Pure DI for .NET
DevTeam/Pure.DI має індекс здоров’я 32 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Vitality (95/100), найнижчий — Security (37/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.
Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.
Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.
Політика юрисдикцій високого ризику застосовує множник 50% до зваженого загального індексу здоров’я і встановлює для нього межу «У зоні ризику» на рівні 49.
За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.
Чи живий проєкт — чи пишеться код і чи виходять релізи?
| 36/36 | Свіжість push — останній push 0 дн. тому |
| 27/36 | Ритм комітів — 39/52 тижнів із комітами |
| 18/18 | Обсяг комітів — 512 комітів за останній рік |
| 10/10 | OpenSSF Scorecard: Maintained — 30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10 |
| commits_last_year | 512 |
| human_commit_share | — |
| days_since_last_push | 0 |
| active_weeks_last_year | 39 |
| 27/27 | Випускає релізи — опубліковано 100 релізів |
| 36/36 | Свіжість релізів — останній реліз 4 дн. тому |
| 27/27 | Ритм релізів — реліз кожні ~14 дн. |
| 0/10 | OpenSSF Scorecard: Signed-Releases — немає даних |
| releases_count | 100 |
| latest_release_tag | 2.5.1 |
| releases_from_tags | ні |
| days_since_latest_release | 4 |
| mean_days_between_releases | 14 |
Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?
| 47.3/60 | Зірки — 823 зірок |
| 12.1/25 | Форки — 29 форків |
| 5/15 | Спостерігачі — 9 спостерігачів |
| forks | 29 |
| stars | 823 |
| watchers | 9 |
| growth_state | unverified |
| growth_factor_pct | 100 |
| growth_unverified_reason | no_history |
| 22.5/22.5 | README |
| 22.5/22.5 | Ліцензія — визнана ліцензія (MIT) |
| 18/18 | Настанови CONTRIBUTING |
| 0/13.5 | Кодекс поведінки |
| 0/7.2 | Шаблон issue |
| 0/6.3 | Шаблон PR |
| has_readme | так |
| has_license | так |
| has_contributing | так |
| has_issue_template | ні |
| has_code_of_conduct | ні |
| has_pull_request_template | ні |
Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?
| 9/54 | Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів |
| 0.2/22.5 | Розподіл комітів — головний контриб’ютор — автор 99% комітів |
| 8.1/13.5 | Широта контриб’юторів — 6 контриб’юторів |
| 10/10 | OpenSSF Scorecard: Contributors — project has 4 contributing companies or organizations |
| bus_factor | 1 |
| contributors_sampled | 6 |
| top_contributor_share | 0,99 |
| 44.1/46.8 | Вирішення issue — закрито 94% issue |
| 19.1/38.3 | Прийняття PR — злито 7/14 вирішених PR |
| 0/15 | OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0 |
| merged_prs | 7 |
| open_issues | 6 |
| closed_issues | 101 |
| issue_closed_ratio | 0,944 |
| closed_unmerged_prs | 7 |
| 30/30 | Підтримка власника — у власності організації |
| 0/20 | Верифікований домен |
| 10.3/25 | Охоплення власника — 26 підписників у DevTeam |
| 21.1/25 | Послужний список — 17 публічних репозиторіїв, вік облікового запису ~11 р. |
| followers | 26 |
| owner_type | Organization |
| is_verified | — |
| owner_login | DevTeam |
| public_repos | 17 |
| account_age_days | 4 099 |
Чи наявні базові інженерні практики та документація?
| 24/24 | Процеси CI — 1 процес(ів) CI |
| 24/24 | Наявні тести |
| 0/16 | Конфігурація лінтера |
| 0/9.6 | Pre-commit-хуки |
| 0/6.4 | .editorconfig |
| 0/20 | OpenSSF Scorecard: CI-Tests — немає даних |
| has_ci | так |
| has_tests | так |
| has_editorconfig | ні |
| has_linter_config | ні |
| has_precommit_config | ні |
| 30/30 | README |
| 25/25 | Каталог документації |
| 0/15 | Сайт документації / домашня сторінка |
| 10/10 | Опис репозиторію |
| 10/10 | Теми — 16 тем |
| 10/10 | Wiki |
| topics | ioc, di, dotnet, pure, csharp, source-generator, injection, injection-framework, avalonia, unity, wpf, composition, root, solid, dependency-injection, pure-di |
| has_wiki | так |
| homepage | — |
| has_readme | так |
| has_docs_dir | так |
| has_description | так |
Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?
Сигнал ґрунтується на публічних локаціях, самостійно вказаних у профілях. Він не визначає національність, громадянство, наміри, санкційний статус чи надійність людини.
Як оцінюється юрисдикційна пов’язаність| 0/7.5 | Binary-Artifacts — binaries present in source code |
| 0/7.5 | Branch-Protection — немає даних |
| 0/2.5 | CI-Tests — немає даних |
| 0/2.5 | CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected |
| 0/7.5 | Code-Review — Found 0/30 approved changesets -- score normalized to 0 |
| 2.5/2.5 | Contributors — project has 4 contributing companies or organizations |
| 10/10 | Dangerous-Workflow — no dangerous workflow patterns detected |
| 0/7.5 | Dependency-Update-Tool — no update tool detected |
| 0/5 | Fuzzing — project is not fuzzed |
| 2.5/2.5 | Ліцензія — license file detected |
| 7.5/7.5 | Maintained — 30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10 |
| 0/5 | Packaging — немає даних |
| 0/5 | Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| 0/5 | SAST — no SAST tool detected |
| 5/5 | Security-Policy — security policy file detected |
| 0/7.5 | Signed-Releases — немає даних |
| 0/7.5 | Token-Permissions — detected GitHub workflow tokens with excessive permissions |
| 7.5/7.5 | Vulnerabilities — 0 existing vulnerabilities detected |
| source | openssf_scorecard |
| checks_evaluated | 14 |
| scorecard_version | v5.5.0 |
| checks_inconclusive | 4 |
| scorecard_aggregate | 4,2 |
| high_risk_jurisdiction_cap | 49 |
| high_risk_jurisdiction_multiplier | 50 |
| security_posture_after_multiplier | 21 |
| security_posture_before_jurisdiction | 42 |
| 35/35 | Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень |
| 0/25 | Непрямі залежності без відомих сповіщень — транзитивний набір не відокремлюється від залежностей розробки й тестування в цьому обсязі |
| 0/40 | Немає задавнених сповіщень — жодне сповіщення не має дати публікації |
| source | osv |
| advisories | 0 |
| affected_packages | 0 |
| assessed_packages | 41 |
| unassessed_packages | 4 |
| affected_by_severity | none |
| direct_affected_packages | 0 |
Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.
| 45/45 | Інструкції для агентів — AGENTS.md |
| 0/15 | Машиночитана документація (llms.txt) |
| 0/40 | Читабельна історія комітів — немає даних |
| has_llms_txt | ні |
| legible_history_share | — |
| agent_instruction_files | AGENTS.md |
| agent_instruction_max_bytes | 497 749 |
| 0/18 | Розгортання однією командою |
| 22/22 | Автоматизовані тести |
| 0/11 | Конфігурація лінтера / форматера |
| 11/11 | Статична перевірка типів — C# (статично типізована) |
| 0/10 | Відтворюване середовище |
| 0/10 | Підтверджена практика роботи з агентами — немає даних |
| 0/8 | Автоматизоване супроводження — немає даних |
| 0/10 | OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| has_nix | ні |
| has_tests | так |
| lockfiles | — |
| has_dockerfile | ні |
| typed_language | так |
| bootstrap_files | — |
| has_devcontainer | ні |
| has_linter_config | ні |
| typecheck_configs | — |
| agent_commit_share | — |
| toolchain_manifests | — |
| dependency_bot_commit_share | — |
| 45/45 | Типізований код — C# (статично типізована) |
| 53.4/55 | Керовані розміри файлів — 26/908 файлів вихідного коду понад 60 КБ |
| primary_language | C# |
| largest_source_bytes | 1 028 740 |
| source_files_sampled | 908 |
| oversized_source_files | 26 |
| 40/40 | Схема API (OpenAPI/GraphQL/proto) — samples/GrpcService/Protos/clock.proto |
| 0/20 | Сервер MCP |
| 40/40 | Придатні до запуску приклади — samples |
| example_dirs | samples |
| has_mcp_signal | ні |
| api_schema_files | samples/GrpcService/Protos/clock.proto |
Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).
| 0 | Binary-Artifacts | binaries present in source code |
| н/д | Branch-Protection | internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md |
| н/д | CI-Tests | no pull request found |
| 0 | CII-Best-Practices | no effort to earn an OpenSSF best practices badge detected |
| 0 | Code-Review | Found 0/30 approved changesets -- score normalized to 0 |
| 10 | Contributors | project has 4 contributing companies or organizations |
| 10 | Dangerous-Workflow | no dangerous workflow patterns detected |
| 0 | Dependency-Update-Tool | no update tool detected |
| 0 | Fuzzing | project is not fuzzed |
| 10 | License | license file detected |
| 10 | Maintained | 30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10 |
| н/д | Packaging | packaging workflow not detected |
| 0 | Pinned-Dependencies | dependency not pinned by hash detected -- score normalized to 0 |
| 0 | SAST | no SAST tool detected |
| 10 | Security-Policy | security policy file detected |
| н/д | Signed-Releases | no releases found |
| 0 | Token-Permissions | detected GitHub workflow tokens with excessive permissions |
| 10 | Vulnerabilities | 0 existing vulnerabilities detected |
| Реєстр | Пакет | Обмеження версії | Маніфест |
|---|---|---|---|
| NuGet | CSharpInteractive | 1.2.3 | build/build.csproj |
| NuGet | Pure.DI | $(InternalVersion) | build/build.csproj |
| NuGet | Immutype | 1.0.16 | build/build.csproj |
| NuGet | System.CommandLine | 2.0.10 | build/build.csproj |
Повний розв'язаний набір залежностей із графа залежностей GitHub: 5 прямих і 40 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.
| Реєстр | Пакет | Версія | Зв'язок |
|---|---|---|---|
| NuGet | CSharpInteractive | 1.2.3 | пряма |
| NuGet | Immutype | 1.0.16 | пряма |
| NuGet | Pure.DI | — | пряма |
| NuGet | Pure.DI | 2.5.1 | пряма |
| NuGet | System.CommandLine | 2.0.10 | пряма |
| NuGet | Autofac | 9.3.1 | непряма |
| NuGet | Avalonia | 12.1.0 | непряма |
| NuGet | Avalonia.Desktop | 12.1.0 | непряма |
| NuGet | Avalonia.Fonts.Inter | 12.1.0 | непряма |
| NuGet | Avalonia.Themes.Fluent | 12.1.0 | непряма |
| NuGet | BenchmarkDotNet | 0.15.8 | непряма |
| NuGet | BenchmarkDotNet.Diagnostics.Windows | 0.15.8 | непряма |
| NuGet | Castle.Windsor | 6.0.0 | непряма |
| NuGet | DryIoc.dll | 5.4.3 | непряма |
| NuGet | Grpc.AspNetCore | 2.80.0 | непряма |
| NuGet | IndexRange | 1.1.1 | непряма |
| NuGet | IoC.Container | 1.3.8 | непряма |
| NuGet | LightInject | 7.1.0 | непряма |
| NuGet | Microsoft.AspNetCore.Components.WebAssembly | 10.0.10 | непряма |
| NuGet | Microsoft.AspNetCore.Components.WebAssembly.DevServer | 10.0.10 | непряма |
| NuGet | Microsoft.AspNetCore.OpenApi | 10.0.10 | непряма |
| NuGet | Microsoft.CodeAnalysis.CSharp | — | непряма |
| NuGet | Microsoft.EntityFrameworkCore.InMemory | 10.0.10 | непряма |
| NuGet | Microsoft.Extensions.DependencyInjection | — | непряма |
| NuGet | Microsoft.Extensions.DependencyInjection | 10.0.8 | непряма |
| NuGet | Microsoft.Extensions.Logging.Debug | 9.0.0 | непряма |
| NuGet | Microsoft.Extensions.Logging.Debug | 9.0.4 | непряма |
| NuGet | Microsoft.Maui.Controls | 9.0.21 | непряма |
| NuGet | Microsoft.Maui.Controls | 9.0.60 | непряма |
| NuGet | Microsoft.Maui.Controls.Compatibility | 9.0.60 | непряма |
| NuGet | Microsoft.NET.Test.Sdk | 18.8.1 | непряма |
| NuGet | Microsoft.NETFramework.ReferenceAssemblies.net20 | 1.0.3 | непряма |
| NuGet | Microsoft.NETFramework.ReferenceAssemblies.net35 | 1.0.3 | непряма |
| NuGet | Microsoft.NETFramework.ReferenceAssemblies.net40 | 1.0.3 | непряма |
| NuGet | Microsoft.NETFramework.ReferenceAssemblies.net45 | 1.0.3 | непряма |
| NuGet | Microsoft.NETFramework.ReferenceAssemblies.net48 | 1.0.3 | непряма |
| NuGet | Moq | 4.20.72 | непряма |
| NuGet | Ninject | 3.3.6 | непряма |
| NuGet | Reactor.Maui | — | непряма |
| NuGet | Shouldly | 4.3.0 | непряма |
| NuGet | SimpleInjector | 5.6.0 | непряма |
| NuGet | Swashbuckle.AspNetCore | 10.2.3 | непряма |
| NuGet | Unity | 5.11.10 | непряма |
| NuGet | xunit | 2.9.3 | непряма |
| NuGet | xunit.runner.visualstudio | 3.1.5 | непряма |
Цей репозиторій не публікує пакета, який розпізнає індекс, тож оцінено його власний граф залежностей — 41 пакетів, серед яких є й піниї розробки та тестування, що ніколи не постачаються: 0 мають відомі сповіщення, з них 0 прямі. 4 не вдалося оцінити — немає резолвленої версії, непідтримувана екосистема або поза наведеним переліком пакетів.
Жодне відоме сповіщення не стосується оцінених залежностей.
Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.
{
"data": {
"repo": {
"topics": [
"ioc",
"di",
"dotnet",
"pure",
"csharp",
"source-generator",
"injection",
"injection-framework",
"avalonia",
"unity",
"wpf",
"composition",
"root",
"solid",
"dependency-injection",
"pure-di"
],
"is_fork": false,
"size_kb": 325579,
"has_wiki": true,
"homepage": null,
"languages": {
"C#": 6611931,
"HTML": 15449,
"Shell": 50,
"Kotlin": 205,
"Batchfile": 327
},
"pushed_at": "2026-07-20T16:54:21Z",
"created_at": "2021-03-28T05:36:20Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T06:21:53Z",
"description": "Pure DI for .NET",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "master",
"license_spdx_raw": "MIT",
"primary_language": "C#",
"significant_languages": [
"C#"
]
},
"owner": {
"blog": "https://teamcity.jetbrains.com/project/OpenSourceProjects_DevTeam",
"name": null,
"type": "Organization",
"login": "DevTeam",
"company": null,
"location": null,
"followers": 26,
"avatar_url": "https://avatars.githubusercontent.com/u/12184234?v=4",
"created_at": "2015-04-30T10:13:07Z",
"is_verified": null,
"public_repos": 17,
"account_age_days": 4099
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases_count": 100,
"commits_last_year": 512,
"latest_release_at": "2026-07-16T14:43:17Z",
"latest_release_tag": "2.5.1",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 39,
"days_since_latest_release": 4,
"mean_days_between_releases": 14
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 29,
"stars": 823,
"watchers": 9,
"open_issues_and_prs": 6
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"samples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [
"samples/GrpcService/Protos/clock.proto"
],
"has_devcontainer": false,
"typecheck_configs": [],
"largest_source_bytes": 1028740,
"source_files_sampled": 908,
"oversized_source_files": 26,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 497749
},
"dependencies": {
"manifests": [
"build/build.csproj"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [],
"collected": true,
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 41,
"assessed_package": null,
"unassessed_count": 4,
"direct_affected_count": 0
},
"ecosystems": [
"nuget"
],
"dependencies": [
{
"name": "CSharpInteractive",
"manifest": "build/build.csproj",
"ecosystem": "nuget",
"version_constraint": "1.2.3"
},
{
"name": "Pure.DI",
"manifest": "build/build.csproj",
"ecosystem": "nuget",
"version_constraint": "$(InternalVersion)"
},
{
"name": "Immutype",
"manifest": "build/build.csproj",
"ecosystem": "nuget",
"version_constraint": "1.0.16"
},
{
"name": "System.CommandLine",
"manifest": "build/build.csproj",
"ecosystem": "nuget",
"version_constraint": "2.0.10"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "CSharpInteractive",
"direct": true,
"version": "1.2.3",
"ecosystem": "nuget"
},
{
"name": "Immutype",
"direct": true,
"version": "1.0.16",
"ecosystem": "nuget"
},
{
"name": "Pure.DI",
"direct": true,
"version": null,
"ecosystem": "nuget"
},
{
"name": "Pure.DI",
"direct": true,
"version": "2.5.1",
"ecosystem": "nuget"
},
{
"name": "System.CommandLine",
"direct": true,
"version": "2.0.10",
"ecosystem": "nuget"
},
{
"name": "Autofac",
"direct": false,
"version": "9.3.1",
"ecosystem": "nuget"
},
{
"name": "Avalonia",
"direct": false,
"version": "12.1.0",
"ecosystem": "nuget"
},
{
"name": "Avalonia.Desktop",
"direct": false,
"version": "12.1.0",
"ecosystem": "nuget"
},
{
"name": "Avalonia.Fonts.Inter",
"direct": false,
"version": "12.1.0",
"ecosystem": "nuget"
},
{
"name": "Avalonia.Themes.Fluent",
"direct": false,
"version": "12.1.0",
"ecosystem": "nuget"
},
{
"name": "BenchmarkDotNet",
"direct": false,
"version": "0.15.8",
"ecosystem": "nuget"
},
{
"name": "BenchmarkDotNet.Diagnostics.Windows",
"direct": false,
"version": "0.15.8",
"ecosystem": "nuget"
},
{
"name": "Castle.Windsor",
"direct": false,
"version": "6.0.0",
"ecosystem": "nuget"
},
{
"name": "DryIoc.dll",
"direct": false,
"version": "5.4.3",
"ecosystem": "nuget"
},
{
"name": "Grpc.AspNetCore",
"direct": false,
"version": "2.80.0",
"ecosystem": "nuget"
},
{
"name": "IndexRange",
"direct": false,
"version": "1.1.1",
"ecosystem": "nuget"
},
{
"name": "IoC.Container",
"direct": false,
"version": "1.3.8",
"ecosystem": "nuget"
},
{
"name": "LightInject",
"direct": false,
"version": "7.1.0",
"ecosystem": "nuget"
},
{
"name": "Microsoft.AspNetCore.Components.WebAssembly",
"direct": false,
"version": "10.0.10",
"ecosystem": "nuget"
},
{
"name": "Microsoft.AspNetCore.Components.WebAssembly.DevServer",
"direct": false,
"version": "10.0.10",
"ecosystem": "nuget"
},
{
"name": "Microsoft.AspNetCore.OpenApi",
"direct": false,
"version": "10.0.10",
"ecosystem": "nuget"
},
{
"name": "Microsoft.CodeAnalysis.CSharp",
"direct": false,
"version": null,
"ecosystem": "nuget"
},
{
"name": "Microsoft.EntityFrameworkCore.InMemory",
"direct": false,
"version": "10.0.10",
"ecosystem": "nuget"
},
{
"name": "Microsoft.Extensions.DependencyInjection",
"direct": false,
"version": null,
"ecosystem": "nuget"
},
{
"name": "Microsoft.Extensions.DependencyInjection",
"direct": false,
"version": "10.0.8",
"ecosystem": "nuget"
},
{
"name": "Microsoft.Extensions.Logging.Debug",
"direct": false,
"version": "9.0.0",
"ecosystem": "nuget"
},
{
"name": "Microsoft.Extensions.Logging.Debug",
"direct": false,
"version": "9.0.4",
"ecosystem": "nuget"
},
{
"name": "Microsoft.Maui.Controls",
"direct": false,
"version": "9.0.21",
"ecosystem": "nuget"
},
{
"name": "Microsoft.Maui.Controls",
"direct": false,
"version": "9.0.60",
"ecosystem": "nuget"
},
{
"name": "Microsoft.Maui.Controls.Compatibility",
"direct": false,
"version": "9.0.60",
"ecosystem": "nuget"
},
{
"name": "Microsoft.NET.Test.Sdk",
"direct": false,
"version": "18.8.1",
"ecosystem": "nuget"
},
{
"name": "Microsoft.NETFramework.ReferenceAssemblies.net20",
"direct": false,
"version": "1.0.3",
"ecosystem": "nuget"
},
{
"name": "Microsoft.NETFramework.ReferenceAssemblies.net35",
"direct": false,
"version": "1.0.3",
"ecosystem": "nuget"
},
{
"name": "Microsoft.NETFramework.ReferenceAssemblies.net40",
"direct": false,
"version": "1.0.3",
"ecosystem": "nuget"
},
{
"name": "Microsoft.NETFramework.ReferenceAssemblies.net45",
"direct": false,
"version": "1.0.3",
"ecosystem": "nuget"
},
{
"name": "Microsoft.NETFramework.ReferenceAssemblies.net48",
"direct": false,
"version": "1.0.3",
"ecosystem": "nuget"
},
{
"name": "Moq",
"direct": false,
"version": "4.20.72",
"ecosystem": "nuget"
},
{
"name": "Ninject",
"direct": false,
"version": "3.3.6",
"ecosystem": "nuget"
},
{
"name": "Reactor.Maui",
"direct": false,
"version": null,
"ecosystem": "nuget"
},
{
"name": "Shouldly",
"direct": false,
"version": "4.3.0",
"ecosystem": "nuget"
},
{
"name": "SimpleInjector",
"direct": false,
"version": "5.6.0",
"ecosystem": "nuget"
},
{
"name": "Swashbuckle.AspNetCore",
"direct": false,
"version": "10.2.3",
"ecosystem": "nuget"
},
{
"name": "Unity",
"direct": false,
"version": "5.11.10",
"ecosystem": "nuget"
},
{
"name": "xunit",
"direct": false,
"version": "2.9.3",
"ecosystem": "nuget"
},
{
"name": "xunit.runner.visualstudio",
"direct": false,
"version": "3.1.5",
"ecosystem": "nuget"
}
],
"collected": true,
"truncated": false,
"total_count": 45,
"direct_count": 5,
"indirect_count": 40
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 7,
"open_issues": 6,
"closed_ratio": 0.944,
"closed_issues": 101,
"closed_unmerged_prs": 7
},
"bus_factor": 1,
"top_contributors": [
{
"type": "User",
"login": "NikolayPianikov",
"commits": 1319,
"avatar_url": "https://avatars.githubusercontent.com/u/11720017?v=4"
},
{
"type": "User",
"login": "Serg046",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/4963385?v=4"
},
{
"type": "User",
"login": "adamhathcock",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/527620?v=4"
},
{
"type": "User",
"login": "xchesh",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/2519047?v=4"
},
{
"type": "User",
"login": "C0DK",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/9048078?v=4"
},
{
"type": "User",
"login": "MisinformedDNA",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/1784452?v=4"
}
],
"contributors_sampled": 6,
"top_contributor_share": 0.99
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"main.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 0,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 4 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "7a1d794daeef790ada66bdb8e1a74335ae25c1c7",
"ran_at": "2026-07-20T19:43:29Z",
"aggregate_score": 4.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/DevTeam/Pure.DI",
"host": "github.com",
"name": "Pure.DI",
"owner": "DevTeam"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": "High-Risk Jurisdiction Policy applies a 50% multiplier to weighted overall health and gives it an At risk ceiling of 49.",
"notes": [
{
"code": "jurisdiction_overall_adjustment",
"params": {
"cap": 49,
"pct": 50
}
}
],
"value": 32,
"inputs": {
"security": 37,
"vitality": 95,
"community": 67,
"governance": 49,
"engineering": 70,
"high_risk_jurisdiction_cap": 49,
"high_risk_jurisdiction_multiplier": 50,
"weighted_overall_before_jurisdiction": 65,
"overall_after_jurisdiction_multiplier": 32
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 95,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 91,
"inputs": {
"commits_last_year": 512,
"human_commit_share": null,
"days_since_last_push": 0,
"active_weeks_last_year": 39
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "39/52 weeks with commits",
"points": 27,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 39
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "512 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 512
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 100,
"latest_release_tag": "2.5.1",
"releases_from_tags": false,
"days_since_latest_release": 4,
"mean_days_between_releases": 14
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 4 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 4
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~14 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 14
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "no_commit_sample",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 67,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"forks": 29,
"stars": 823,
"watchers": 9,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "823 stars",
"points": 47.3,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 823
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "29 forks",
"points": 12.1,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 29
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "9 watchers",
"points": 5,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 9
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 49,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 27,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 6,
"top_contributor_share": 0.99
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 99% of commits",
"points": 0.2,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 99
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "6 contributors",
"points": 8.1,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 6
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 4 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 63,
"inputs": {
"merged_prs": 7,
"open_issues": 6,
"closed_issues": 101,
"issue_closed_ratio": 0.944,
"closed_unmerged_prs": 7
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "94% of issues closed",
"points": 44.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 94
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "7/14 decided PRs merged",
"points": 19.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 7,
"decided": 14
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"followers": 26,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "DevTeam",
"public_repos": 17,
"account_age_days": 4099
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "26 followers of DevTeam",
"points": 10.3,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 26,
"login": "DevTeam"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "17 public repos, account ~11 yr old",
"points": 21.1,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 17
}
},
{
"code": "account_age_years",
"params": {
"years": 11
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 70,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"topics": [
"ioc",
"di",
"dotnet",
"pure",
"csharp",
"source-generator",
"injection",
"injection-framework",
"avalonia",
"unity",
"wpf",
"composition",
"root",
"solid",
"dependency-injection",
"pure-di"
],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "16 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 16
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 37,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized. High-Risk Jurisdiction Policy applies a 50% multiplier to Security posture and gives it an At risk ceiling of 49.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"ci_tests",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "jurisdiction_posture_adjustment",
"params": {
"cap": 49,
"pct": 50
}
}
],
"value": 21,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 14,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 4,
"scorecard_aggregate": 4.2,
"high_risk_jurisdiction_cap": 49,
"high_risk_jurisdiction_multiplier": 50,
"security_posture_after_multiplier": 21,
"security_posture_before_jurisdiction": 42
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 4 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 41 resolved dependencies against OSV; 4 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 41
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 4
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 41,
"unassessed_packages": 4,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 41,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "moderate",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 50,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": true,
"exposures": [
{
"role": "top_contributor",
"count": 1,
"country": "Russia"
}
],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 7
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "Russia: top_contributor (1)",
"points": 50,
"status": "partial",
"details": [
{
"code": "jurisdiction_exposure",
"params": {
"role": "top_contributor",
"count": 1,
"country": "Russia"
}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 65,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "good",
"name": "Agent context & guidance",
"note": "Excluded from scoring (no data or not applicable): Legible commit history. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"legible_commit_history"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 75,
"inputs": {
"has_llms_txt": false,
"legible_history_share": null,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 497749
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): Demonstrated agent practice, Automated maintenance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"demonstrated_agent_practice",
"automated_maintenance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 40,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": null,
"toolchain_manifests": [],
"dependency_bot_commit_share": null
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "C# (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "C#"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"primary_language": "C#",
"largest_source_bytes": 1028740,
"source_files_sampled": 908,
"oversized_source_files": 26
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "C# (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "C#"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "26/908 source files over 60KB",
"points": 53.4,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 908,
"oversized": 26
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"samples"
],
"has_mcp_signal": false,
"api_schema_files": [
"samples/GrpcService/Protos/clock.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "samples/GrpcService/Protos/clock.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "samples/GrpcService/Protos/clock.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "samples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "samples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [],
"report_type": "repository",
"generated_at": "2026-07-20T19:43:38.537061Z",
"schema_version": "0.16.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/DevTeam/Pure.DI.svg",
"full_name": "DevTeam/Pure.DI",
"license_state": "standard",
"license_spdx": "MIT"
}Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.
Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.16.0 — повна методологія · вікі метрик.
Як окремий результат виглядає на тлі всього реєстру: сукупна статистика.