencepiece0.1.95indirect
PyPIsentencepiece0.1.97indirect
PyPIsetuptoolsindirect
PyPIsphinx7.1.2indirect
PyPIsphinx-glpi-themeindirect
PyPIsympy1.9indirect
PyPItabulateindirect
PyPItensorflowindirect
PyPItensorflow-gpu2.8.0indirect
PyPItensorrtindirect
PyPItf2onnxindirect
PyPItf2onnx1.10.1indirect
PyPItomlindirect
PyPItomli2.0.0indirect
PyPItorchindirect
PyPItorch1.10indirect
PyPItorch1.10.2indirect
PyPItorch1.10.2+cu113indirect
PyPItorch1.11.0indirect
PyPItorch1.11.0+cu113indirect
PyPItorch1.13.1indirect
PyPItorch2.8.0indirect
PyPItorch2.9.1indirect
PyPItorchvisionindirect
PyPItorchvision0.11.3indirect
PyPItorchvision0.12.0indirect
PyPItqdm4.66.4indirect
PyPItransformers4.18.0indirect
PyPItransformers4.20.0indirect
PyPItransformers4.52.4indirect
PyPItritonindirect
PyPItriton3.2.0indirect
PyPItriton3.5.0indirect
PyPIvirtualenvindirect
PyPIwgetindirect
PyPIwget3.2indirect
PyPIwheelindirect
PyPIwheel0.45.1indirect
Dependency advisories 29

This repository publishes no package the index resolves, so its own dependency graph was assessed — 75 packages, which also include development and test pins that never ship: 29 carry known advisories, of which 0 are direct. 50 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

PackageVersionRelationSeverityAdvisoriesFixed in
nltk3.9.1indirectcritical183.10.0
onnx1.13.1indirectcritical211.22.0
onnx1.14.0indirectcritical211.22.0
onnx1.17.0indirectcritical141.22.0
onnx1.18.0indirectcritical131.22.0
onnx1.20.0indirectcritical131.22.0
onnx1.9.0indirectcritical231.22.0
pillow11.3.0indirectcritical3112.3.0
diffusers0.35.2indirecthigh50.38.0
opencv-python-headless4.8.0.74indirecthigh24.8.1.78
protobuf3.20.2indirecthigh46.33.5
protobuf3.20.3indirecthigh46.33.5
sentencepiece0.1.95indirecthigh20.2.1
sentencepiece0.1.97indirecthigh20.2.1
tensorflow-gpu2.8.0indirecthigh2472.11.1
requests2.25.1indirectmoderate82.33.0
requests2.32.4indirectmoderate22.33.0
torch1.10indirectunknown30
torch1.10.2indirectunknown30
torch1.10.2+cu113indirectunknown30
torch1.11.0indirectunknown30
torch1.11.0+cu113indirectunknown30
torch1.13.1indirectunknown28
torch2.8.0indirectunknown8
torch2.9.1indirectunknown4
transformers4.18.0indirectunknown50
transformers4.20.0indirectunknown50
transformers4.52.4indirectunknown22
wheel0.45.1indirectunknown2

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "tensorrt",
        "nvidia",
        "deep-learning",
        "inference",
        "gpu-acceleration"
      ],
      "is_fork": false,
      "size_kb": 144933,
      "has_wiki": false,
      "homepage": "https://developer.nvidia.com/tensorrt",
      "languages": {
        "C": 20527,
        "C++": 247597953,
        "Cuda": 771403,
        "HTML": 60248,
        "CMake": 176616,
        "Shell": 23080,
        "Python": 3318529,
        "Makefile": 9329,
        "Batchfile": 2731,
        "PureBasic": 388,
        "Dockerfile": 30451,
        "PowerShell": 162,
        "Jupyter Notebook": 603346
      },
      "pushed_at": "2026-07-07T20:42:11Z",
      "created_at": "2019-05-02T22:02:08Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T03:14:15Z",
      "description": "NVIDIA® TensorRT™ is an SDK for high-performance deep learning inference on NVIDIA GPUs. This repository contains the open source components of TensorRT.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "C++",
      "significant_languages": [
        "C++"
      ]
    },
    "owner": {
      "blog": "https://nvidia.com",
      "name": "NVIDIA Corporation",
      "type": "Organization",
      "login": "NVIDIA",
      "company": null,
      "location": "2788 San Tomas Expressway, Santa Clara, CA, 95051",
      "followers": 28173,
      "avatar_url": "https://avatars.githubusercontent.com/u/1728152?v=4",
      "created_at": "2012-05-10T22:06:34Z",
      "is_verified": null,
      "public_repos": 769,
      "account_age_days": 5184
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": null,
      "profile_has_license": true
    },
    "activity": {
      "releases_count": 70,
      "commits_last_year": 25,
      "latest_release_at": "2026-06-24T21:27:05Z",
      "latest_release_tag": "v11.1",
      "releases_from_tags": false,
      "days_since_last_push": 13,
      "active_weeks_last_year": 18,
      "days_since_latest_release": 26,
      "mean_days_between_releases": 44.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "polygraphy",
          "exists": true,
          "license": "Apache 2.0",
          "keywords": [
            "Intended Audience :: Developers",
            "Programming Language :: Python :: 3"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/polygraphy/",
          "is_deprecated": false,
          "latest_version": "0.50.3",
          "repository_url": "https://github.com/NVIDIA/TensorRT/tree/main/tools/Polygraphy",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 211647,
          "first_published_at": "2020-10-17T15:39:03.980211Z",
          "latest_published_at": "2026-05-27T21:35:58.591560Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 54
        },
        {
          "name": "onnx_graphsurgeon",
          "exists": true,
          "license": "Apache 2.0",
          "keywords": [
            "Intended Audience :: Developers",
            "Programming Language :: Python :: 3"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/onnx_graphsurgeon/",
          "is_deprecated": false,
          "latest_version": "0.6.1",
          "repository_url": "https://github.com/NVIDIA/TensorRT/tree/main/tools/onnx-graphsurgeon",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 719076,
          "first_published_at": "2020-09-18T22:49:45.474964Z",
          "latest_published_at": "2026-04-08T19:29:29.678727Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 103
        },
        {
          "name": "pytorch_quantization",
          "exists": true,
          "license": "Apache2",
          "keywords": [
            "nvidia",
            "deep learning",
            "machine learning",
            "supervised learning",
            "unsupervised learning",
            "reinforcement learning",
            "logging",
            "Development Status :: 3 - Alpha",
            "Environment :: Console",
            "Intended Audience :: Developers",
            "Intended Audience :: Information Technology",
            "Intended Audience :: Science/Research",
            "License :: OSI Approved :: Apache Software License",
            "Natural Language :: English",
            "Operating System :: OS Independent",
            "Programming Language :: Python :: 3.5",
            "Programming Language :: Python :: 3.6",
            "Programming Language :: Python :: 3.7",
            "Programming Language :: Python :: 3.8",
            "Topic :: Scientific/Engineering",
            "Topic :: Scientific/Engineering :: Artificial Intelligence",
            "Topic :: Scientific/Engineering :: Image Recognition",
            "Topic :: Software Development :: Libraries",
            "Topic :: Utilities"
          ],
          "ecosystem": "pypi",
          "matches_repo": false,
          "registry_url": "https://pypi.org/project/pytorch_quantization/",
          "is_deprecated": false,
          "latest_version": "2.2.1",
          "repository_url": "https://github.com/NVIDIA",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2020-11-04T23:27:42.358892Z",
          "latest_published_at": "2023-11-03T10:51:39.086395Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 990
        },
        {
          "name": "polygraphy_trtexec",
          "exists": true,
          "license": "Apache 2.0",
          "keywords": [
            "Intended Audience :: Developers",
            "Programming Language :: Python :: 3"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/polygraphy_trtexec/",
          "is_deprecated": false,
          "latest_version": "0.0.9",
          "repository_url": "https://github.com/NVIDIA/TensorRT/tree/main/tools/Polygraphy",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2022-08-10T20:26:51.188473Z",
          "latest_published_at": "2023-08-24T00:41:05.354356Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1062
        }
      ]
    },
    "popularity": {
      "forks": 2389,
      "stars": 13169,
      "watchers": 157,
      "star_history": {
        "days": [
          {
            "date": "2025-10-25",
            "count": 3
          },
          {
            "date": "2025-10-26",
            "count": 3
          },
          {
            "date": "2025-10-27",
            "count": 7
          },
          {
            "date": "2025-10-28",
            "count": 7
          },
          {
            "date": "2025-10-29",
            "count": 7
          },
          {
            "date": "2025-10-30",
            "count": 5
          },
          {
            "date": "2025-10-31",
            "count": 8
          },
          {
            "date": "2025-11-01",
            "count": 2
          },
          {
            "date": "2025-11-02",
            "count": 1
          },
          {
            "date": "2025-11-03",
            "count": 1
          },
          {
            "date": "2025-11-04",
            "count": 8
          },
          {
            "date": "2025-11-05",
            "count": 4
          },
          {
            "date": "2025-11-06",
            "count": 8
          },
          {
            "date": "2025-11-07",
            "count": 5
          },
          {
            "date": "2025-11-08",
            "count": 1
          },
          {
            "date": "2025-11-09",
            "count": 3
          },
          {
            "date": "2025-11-10",
            "count": 6
          },
          {
            "date": "2025-11-11",
            "count": 1
          },
          {
            "date": "2025-11-12",
            "count": 4
          },
          {
            "date": "2025-11-13",
            "count": 1
          },
          {
            "date": "2025-11-14",
            "count": 2
          },
          {
            "date": "2025-11-15",
            "count": 3
          },
          {
            "date": "2025-11-16",
            "count": 3
          },
          {
            "date": "2025-11-17",
            "count": 5
          },
          {
            "date": "2025-11-18",
            "count": 9
          },
          {
            "date": "2025-11-19",
            "count": 7
          },
          {
            "date": "2025-11-20",
            "count": 7
          },
          {
            "date": "2025-11-21",
            "count": 4
          },
          {
            "date": "2025-11-22",
            "count": 1
          },
          {
            "date": "2025-11-23",
            "count": 3
          },
          {
            "date": "2025-11-24",
            "count": 2
          },
          {
            "date": "2025-11-25",
            "count": 8
          },
          {
            "date": "2025-11-26",
            "count": 4
          },
          {
            "date": "2025-11-27",
            "count": 4
          },
          {
            "date": "2025-11-28",
            "count": 3
          },
          {
            "date": "2025-11-29",
            "count": 2
          },
          {
            "date": "2025-11-30",
            "count": 2
          },
          {
            "date": "2025-12-01",
            "count": 2
          },
          {
            "date": "2025-12-02",
            "count": 4
          },
          {
            "date": "2025-12-03",
            "count": 3
          },
          {
            "date": "2025-12-04",
            "count": 2
          },
          {
            "date": "2025-12-05",
            "count": 3
          },
          {
            "date": "2025-12-06",
            "count": 4
          },
          {
            "date": "2025-12-07",
            "count": 5
          },
          {
            "date": "2025-12-08",
            "count": 2
          },
          {
            "date": "2025-12-09",
            "count": 8
          },
          {
            "date": "2025-12-10",
            "count": 6
          },
          {
            "date": "2025-12-11",
            "count": 4
          },
          {
            "date": "2025-12-12",
            "count": 3
          },
          {
            "date": "2025-12-13",
            "count": 5
          },
          {
            "date": "2025-12-14",
            "count": 1
          },
          {
            "date": "2025-12-15",
            "count": 2
          },
          {
            "date": "2025-12-16",
            "count": 1
          },
          {
            "date": "2025-12-17",
            "count": 4
          },
          {
            "date": "2025-12-18",
            "count": 3
          },
          {
            "date": "2025-12-19",
            "count": 4
          },
          {
            "date": "2025-12-20",
            "count": 2
          },
          {
            "date": "2025-12-21",
            "count": 2
          },
          {
            "date": "2025-12-22",
            "count": 5
          },
          {
            "date": "2025-12-23",
            "count": 8
          },
          {
            "date": "2025-12-24",
            "count": 6
          },
          {
            "date": "2025-12-25",
            "count": 2
          },
          {
            "date": "2025-12-26",
            "count": 9
          },
          {
            "date": "2025-12-27",
            "count": 3
          },
          {
            "date": "2025-12-28",
            "count": 5
          },
          {
            "date": "2025-12-29",
            "count": 5
          },
          {
            "date": "2025-12-30",
            "count": 7
          },
          {
            "date": "2025-12-31",
            "count": 1
          },
          {
            "date": "2026-01-01",
            "count": 2
          },
          {
            "date": "2026-01-02",
            "count": 2
          },
          {
            "date": "2026-01-03",
            "count": 1
          },
          {
            "date": "2026-01-04",
            "count": 4
          },
          {
            "date": "2026-01-05",
            "count": 5
          },
          {
            "date": "2026-01-06",
            "count": 7
          },
          {
            "date": "2026-01-07",
            "count": 10
          },
          {
            "date": "2026-01-08",
            "count": 5
          },
          {
            "date": "2026-01-09",
            "count": 5
          },
          {
            "date": "2026-01-10",
            "count": 3
          },
          {
            "date": "2026-01-11",
            "count": 2
          },
          {
            "date": "2026-01-12",
            "count": 5
          },
          {
            "date": "2026-01-13",
            "count": 3
          },
          {
            "date": "2026-01-14",
            "count": 7
          },
          {
            "date": "2026-01-15",
            "count": 4
          },
          {
            "date": "2026-01-16",
            "count": 1
          },
          {
            "date": "2026-01-17",
            "count": 5
          },
          {
            "date": "2026-01-18",
            "count": 6
          },
          {
            "date": "2026-01-19",
            "count": 2
          },
          {
            "date": "2026-01-20",
            "count": 4
          },
          {
            "date": "2026-01-21",
            "count": 5
          },
          {
            "date": "2026-01-22",
            "count": 2
          },
          {
            "date": "2026-01-23",
            "count": 3
          },
          {
            "date": "2026-01-24",
            "count": 4
          },
          {
            "date": "2026-01-25",
            "count": 3
          },
          {
            "date": "2026-01-26",
            "count": 3
          },
          {
            "date": "2026-01-27",
            "count": 5
          },
          {
            "date": "2026-01-28",
            "count": 6
          },
          {
            "date": "2026-01-29",
            "count": 7
          },
          {
            "date": "2026-01-30",
            "count": 3
          },
          {
            "date": "2026-01-31",
            "count": 5
          },
          {
            "date": "2026-02-01",
            "count": 2
          },
          {
            "date": "2026-02-02",
            "count": 3
          },
          {
            "date": "2026-02-03",
            "count": 2
          },
          {
            "date": "2026-02-04",
            "count": 3
          },
          {
            "date": "2026-02-06",
            "count": 3
          },
          {
            "date": "2026-02-07",
            "count": 3
          },
          {
            "date": "2026-02-08",
            "count": 2
          },
          {
            "date": "2026-02-09",
            "count": 3
          },
          {
            "date": "2026-02-10",
            "count": 6
          },
          {
            "date": "2026-02-11",
            "count": 6
          },
          {
            "date": "2026-02-12",
            "count": 3
          },
          {
            "date": "2026-02-13",
            "count": 1
          },
          {
            "date": "2026-02-14",
            "count": 3
          },
          {
            "date": "2026-02-15",
            "count": 1
          },
          {
            "date": "2026-02-16",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 2
          },
          {
            "date": "2026-02-18",
            "count": 2
          },
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-02-21",
            "count": 2
          },
          {
            "date": "2026-02-22",
            "count": 5
          },
          {
            "date": "2026-02-23",
            "count": 3
          },
          {
            "date": "2026-02-24",
            "count": 1
          },
          {
            "date": "2026-02-25",
            "count": 3
          },
          {
            "date": "2026-02-26",
            "count": 6
          },
          {
            "date": "2026-02-27",
            "count": 6
          },
          {
            "date": "2026-02-28",
            "count": 2
          },
          {
            "date": "2026-03-01",
            "count": 3
          },
          {
            "date": "2026-03-02",
            "count": 2
          },
          {
            "date": "2026-03-03",
            "count": 8
          },
          {
            "date": "2026-03-04",
            "count": 3
          },
          {
            "date": "2026-03-05",
            "count": 9
          },
          {
            "date": "2026-03-06",
            "count": 5
          },
          {
            "date": "2026-03-07",
            "count": 5
          },
          {
            "date": "2026-03-08",
            "count": 1
          },
          {
            "date": "2026-03-09",
            "count": 4
          },
          {
            "date": "2026-03-10",
            "count": 3
          },
          {
            "date": "2026-03-11",
            "count": 5
          },
          {
            "date": "2026-03-12",
            "count": 8
          },
          {
            "date": "2026-03-13",
            "count": 3
          },
          {
            "date": "2026-03-14",
            "count": 4
          },
          {
            "date": "2026-03-15",
            "count": 2
          },
          {
            "date": "2026-03-16",
            "count": 3
          },
          {
            "date": "2026-03-17",
            "count": 5
          },
          {
            "date": "2026-03-18",
            "count": 6
          },
          {
            "date": "2026-03-19",
            "count": 5
          },
          {
            "date": "2026-03-20",
            "count": 3
          },
          {
            "date": "2026-03-21",
            "count": 7
          },
          {
            "date": "2026-03-23",
            "count": 5
          },
          {
            "date": "2026-03-24",
            "count": 4
          },
          {
            "date": "2026-03-25",
            "count": 8
          },
          {
            "date": "2026-03-26",
            "count": 2
          },
          {
            "date": "2026-03-27",
            "count": 5
          },
          {
            "date": "2026-03-28",
            "count": 4
          },
          {
            "date": "2026-03-29",
            "count": 2
          },
          {
            "date": "2026-03-30",
            "count": 4
          },
          {
            "date": "2026-03-31",
            "count": 8
          },
          {
            "date": "2026-04-01",
            "count": 4
          },
          {
            "date": "2026-04-02",
            "count": 4
          },
          {
            "date": "2026-04-03",
            "count": 5
          },
          {
            "date": "2026-04-04",
            "count": 3
          },
          {
            "date": "2026-04-05",
            "count": 4
          },
          {
            "date": "2026-04-06",
            "count": 2
          },
          {
            "date": "2026-04-07",
            "count": 7
          },
          {
            "date": "2026-04-08",
            "count": 3
          },
          {
            "date": "2026-04-09",
            "count": 7
          },
          {
            "date": "2026-04-10",
            "count": 4
          },
          {
            "date": "2026-04-11",
            "count": 4
          },
          {
            "date": "2026-04-12",
            "count": 2
          },
          {
            "date": "2026-04-13",
            "count": 5
          },
          {
            "date": "2026-04-14",
            "count": 4
          },
          {
            "date": "2026-04-15",
            "count": 5
          },
          {
            "date": "2026-04-16",
            "count": 2
          },
          {
            "date": "2026-04-17",
            "count": 6
          },
          {
            "date": "2026-04-18",
            "count": 2
          },
          {
            "date": "2026-04-19",
            "count": 5
          },
          {
            "date": "2026-04-20",
            "count": 6
          },
          {
            "date": "2026-04-21",
            "count": 4
          },
          {
            "date": "2026-04-22",
            "count": 4
          },
          {
            "date": "2026-04-23",
            "count": 2
          },
          {
            "date": "2026-04-24",
            "count": 6
          },
          {
            "date": "2026-04-25",
            "count": 1
          },
          {
            "date": "2026-04-26",
            "count": 3
          },
          {
            "date": "2026-04-27",
            "count": 5
          },
          {
            "date": "2026-04-28",
            "count": 5
          },
          {
            "date": "2026-04-29",
            "count": 6
          },
          {
            "date": "2026-04-30",
            "count": 1
          },
          {
            "date": "2026-05-01",
            "count": 3
          },
          {
            "date": "2026-05-02",
            "count": 1
          },
          {
            "date": "2026-05-04",
            "count": 3
          },
          {
            "date": "2026-05-05",
            "count": 5
          },
          {
            "date": "2026-05-06",
            "count": 3
          },
          {
            "date": "2026-05-07",
            "count": 5
          },
          {
            "date": "2026-05-08",
            "count": 5
          },
          {
            "date": "2026-05-09",
            "count": 1
          },
          {
            "date": "2026-05-10",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 3
          },
          {
            "date": "2026-05-12",
            "count": 3
          },
          {
            "date": "2026-05-13",
            "count": 4
          },
          {
            "date": "2026-05-14",
            "count": 4
          },
          {
            "date": "2026-05-15",
            "count": 4
          },
          {
            "date": "2026-05-16",
            "count": 3
          },
          {
            "date": "2026-05-17",
            "count": 3
          },
          {
            "date": "2026-05-18",
            "count": 1
          },
          {
            "date": "2026-05-19",
            "count": 7
          },
          {
            "date": "2026-05-20",
            "count": 5
          },
          {
            "date": "2026-05-21",
            "count": 3
          },
          {
            "date": "2026-05-22",
            "count": 5
          },
          {
            "date": "2026-05-23",
            "count": 1
          },
          {
            "date": "2026-05-24",
            "count": 4
          },
          {
            "date": "2026-05-25",
            "count": 3
          },
          {
            "date": "2026-05-26",
            "count": 2
          },
          {
            "date": "2026-05-27",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 4
          },
          {
            "date": "2026-05-29",
            "count": 4
          },
          {
            "date": "2026-05-30",
            "count": 4
          },
          {
            "date": "2026-05-31",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 3
          },
          {
            "date": "2026-06-02",
            "count": 3
          },
          {
            "date": "2026-06-03",
            "count": 3
          },
          {
            "date": "2026-06-04",
            "count": 2
          },
          {
            "date": "2026-06-05",
            "count": 2
          },
          {
            "date": "2026-06-06",
            "count": 3
          },
          {
            "date": "2026-06-07",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 6
          },
          {
            "date": "2026-06-09",
            "count": 4
          },
          {
            "date": "2026-06-10",
            "count": 5
          },
          {
            "date": "2026-06-11",
            "count": 3
          },
          {
            "date": "2026-06-12",
            "count": 5
          },
          {
            "date": "2026-06-13",
            "count": 2
          },
          {
            "date": "2026-06-14",
            "count": 3
          },
          {
            "date": "2026-06-15",
            "count": 4
          },
          {
            "date": "2026-06-16",
            "count": 7
          },
          {
            "date": "2026-06-17",
            "count": 3
          },
          {
            "date": "2026-06-18",
            "count": 4
          },
          {
            "date": "2026-06-19",
            "count": 5
          },
          {
            "date": "2026-06-20",
            "count": 4
          },
          {
            "date": "2026-06-21",
            "count": 3
          },
          {
            "date": "2026-06-22",
            "count": 4
          },
          {
            "date": "2026-06-23",
            "count": 3
          },
          {
            "date": "2026-06-24",
            "count": 5
          },
          {
            "date": "2026-06-25",
            "count": 3
          },
          {
            "date": "2026-06-26",
            "count": 2
          },
          {
            "date": "2026-06-27",
            "count": 2
          },
          {
            "date": "2026-06-28",
            "count": 1
          },
          {
            "date": "2026-06-29",
            "count": 3
          },
          {
            "date": "2026-06-30",
            "count": 3
          },
          {
            "date": "2026-07-01",
            "count": 2
          },
          {
            "date": "2026-07-02",
            "count": 6
          },
          {
            "date": "2026-07-03",
            "count": 3
          },
          {
            "date": "2026-07-05",
            "count": 4
          },
          {
            "date": "2026-07-06",
            "count": 4
          },
          {
            "date": "2026-07-07",
            "count": 4
          },
          {
            "date": "2026-07-08",
            "count": 9
          },
          {
            "date": "2026-07-09",
            "count": 4
          },
          {
            "date": "2026-07-11",
            "count": 2
          },
          {
            "date": "2026-07-12",
            "count": 2
          },
          {
            "date": "2026-07-13",
            "count": 2
          },
          {
            "date": "2026-07-14",
            "count": 5
          },
          {
            "date": "2026-07-15",
            "count": 3
          },
          {
            "date": "2026-07-16",
            "count": 4
          },
          {
            "date": "2026-07-17",
            "count": 5
          },
          {
            "date": "2026-07-18",
            "count": 2
          },
          {
            "date": "2026-07-19",
            "count": 2
          },
          {
            "date": "2026-07-20",
            "count": 3
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": false,
        "collected": 1000,
        "total_stars": 13169
      },
      "open_issues_and_prs": 614
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "notebooks",
        "samples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "quickstart/Makefile",
        "quickstart/SemanticSegmentation/Makefile",
        "tools/Polygraphy/Makefile",
        "tools/onnx-graphsurgeon/Makefile",
        "tools/polygraphy-extension-trtexec/Makefile",
        "tools/pytorch-quantization/docs/Makefile",
        "tools/tensorflow-quantization/docs/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "largest_source_bytes": 3041274,
      "source_files_sampled": 1073,
      "oversized_source_files": 199,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "python/requirements.txt"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "nltk",
            "direct": false,
            "version": "3.9.1",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 10,
            "advisory_ids": [
              "GHSA-469j-vmhf-r6v7",
              "GHSA-68j8-pq59-fqgm",
              "GHSA-7p94-766c-hgjp",
              "GHSA-gfwx-w7gr-fvh7",
              "GHSA-h8wq-7xc4-p3qx",
              "GHSA-jm6w-m3j8-898g",
              "GHSA-p4gq-832x-fm9v",
              "GHSA-rf74-v2fm-23pw",
              "PYSEC-2026-2078",
              "PYSEC-2026-2085"
            ],
            "fixed_version": "3.10.0",
            "advisory_count": 18,
            "oldest_advisory_days": 152
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.13.1",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-3r9x-f23j-gc73",
              "GHSA-538c-55jv-c5g9",
              "GHSA-6rq9-53c3-f7vj",
              "GHSA-cmw6-hcpp-c6jp",
              "GHSA-h36j-8vv3-cj52",
              "GHSA-h8wv-9h96-m4hr",
              "GHSA-hqmj-h5c6-369m",
              "GHSA-hwpq-hmq9-wj77",
              "GHSA-p433-9wv8-28xj",
              "GHSA-q56x-g2fj-4rj6"
            ],
            "fixed_version": "1.22.0",
            "advisory_count": 21,
            "oldest_advisory_days": 878
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.14.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-3r9x-f23j-gc73",
              "GHSA-538c-55jv-c5g9",
              "GHSA-6rq9-53c3-f7vj",
              "GHSA-cmw6-hcpp-c6jp",
              "GHSA-h36j-8vv3-cj52",
              "GHSA-h8wv-9h96-m4hr",
              "GHSA-hqmj-h5c6-369m",
              "GHSA-hwpq-hmq9-wj77",
              "GHSA-p433-9wv8-28xj",
              "GHSA-q56x-g2fj-4rj6"
            ],
            "fixed_version": "1.22.0",
            "advisory_count": 21,
            "oldest_advisory_days": 878
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.17.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-3r9x-f23j-gc73",
              "GHSA-538c-55jv-c5g9",
              "GHSA-cmw6-hcpp-c6jp",
              "GHSA-hqmj-h5c6-369m",
              "GHSA-hwpq-hmq9-wj77",
              "GHSA-p433-9wv8-28xj",
              "GHSA-q56x-g2fj-4rj6",
              "PYSEC-2025-148",
              "PYSEC-2026-103",
              "PYSEC-2026-104"
            ],
            "fixed_version": "1.22.0",
            "advisory_count": 14,
            "oldest_advisory_days": 363
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.18.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-3r9x-f23j-gc73",
              "GHSA-538c-55jv-c5g9",
              "GHSA-cmw6-hcpp-c6jp",
              "GHSA-hqmj-h5c6-369m",
              "GHSA-hwpq-hmq9-wj77",
              "GHSA-p433-9wv8-28xj",
              "GHSA-q56x-g2fj-4rj6",
              "PYSEC-2026-103",
              "PYSEC-2026-104",
              "PYSEC-2026-2239"
            ],
            "fixed_version": "1.22.0",
            "advisory_count": 13,
            "oldest_advisory_days": 126
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.20.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-3r9x-f23j-gc73",
              "GHSA-538c-55jv-c5g9",
              "GHSA-cmw6-hcpp-c6jp",
              "GHSA-hqmj-h5c6-369m",
              "GHSA-hwpq-hmq9-wj77",
              "GHSA-p433-9wv8-28xj",
              "GHSA-q56x-g2fj-4rj6",
              "PYSEC-2026-103",
              "PYSEC-2026-104",
              "PYSEC-2026-2239"
            ],
            "fixed_version": "1.22.0",
            "advisory_count": 13,
            "oldest_advisory_days": 126
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.9.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-3r9x-f23j-gc73",
              "GHSA-538c-55jv-c5g9",
              "GHSA-6rq9-53c3-f7vj",
              "GHSA-cmw6-hcpp-c6jp",
              "GHSA-ffxj-547x-5j7c",
              "GHSA-h36j-8vv3-cj52",
              "GHSA-h8wv-9h96-m4hr",
              "GHSA-hqmj-h5c6-369m",
              "GHSA-hwpq-hmq9-wj77",
              "GHSA-p433-9wv8-28xj"
            ],
            "fixed_version": "1.22.0",
            "advisory_count": 23,
            "oldest_advisory_days": 1271
          },
          {
            "name": "pillow",
            "direct": false,
            "version": "11.3.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-45hq-cxwh-f6vc",
              "GHSA-4x4j-2g7c-83w6",
              "GHSA-5x94-69rx-g8h2",
              "GHSA-5xmw-vc9v-4wf2",
              "GHSA-62p4-gmf7-7g93",
              "GHSA-6r8x-57c9-28j4",
              "GHSA-8v84-f9pq-wr9x",
              "GHSA-9hw9-ch79-4vh6",
              "GHSA-cfh3-3jmp-rvhc",
              "GHSA-fj7v-r99m-22gq"
            ],
            "fixed_version": "12.3.0",
            "advisory_count": 31,
            "oldest_advisory_days": 159
          },
          {
            "name": "diffusers",
            "direct": false,
            "version": "0.35.2",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-7wx4-6vff-v64p",
              "GHSA-98h9-4798-4q5v",
              "PYSEC-2026-2446",
              "PYSEC-2026-40",
              "PYSEC-2026-41"
            ],
            "fixed_version": "0.38.0",
            "advisory_count": 5,
            "oldest_advisory_days": 74
          },
          {
            "name": "opencv-python-headless",
            "direct": false,
            "version": "4.8.0.74",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-jh2j-j4j9-crg3",
              "PYSEC-2023-184"
            ],
            "fixed_version": "4.8.1.78",
            "advisory_count": 2,
            "oldest_advisory_days": 1025
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": "3.20.2",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-7gcm-g887-7qv7",
              "GHSA-8qvm-5x2c-j2w7",
              "PYSEC-2026-1805",
              "PYSEC-2026-1806"
            ],
            "fixed_version": "6.33.5",
            "advisory_count": 4,
            "oldest_advisory_days": 399
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": "3.20.3",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-7gcm-g887-7qv7",
              "GHSA-8qvm-5x2c-j2w7",
              "PYSEC-2026-1805",
              "PYSEC-2026-1806"
            ],
            "fixed_version": "6.33.5",
            "advisory_count": 4,
            "oldest_advisory_days": 399
          },
          {
            "name": "sentencepiece",
            "direct": false,
            "version": "0.1.95",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-38vq-g6vr-w8wf",
              "PYSEC-2026-1909"
            ],
            "fixed_version": "0.2.1",
            "advisory_count": 2,
            "oldest_advisory_days": 179
          },
          {
            "name": "sentencepiece",
            "direct": false,
            "version": "0.1.97",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-38vq-g6vr-w8wf",
              "PYSEC-2026-1909"
            ],
            "fixed_version": "0.2.1",
            "advisory_count": 2,
            "oldest_advisory_days": 179
          },
          {
            "name": "tensorflow-gpu",
            "direct": false,
            "version": "2.8.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.8,
            "advisory_ids": [
              "GHSA-2475-53vw-vp25",
              "GHSA-27rc-728f-x5w2",
              "GHSA-2p9q-h29j-3f5v",
              "GHSA-2r2f-g8mw-9gvr",
              "GHSA-2vv3-56qg-g2cf",
              "GHSA-368v-7v32-52fx",
              "GHSA-37jf-mjv6-xfqw",
              "GHSA-397c-5g2j-qxpv",
              "GHSA-49rq-hwc3-x77w",
              "GHSA-4pc4-m9mj-v2r9"
            ],
            "fixed_version": "2.11.1",
            "advisory_count": 247,
            "oldest_advisory_days": 1518
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.25.1",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.1,
            "advisory_ids": [
              "GHSA-9hjg-9r4m-mvj7",
              "GHSA-9wx4-h78v-vm56",
              "GHSA-gc5v-m9x4-r6x2",
              "GHSA-j8r2-6x86-q33q",
              "PYSEC-2023-74",
              "PYSEC-2026-1872",
              "PYSEC-2026-1873",
              "PYSEC-2026-2275"
            ],
            "fixed_version": "2.33.0",
            "advisory_count": 8,
            "oldest_advisory_days": 1155
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.32.4",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.5,
            "advisory_ids": [
              "GHSA-gc5v-m9x4-r6x2",
              "PYSEC-2026-2275"
            ],
            "fixed_version": "2.33.0",
            "advisory_count": 2,
            "oldest_advisory_days": 117
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.10",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3749-ghw9-m3mg",
              "GHSA-47fc-vmwq-366v",
              "GHSA-53q9-r3pm-6pq6",
              "GHSA-5pcm-hx3q-hm94",
              "GHSA-887c-mr87-cxwp",
              "GHSA-c678-jfcj-6jmf",
              "GHSA-f4hp-rmr7-r7v8",
              "GHSA-pg7h-5qx3-wjr3",
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47"
            ],
            "fixed_version": null,
            "advisory_count": 30,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.10.2",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3749-ghw9-m3mg",
              "GHSA-47fc-vmwq-366v",
              "GHSA-53q9-r3pm-6pq6",
              "GHSA-5pcm-hx3q-hm94",
              "GHSA-887c-mr87-cxwp",
              "GHSA-c678-jfcj-6jmf",
              "GHSA-f4hp-rmr7-r7v8",
              "GHSA-pg7h-5qx3-wjr3",
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47"
            ],
            "fixed_version": null,
            "advisory_count": 30,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.10.2+cu113",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3749-ghw9-m3mg",
              "GHSA-47fc-vmwq-366v",
              "GHSA-53q9-r3pm-6pq6",
              "GHSA-5pcm-hx3q-hm94",
              "GHSA-887c-mr87-cxwp",
              "GHSA-c678-jfcj-6jmf",
              "GHSA-f4hp-rmr7-r7v8",
              "GHSA-pg7h-5qx3-wjr3",
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47"
            ],
            "fixed_version": null,
            "advisory_count": 30,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.11.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3749-ghw9-m3mg",
              "GHSA-47fc-vmwq-366v",
              "GHSA-53q9-r3pm-6pq6",
              "GHSA-5pcm-hx3q-hm94",
              "GHSA-887c-mr87-cxwp",
              "GHSA-c678-jfcj-6jmf",
              "GHSA-f4hp-rmr7-r7v8",
              "GHSA-pg7h-5qx3-wjr3",
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47"
            ],
            "fixed_version": null,
            "advisory_count": 30,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.11.0+cu113",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3749-ghw9-m3mg",
              "GHSA-47fc-vmwq-366v",
              "GHSA-53q9-r3pm-6pq6",
              "GHSA-5pcm-hx3q-hm94",
              "GHSA-887c-mr87-cxwp",
              "GHSA-c678-jfcj-6jmf",
              "GHSA-f4hp-rmr7-r7v8",
              "GHSA-pg7h-5qx3-wjr3",
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47"
            ],
            "fixed_version": null,
            "advisory_count": 30,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.13.1",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3749-ghw9-m3mg",
              "GHSA-53q9-r3pm-6pq6",
              "GHSA-5pcm-hx3q-hm94",
              "GHSA-887c-mr87-cxwp",
              "GHSA-c678-jfcj-6jmf",
              "GHSA-f4hp-rmr7-r7v8",
              "GHSA-pg7h-5qx3-wjr3",
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47",
              "GHSA-vgrw-7cvw-pwgx"
            ],
            "fixed_version": null,
            "advisory_count": 28,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.8.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47",
              "GHSA-vgrw-7cvw-pwgx",
              "PYSEC-2025-203",
              "PYSEC-2025-204",
              "PYSEC-2025-206",
              "PYSEC-2026-139",
              "PYSEC-2026-2286"
            ],
            "fixed_version": null,
            "advisory_count": 8,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.9.1",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47",
              "PYSEC-2026-139",
              "PYSEC-2026-2286"
            ],
            "fixed_version": null,
            "advisory_count": 4,
            "oldest_advisory_days": null
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.18.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-282v-666c-3fvg",
              "GHSA-29pf-2h5f-8g72",
              "GHSA-37mw-44qp-f5jm",
              "GHSA-37q5-v5qm-c9v8",
              "GHSA-3863-2447-669p",
              "GHSA-4w7r-h757-3r74",
              "GHSA-59p9-h35m-wg4g",
              "GHSA-69w3-r845-3855",
              "GHSA-6rvg-6v2m-4j46",
              "GHSA-9356-575x-2w9m"
            ],
            "fixed_version": null,
            "advisory_count": 50,
            "oldest_advisory_days": null
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.20.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-282v-666c-3fvg",
              "GHSA-29pf-2h5f-8g72",
              "GHSA-37mw-44qp-f5jm",
              "GHSA-37q5-v5qm-c9v8",
              "GHSA-3863-2447-669p",
              "GHSA-4w7r-h757-3r74",
              "GHSA-59p9-h35m-wg4g",
              "GHSA-69w3-r845-3855",
              "GHSA-6rvg-6v2m-4j46",
              "GHSA-9356-575x-2w9m"
            ],
            "fixed_version": null,
            "advisory_count": 50,
            "oldest_advisory_days": null
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.52.4",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-29pf-2h5f-8g72",
              "GHSA-4w7r-h757-3r74",
              "GHSA-59p9-h35m-wg4g",
              "GHSA-69w3-r845-3855",
              "GHSA-9356-575x-2w9m",
              "GHSA-fgcw-684q-jj6r",
              "GHSA-rcv9-qm8p-9p6j",
              "PYSEC-2025-211",
              "PYSEC-2025-212",
              "PYSEC-2025-213"
            ],
            "fixed_version": null,
            "advisory_count": 22,
            "oldest_advisory_days": null
          },
          {
            "name": "wheel",
            "direct": false,
            "version": "0.45.1",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-8rrh-rw8j-w5fx",
              "PYSEC-2026-2047"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": null
          }
        ],
        "collected": true,
        "truncated": false,
        "by_severity": {
          "high": 7,
          "unknown": 12,
          "critical": 8,
          "moderate": 2
        },
        "advisory_count": 744,
        "affected_count": 29,
        "assessed_count": 75,
        "assessed_package": null,
        "unassessed_count": 50,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "absl-py",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "accelerate",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "apex",
            "direct": false,
            "version": "0.9.10dev",
            "ecosystem": "pypi"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "build",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "colored",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "colored",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "pypi"
          },
          {
            "name": "controlnet-aux",
            "direct": false,
            "version": "0.0.6",
            "ecosystem": "pypi"
          },
          {
            "name": "cuda-bindings",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "cuda-python",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "cuda-python",
            "direct": false,
            "version": "12.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "cupy-cuda12x",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "cupy-cuda12x",
            "direct": false,
            "version": "13.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "diffusers",
            "direct": false,
            "version": "0.35.2",
            "ecosystem": "pypi"
          },
          {
            "name": "docutils",
            "direct": false,
            "version": "0.16",
            "ecosystem": "pypi"
          },
          {
            "name": "docutils",
            "direct": false,
            "version": "0.18.1",
            "ecosystem": "pypi"
          },
          {
            "name": "ftfy",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "furo",
            "direct": false,
            "version": "2024.8.6",
            "ecosystem": "pypi"
          },
          {
            "name": "gcloud",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "google-cloud-storage",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "huggingface-hub",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "pypi"
          },
          {
            "name": "huggingface-hub",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "imageio-ffmpeg",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "matplotlib",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "ml-dtypes",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "mpi4py",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "myst-parser",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "nccl4py",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "nltk",
            "direct": false,
            "version": "3.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "numba",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "numba-cuda",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "numpy",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "numpy",
            "direct": false,
            "version": "1.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "numpy",
            "direct": false,
            "version": "1.23.1",
            "ecosystem": "pypi"
          },
          {
            "name": "numpy",
            "direct": false,
            "version": "1.26.4",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cutlass-dsl",
            "direct": false,
            "version": "4.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-modelopt",
            "direct": false,
            "version": "0.31.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-modelopt",
            "direct": false,
            "version": "0.35.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-pyindex",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-tensorrt",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "nvtx",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "onnx",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.13.1",
            "ecosystem": "pypi"
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.18.0",
            "ecosystem": "pypi"
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "onnx",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "onnx-graphsurgeon",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "onnx-graphsurgeon",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxconverter-common",
            "direct": false,
            "version": "1.12.2",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxmltools",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxruntime",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "onnxruntime",
            "direct": false,
            "version": "1.12.1",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxruntime",
            "direct": false,
            "version": "1.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxruntime",
            "direct": false,
            "version": "1.18.1",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxruntime",
            "direct": false,
            "version": "1.19.2",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxruntime",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "pypi"
          },
          {
            "name": "onnxruntime-gpu",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "onnxscript",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "onnxscript",
            "direct": false,
            "version": "0.5.4",
            "ecosystem": "pypi"
          },
          {
            "name": "opencv-python-headless",
            "direct": false,
            "version": "4.8.0.74",
            "ecosystem": "pypi"
          },
          {
            "name": "peft",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pillow",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pillow",
            "direct": false,
            "version": "11.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "polygraphy",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "polygraphy",
            "direct": false,
            "version": "0.49.0",
            "ecosystem": "pypi"
          },
          {
            "name": "polygraphy",
            "direct": false,
            "version": "0.49.22",
            "ecosystem": "pypi"
          },
          {
            "name": "polygraphy",
            "direct": false,
            "version": "0.50.1",
            "ecosystem": "pypi"
          },
          {
            "name": "prettytable",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": "3.20.2",
            "ecosystem": "pypi"
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": "3.20.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pycuda",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-console-scripts",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-rerunfailures",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-virtualenv",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-xdist",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pywin32",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.25.1",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.32.4",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.33.0",
            "ecosystem": "pypi"
          },
          {
            "name": "scipy",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "sentencepiece",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "sentencepiece",
            "direct": false,
            "version": "0.1.95",
            "ecosystem": "pypi"
          },
          {
            "name": "sentencepiece",
            "direct": false,
            "version": "0.1.97",
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "sphinx",
            "direct": false,
            "version": "7.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "sphinx-glpi-theme",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "sympy",
            "direct": false,
            "version": "1.9",
            "ecosystem": "pypi"
          },
          {
            "name": "tabulate",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "tensorflow",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "tensorflow-gpu",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tensorrt",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "tf2onnx",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "tf2onnx",
            "direct": false,
            "version": "1.10.1",
            "ecosystem": "pypi"
          },
          {
            "name": "toml",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "tomli",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.10",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.10.2",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.10.2+cu113",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.11.0",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.11.0+cu113",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "1.13.1",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "torchvision",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "torchvision",
            "direct": false,
            "version": "0.11.3",
            "ecosystem": "pypi"
          },
          {
            "name": "torchvision",
            "direct": false,
            "version": "0.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tqdm",
            "direct": false,
            "version": "4.66.4",
            "ecosystem": "pypi"
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.18.0",
            "ecosystem": "pypi"
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.52.4",
            "ecosystem": "pypi"
          },
          {
            "name": "triton",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "triton",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "triton",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "virtualenv",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "wget",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "wget",
            "direct": false,
            "version": "3.2",
            "ecosystem": "pypi"
          },
          {
            "name": "wheel",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "wheel",
            "direct": false,
            "version": "0.45.1",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 125,
        "direct_count": 0,
        "indirect_count": 125
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 54,
        "merged_prs": 323,
        "open_issues": 560,
        "closed_ratio": 0.867,
        "closed_issues": 3657,
        "closed_unmerged_prs": 169
      },
      "bus_factor": 3,
      "top_contributors": [
        {
          "type": "User",
          "login": "rajeevsrao",
          "commits": 198,
          "avatar_url": "https://avatars.githubusercontent.com/u/1845387?v=4"
        },
        {
          "type": "User",
          "login": "kevinch-nv",
          "commits": 73,
          "avatar_url": "https://avatars.githubusercontent.com/u/45886021?v=4"
        },
        {
          "type": "User",
          "login": "shuyuelan",
          "commits": 29,
          "avatar_url": "https://avatars.githubusercontent.com/u/103954203?v=4"
        },
        {
          "type": "User",
          "login": "ttyio",
          "commits": 25,
          "avatar_url": "https://avatars.githubusercontent.com/u/365590?v=4"
        },
        {
          "type": "User",
          "login": "pranavm-nvidia",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/49246958?v=4"
        },
        {
          "type": "User",
          "login": "samurdhikaru",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/97725867?v=4"
        },
        {
          "type": "User",
          "login": "ilyasher",
          "commits": 19,
          "avatar_url": "https://avatars.githubusercontent.com/u/46343317?v=4"
        },
        {
          "type": "User",
          "login": "asfiyab-nvidia",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/117682710?v=4"
        },
        {
          "type": "User",
          "login": "nvpohanh",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/53919306?v=4"
        },
        {
          "type": "User",
          "login": "yuanyao-nv",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/99693700?v=4"
        }
      ],
      "contributors_sampled": 83,
      "top_contributor_share": 0.334
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "blossom-ci.yml",
        "docker-image.yml",
        "feedback-update.yml",
        "label_issue.yml",
        "stale.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".pylintrc"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": null,
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/NVIDIA/TensorRT",
    "host": "github.com",
    "name": "TensorRT",
    "owner": "NVIDIA"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 70,
      "inputs": {
        "security": 21,
        "vitality": 76,
        "community": 88,
        "governance": 81,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 25,
              "human_commit_share": null,
              "days_since_last_push": 13,
              "active_weeks_last_year": 18
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 13 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "18/52 weeks with commits",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 18
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "25 commits in the last year",
                "points": 12.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "releases_count": 70,
              "latest_release_tag": "v11.1",
              "releases_from_tags": false,
              "days_since_latest_release": 26,
              "mean_days_between_releases": 44.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "70 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 70
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 26 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 26
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~44.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 44.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "no_commit_sample",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "excellent",
        "name": "Community & Adoption",
        "value": 88,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "excellent",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "forks": 2389,
              "stars": 13169,
              "watchers": 157,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "13,169 stars",
                "points": 60,
                "status": "met",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 13169
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2,389 forks",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2389
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "157 watchers",
                "points": 12.2,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 157
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "excellent",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 99,
            "inputs": {
              "packages": [
                "polygraphy",
                "onnx_graphsurgeon",
                "polygraphy_trtexec"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 930723
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "930,723 downloads/month across pypi",
                "points": 79.6,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 930723,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 81,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 83,
              "top_contributor_share": 0.334
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 33% of commits",
                "points": 15,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 33
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "83 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 83
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "merged_prs": 323,
              "open_issues": 560,
              "closed_issues": 3657,
              "issue_closed_ratio": 0.867,
              "closed_unmerged_prs": 169
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "87% of issues closed",
                "points": 40.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 87
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "323/492 decided PRs merged",
                "points": 25.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 323,
                      "decided": 492
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "followers": 28173,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "NVIDIA",
              "public_repos": 769,
              "account_age_days": 5184
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "28,173 followers of NVIDIA",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 28173,
                      "login": "NVIDIA"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "769 public repos, account ~14 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 769
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "polygraphy",
                "onnx_graphsurgeon",
                "polygraphy_trtexec"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 54
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "3 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 3,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 54 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 54
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".pylintrc",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".pylintrc"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "tensorrt",
                "nvidia",
                "deep-learning",
                "inference",
                "gpu-acceleration"
              ],
              "has_wiki": false,
              "homepage": "https://developer.nvidia.com/tensorrt",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://developer.nvidia.com/tensorrt",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "5 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 21,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Dependency lockfiles. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "dependency_lockfiles"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "source": "file_signals",
              "lockfiles": [],
              "manifests": [
                "python/requirements.txt"
              ],
              "has_codeql_workflow": false,
              "has_security_policy": false,
              "has_dependabot_config": false
            },
            "components": [
              {
                "key": "security_policy_security_md",
                "name": "Security policy (SECURITY.md)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "dependabot_config",
                "name": "Dependabot config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "dependency_lockfiles",
                "name": "Dependency lockfiles",
                "detail": "published library — lockfiles are an application concern, not expected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "lockfiles_not_expected",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "codeql_workflow",
                "name": "CodeQL workflow",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 75 resolved dependencies against OSV; 50 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 75
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 50
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 744,
              "affected_packages": 29,
              "assessed_packages": 75,
              "unassessed_packages": 50,
              "affected_by_severity": "critical 8, high 7, moderate 2, unknown 12",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 75,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 6
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 54,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": "Excluded from scoring (no data or not applicable): Legible commit history. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "legible_commit_history"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": null,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): Demonstrated agent practice, Automated maintenance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "demonstrated_agent_practice",
                    "automated_maintenance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 86,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "quickstart/Makefile",
                "quickstart/SemanticSegmentation/Makefile",
                "tools/Polygraphy/Makefile",
                "tools/onnx-graphsurgeon/Makefile",
                "tools/polygraphy-extension-trtexec/Makefile",
                "tools/pytorch-quantization/docs/Makefile",
                "tools/tensorflow-quantization/docs/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": null,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": null
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "quickstart/Makefile, quickstart/SemanticSegmentation/Makefile, tools/Polygraphy/Makefile, tools/onnx-graphsurgeon/Makefile, tools/polygraphy-extension-trtexec/Makefile, tools/pytorch-quantization/docs/Makefile, tools/tensorflow-quantization/docs/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "quickstart/Makefile, quickstart/SemanticSegmentation/Makefile, tools/Polygraphy/Makefile, tools/onnx-graphsurgeon/Makefile, tools/polygraphy-extension-trtexec/Makefile, tools/pytorch-quantization/docs/Makefile, tools/tensorflow-quantization/docs/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".pylintrc",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".pylintrc"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "C++ (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "C++"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "primary_language": "C++",
              "largest_source_bytes": 3041274,
              "source_files_sampled": 1073,
              "oversized_source_files": 199
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "C++ (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "C++"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "199/1073 source files over 60KB",
                "points": 44.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1073,
                      "oversized": 199
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples",
                "notebooks",
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, notebooks, samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, notebooks, samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "pypi package 'pytorch_quantization' points at a different repository (https://github.com/NVIDIA); excluded from ecosystem scoring",
    "Could not fetch pypi package 'tensorflow_quantization' from its registry",
    "Advisory severity resolved for 120 of 422 advisories (lookup cap); the remainder are reported as unknown severity",
    "OpenSSF Scorecard did not return a usable result (2026/07/21 04:41:52 Warning: PATs stored in env variables GITHUB_AUTH_TOKEN and GITHUB_TOKEN differ. Scorecard will use the former.); skipping Scorecard checks"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T04:42:50.437293Z",
  "schema_version": "0.17.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/NVIDIA/TensorRT.svg",
  "full_name": "NVIDIA/TensorRT",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.17.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsPyPI.