Public recordSoftware health report schema 0.11.0 · metrics 2.10.0 · 2026-07-16 18:10 UTC
Engine-agnostic LLM gateway in Rust. Full OpenAI & Anthropic API compatibility across vLLM, TRT-LLM, TokenSpeed, SGLang, OpenAI, Gemini & more. Industry-first gRPC pipeline, KV cache-aware routing, chat history, tokenization caching, Responses API, embeddings, WASM plugins, MCP, and multi-tenant auth.
Add score badge to README Compare to…
Rust · Python Apache-2.0 ★ 398 stars ⑂ 118 forks since Nov 2025 View on GitHub ↗ lightseekorg/smg holds a health index of 92 out of 100, placing it in the Excellent band. It scores highest on Vitality (100/100) and lowest on Security (57/100). It was last updated today. 2 contributors account for most of its recent work.
Software health index Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.
92
Exceptional 93-100 The record's top tier (≈ top 5%); essentially all checked criteria met
Excellent 80-92 Strong across the board; minor gaps
Good 65-79 Healthy; gaps are limited and manageable
Moderate 50-64 Acceptable with notable gaps; review recommended
Weak 35-49 Material weaknesses across several areas
At Risk 20-34 Significant weaknesses; adoption warrants caution
Critical 1-19 Severe problems (abandoned, single-maintainer, no hygiene)
Vitality Community & Adoption Sustainability & Governance Engineering Quality Security AI Readiness Score profile Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.
The weighted overall 78 is calibrated to 92 on the published index scale (record calibration 2026-08-02).
Ownership 168 followers 7 public repos since Oct 2025
This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.
Package ecosystems
Metrics by category Is the project alive — is code being written and are releases shipping?
100 Exceptional · 21% of overall
How it's scored 36/36 Push recency — last push 0 days ago 36/36 Commit cadence — 52/52 weeks with commits 18/18 Commit volume — 1,935 commits in the last year 10/10 OpenSSF Scorecard: Maintained — 30 commit(s) and 16 issue activity found in the last 90 days -- score normalized to 10
Inputs used
How it's scored 27/27 Ships releases — 12 releases published 36/36 Release recency — latest release 16 days ago 27/27 Release cadence — a release every ~12.4 days 0/10 OpenSSF Scorecard: Signed-Releases — no data
Inputs used Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.
Does the project have users, downloads, attention, and a welcoming setup for contributors?
63 Moderate · 17% of overall
How it's scored 42.2/60 Stars — 398 stars 17.2/25 Forks — 118 forks 0/15 Watchers — 1 watchers
Inputs used
How it's scored 22.5/22.5 README 22.5/22.5 License — recognized license (Apache-2.0) 18/18 CONTRIBUTING guide 13.5/13.5 Code of conduct 0/7.2 Issue template 6.3/6.3 PR template
Inputs used
How it's scored 21.4/80 Monthly downloads — 39 downloads/month across crates, pypi 0/20 Registry dependents — not reported by this ecosystem
Inputs used Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.
Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?
75 Good · 23% of overall
How it's scored 25.2/54 Bus factor — 2 contributor(s) cover half of all commits 11.9/22.5 Commit distribution — top contributor authored 47% of commits 13.5/13.5 Contributor breadth — 100 contributors 10/10 OpenSSF Scorecard: Contributors — project has 14 contributing companies or organizations
Inputs used
How it's scored 33.6/42 Issue resolution — 80% of issues closed 22.5/30 PR acceptance — 1,216/1,621 decided PRs merged 0/13 Newcomer PR acceptance — no first-time contributor's PR decided in 30d 13.5/15 OpenSSF Scorecard: Code-Review — Found 25/27 approved changesets -- score normalized to 9
Inputs used Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.
How it's scored 30/30 Ownership backing — organization-owned 0/20 Verified domain — verified-domain status not read for this organization 16/25 Owner reach — 168 followers of lightseekorg 8.1/25 Track record — 7 public repos, account ~0 yr old
Inputs used Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored 25/25 Published & resolvable — 2 package(s) on crates, pypi 35/35 Publish recency — latest publish 17 days ago 20/20 Version history — 15 published versions 20/20 Not deprecated — active, not deprecated or yanked
Inputs used Are baseline engineering and documentation practices in place?
92 Excellent · 19% of overall
How it's scored 24/24 CI workflows — 32 workflow(s) 24/24 Tests present 16/16 Linter config — ruff.toml 9.6/9.6 Pre-commit hooks 0/6.4 .editorconfig 20/20 OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
How it's scored 30/30 README 25/25 Documentation directory 15/15 Documentation / homepage site — https://lightseek.org/smg 10/10 Repository description 10/10 Topics — 17 topics 0/10 Wiki
Inputs used Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?
57 Moderate · 16% of overall
How it's scored 7.5/7.5 Binary-Artifacts — no binaries found in the repo 3/7.5 Branch-Protection — branch protection is not maximal on development and all release branches 2.5/2.5 CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10 0/2.5 CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected 6.8/7.5 Code-Review — Found 25/27 approved changesets -- score normalized to 9 2.5/2.5 Contributors — project has 14 contributing companies or organizations 10/10 Dangerous-Workflow — no dangerous workflow patterns detected 7.5/7.5 Dependency-Update-Tool — update tool detected 0/5 Fuzzing — project is not fuzzed 2.5/2.5 License — license file detected 7.5/7.5 Maintained — 30 commit(s) and 16 issue activity found in the last 90 days -- score normalized to 10 5/5 Packaging — packaging workflow detected 0.5/5 Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1 0/5 SAST — SAST tool is not run on all commits -- score normalized to 0 0/5 Security-Policy — security policy file not detected 0/7.5 Signed-Releases — no data 0/7.5 Token-Permissions — detected GitHub workflow tokens with excessive permissions 0/7.5 Vulnerabilities — 13 existing vulnerabilities detected
Inputs used Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.
How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.
65 Good · 4% of overall
How it's scored 0/45 Agent instructions — no CLAUDE.md / AGENTS.md / editor rules 0/15 Machine-readable docs (llms.txt) 0/40 Legible commit history — no data
Inputs used Excluded from scoring (no data or not applicable): Legible commit history. Remaining weights renormalized.
How it's scored 18/18 One-command bootstrap — Makefile, bindings/golang/Makefile, bindings/golang/examples/oai_server/Makefile 22/22 Automated tests 11/11 Lint / format config — ruff.toml 11/11 Static type checking — mypy.ini 10/10 Reproducible environment — Dockerfile, lockfile 0/10 Demonstrated agent practice — no data 5/8 Automated maintenance — dependency automation configured, none observed in the sampled commits 1/10 OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
Inputs used Excluded from scoring (no data or not applicable): Demonstrated agent practice. Remaining weights renormalized.
How it's scored 45/45 Type-checkable code — Rust (statically typed) 53.4/55 Manageable file sizes — 27/928 source files over 60KB
Inputs used
How it's scored 40/40 API schema (OpenAPI/GraphQL/proto) — crates/grpc_client/proto/common.proto, crates/grpc_client/proto/mlx_engine.proto, crates/grpc_client/proto/sglang_encoder.proto, crates/grpc_client/proto/sglang_scheduler.proto, crates/grpc_client/proto/tokenspeed_encoder.proto, crates/grpc_client/proto/tokenspeed_scheduler.proto, crates/grpc_client/proto/trtllm_service.proto, crates/grpc_client/proto/vllm_engine.proto, crates/mesh/src/proto/gossip.proto 20/20 MCP server 40/40 Runnable examples — examples
Inputs used
Key facts 398 GitHub stars
100 contributors
1,935 commits, last 12 months
0 days since last push
12 releases
2 bus factor
56 open issues
crates.io, PyPI package ecosystems
Data collection warnings Could not fetch pypi package 'smg-e2e-tests' from its registry
More detail OpenSSF Scorecard 5.7 / 10 5.7 aggregate
Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard . Each check rewards a security practice , not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero). Scorecard v5.5.0 · 2026-07-16 18:09 UTC
Direct dependencies 109 Registry Package Version constraint Manifest PyPI anthropic —e2e_test/pyproject.toml PyPI datasets —e2e_test/pyproject.toml PyPI grpcio —e2e_test/pyproject.toml PyPI grpcio-health-checking —e2e_test/pyproject.toml PyPI httpx —e2e_test/pyproject.toml PyPI jinja2 —e2e_test/pyproject.toml PyPI mcp >=1.2,<2e2e_test/pyproject.toml PyPI numpy —e2e_test/pyproject.toml PyPI openai —e2e_test/pyproject.toml PyPI pandas —e2e_test/pyproject.toml PyPI pillow —e2e_test/pyproject.toml PyPI pytest —e2e_test/pyproject.toml PyPI pytest-rerunfailures —e2e_test/pyproject.toml PyPI requests —e2e_test/pyproject.toml PyPI tqdm —e2e_test/pyproject.toml PyPI uvicorn >=0.30e2e_test/pyproject.toml PyPI websockets —e2e_test/pyproject.toml PyPI smg-grpc-proto >=0.4.13grpc_servicer/pyproject.toml PyPI grpcio >=1.81.1grpc_servicer/pyproject.toml PyPI grpcio-reflection >=1.81.1grpc_servicer/pyproject.toml PyPI grpcio-health-checking >=1.81.1grpc_servicer/pyproject.toml crates.io anyhow —model_gateway/Cargo.toml crates.io async-trait —model_gateway/Cargo.toml crates.io blake3 —model_gateway/Cargo.toml crates.io chrono —model_gateway/Cargo.toml crates.io dashmap —model_gateway/Cargo.toml crates.io futures —model_gateway/Cargo.toml crates.io http —model_gateway/Cargo.toml crates.io lru —model_gateway/Cargo.toml crates.io parking_lot —model_gateway/Cargo.toml crates.io prost —model_gateway/Cargo.toml crates.io prost-types —model_gateway/Cargo.toml crates.io rand —model_gateway/Cargo.toml crates.io subtle —model_gateway/Cargo.toml crates.io thiserror —model_gateway/Cargo.toml crates.io tonic —model_gateway/Cargo.toml crates.io tonic-prost —model_gateway/Cargo.toml crates.io tracing —model_gateway/Cargo.toml crates.io tracing-subscriber —model_gateway/Cargo.toml crates.io axum —model_gateway/Cargo.toml crates.io bytemuck —model_gateway/Cargo.toml crates.io reqwest —model_gateway/Cargo.toml crates.io serde —model_gateway/Cargo.toml crates.io tokio —model_gateway/Cargo.toml crates.io tokio-util —model_gateway/Cargo.toml crates.io uuid —model_gateway/Cargo.toml crates.io openai-protocol —model_gateway/Cargo.toml crates.io reasoning-parser —model_gateway/Cargo.toml crates.io tool-parser —model_gateway/Cargo.toml crates.io wfaas —model_gateway/Cargo.toml crates.io llm-tokenizer —model_gateway/Cargo.toml crates.io smg-auth —model_gateway/Cargo.toml crates.io smg-mcp —model_gateway/Cargo.toml crates.io kv-index —model_gateway/Cargo.toml crates.io smg-data-connector —model_gateway/Cargo.toml crates.io llm-multimodal —model_gateway/Cargo.toml crates.io smg-mm-rdma —model_gateway/Cargo.toml crates.io smg-wasm —model_gateway/Cargo.toml crates.io smg-mesh —model_gateway/Cargo.toml crates.io smg-grpc-client —model_gateway/Cargo.toml crates.io bincode 1.3model_gateway/Cargo.toml crates.io clap 4model_gateway/Cargo.toml crates.io axum-server 0.8.0model_gateway/Cargo.toml crates.io ndarray 0.17model_gateway/Cargo.toml crates.io memmap2 0.9model_gateway/Cargo.toml crates.io rayon 1.12model_gateway/Cargo.toml crates.io rustix 1model_gateway/Cargo.toml crates.io tower 0.5model_gateway/Cargo.toml crates.io tower-http 0.7model_gateway/Cargo.toml crates.io serde_json 1.0model_gateway/Cargo.toml crates.io bytes 1.12.0model_gateway/Cargo.toml crates.io http-body 1.0model_gateway/Cargo.toml crates.io http-body-util 0.1model_gateway/Cargo.toml crates.io futures-util 0.3model_gateway/Cargo.toml crates.io xxhash-rust 0.8model_gateway/Cargo.toml crates.io tracing-log 0.2model_gateway/Cargo.toml crates.io tracing-appender 0.2.5model_gateway/Cargo.toml crates.io opentelemetry 0.32model_gateway/Cargo.toml crates.io opentelemetry_sdk 0.32model_gateway/Cargo.toml crates.io opentelemetry-otlp 0.32model_gateway/Cargo.toml crates.io tracing-opentelemetry 0.33model_gateway/Cargo.toml crates.io kube 3.0.1model_gateway/Cargo.toml crates.io k8s-openapi 0.27.0model_gateway/Cargo.toml crates.io metrics 0.24.6model_gateway/Cargo.toml crates.io metrics-exporter-prometheus 0.18.3model_gateway/Cargo.toml crates.io regex 1.12model_gateway/Cargo.toml crates.io memchr 2.8model_gateway/Cargo.toml crates.io url 2.5.8model_gateway/Cargo.toml crates.io tokio-stream 0.1model_gateway/Cargo.toml crates.io rustls 0.23model_gateway/Cargo.toml crates.io tokio-rustls 0.26model_gateway/Cargo.toml crates.io rustls-pemfile 2.2model_gateway/Cargo.toml crates.io openssl 0.10.81model_gateway/Cargo.toml crates.io rmcp 1.7model_gateway/Cargo.toml crates.io serde_yaml 0.9model_gateway/Cargo.toml crates.io openai-harmony 0.0.8model_gateway/Cargo.toml crates.io openmetrics-parser 0.4.4model_gateway/Cargo.toml crates.io arc-swap 1.9.1model_gateway/Cargo.toml crates.io bitflags —model_gateway/Cargo.toml crates.io once_cell 1.21.4model_gateway/Cargo.toml crates.io sha2 0.11model_gateway/Cargo.toml crates.io base64 0.22model_gateway/Cargo.toml crates.io image 0.25.10model_gateway/Cargo.toml crates.io tokio-tungstenite —model_gateway/Cargo.toml crates.io webpki-roots —model_gateway/Cargo.toml crates.io wasmtime —model_gateway/Cargo.toml crates.io tempfile 3.27model_gateway/Cargo.toml crates.io multer —model_gateway/Cargo.toml crates.io str0m —model_gateway/Cargo.toml
All dependencies 145 Full resolved dependency set from the GitHub dependency graph: 64 direct and 81 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.
Registry Package Version Relation crates.io arc-swap —direct crates.io async-trait —direct crates.io axum-server —direct crates.io base64 —direct crates.io bincode —direct crates.io bytes —direct crates.io chrono —direct crates.io clap —direct crates.io futures —direct crates.io futures-util —direct crates.io http-body —direct crates.io http-body-util —direct crates.io image —direct crates.io k8s-openapi —direct crates.io kube —direct crates.io memchr —direct crates.io memmap2 —direct crates.io metrics —direct crates.io metrics-exporter-prometheus —direct crates.io ndarray —direct crates.io once_cell —direct crates.io openai-harmony —direct crates.io openmetrics-parser —direct crates.io openssl —direct crates.io opentelemetry —direct crates.io opentelemetry-otlp —direct crates.io opentelemetry_sdk —direct crates.io prost —direct crates.io prost-types —direct crates.io rayon —direct crates.io regex —direct crates.io reqwest —direct crates.io rmcp —direct crates.io rustix —direct crates.io rustls —direct crates.io rustls-pemfile —direct crates.io serde —direct crates.io serde_json —direct crates.io serde_yaml —direct crates.io sha2 —direct crates.io tempfile —direct crates.io tokio —direct crates.io tokio-rustls —direct crates.io tokio-stream —direct crates.io tonic —direct crates.io tonic-prost —direct crates.io tower —direct crates.io tower-http —direct crates.io tracing —direct crates.io tracing-appender —direct crates.io tracing-log —direct crates.io tracing-opentelemetry —direct crates.io url —direct crates.io uuid —direct crates.io xxhash-rust —direct PyPI grpcio —direct PyPI grpcio-health-checking —direct PyPI grpcio-reflection —direct PyPI httpx —direct PyPI mcp —direct PyPI pytest —direct PyPI requests —direct PyPI smg-grpc-proto —direct PyPI uvicorn —direct crates.io aho-corasick —indirect crates.io async-channel —indirect crates.io backoff —indirect crates.io cc —indirect crates.io crdts —indirect crates.io criterion —indirect crates.io deadpool —indirect crates.io deadpool-postgres —indirect crates.io deadpool-redis —indirect crates.io fast_image_resize —indirect crates.io hf-hub —indirect crates.io jsonwebtoken —indirect crates.io lazy_static —indirect crates.io libc —indirect crates.io libloading —indirect crates.io minijinja —indirect crates.io minijinja-contrib —indirect crates.io nixl-sys —indirect crates.io npyz —indirect crates.io num-bigint —indirect crates.io opencv —indirect crates.io opentelemetry-proto —indirect crates.io oracle —indirect crates.io pkg-config —indirect crates.io portpicker —indirect crates.io prost-build —indirect crates.io pyo3 —indirect crates.io redis —indirect crates.io rsa —indirect crates.io rustc-hash —indirect crates.io rustfft —indirect crates.io rustpython-parser —indirect crates.io serde_bytes —indirect crates.io serde_yaml_ng —indirect crates.io serial_test —indirect crates.io symphonia —indirect crates.io tiktoken-rs —indirect crates.io tokenizers —indirect crates.io tokio-postgres —indirect crates.io toml —indirect crates.io tonic-prost-build —indirect crates.io tracing-test —indirect crates.io ulid —indirect crates.io unicode-segmentation —indirect crates.io validator —indirect crates.io wasm-encoder —indirect crates.io wat —indirect crates.io wiremock —indirect crates.io wit-bindgen —indirect crates.io zip —indirect Go github.com/andybalholm/brotli v1.1.0indirect Go github.com/klauspost/compress v1.17.9indirect Go github.com/stretchr/testify v1.10.0indirect Go github.com/valyala/bytebufferpool v1.0.0indirect Go github.com/valyala/fasthttp v1.52.0indirect Go go.uber.org/multierr v1.10.0indirect Go go.uber.org/zap v1.27.0indirect Go golang.org/x/net v0.48.0indirect Go golang.org/x/sys v0.39.0indirect Go golang.org/x/text v0.32.0indirect Go google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217indirect Go google.golang.org/grpc v1.79.3indirect Go google.golang.org/protobuf v1.36.10indirect Go google.golang.org/protobuf v1.36.11indirect Go gopkg.in/natefinch/lumberjack.v2 v2.2.1indirect Maven com.fasterxml.jackson.core:jackson-annotations 2.17.1indirect Maven com.fasterxml.jackson.core:jackson-databind 2.17.1indirect Maven com.fasterxml.jackson.datatype:jackson-datatype-jsr310 2.17.1indirect Maven jakarta.annotation:jakarta.annotation-api 2.1.1indirect PyPI grpcio-tools —indirect PyPI maturin —indirect PyPI mlx —indirect PyPI mlx-lm —indirect PyPI msgspec —indirect PyPI protobuf —indirect PyPI pydantic —indirect PyPI pyzmq —indirect PyPI setuptools —indirect PyPI sglang —indirect PyPI transformers —indirect PyPI vllm —indirect
Raw JSON report machine-readable
Feedback Spotted something off in this report, or have thoughts to share? Wrong measurements, missed tooling, ideas, questions — anything is welcome. Every message is read and gets a response.