Looks at Python code to search for things which look "dodgy" such as passwords or diffs
prospector-dev/dodgy має індекс здоров’я 28 зі 100, що відповідає смузі «Критичний». Найвищий показник — Engineering Quality (58/100), найнижчий — Vitality (10/100). Останнє оновлення було 1786 днів тому. Більшість нещодавньої роботи виконує один учасник.
Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.
Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.
Політика юрисдикцій високого ризику застосовує множник 75% до зваженого загального індексу здоров’я і встановлює для нього межу «У зоні ризику» на рівні 49.
За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.
| Реєстр | Пакет | Версія | Завантажень / міс | Версії | Остання публікація | Теги |
|---|---|---|---|---|---|---|
| PyPI | dodgyвказує на інший репозиторій — не оцінюється | 0.2.1 | 672 926 | 10 | 2393 дні тому | checkforsuspiciouscode |
Чи живий проєкт — чи пишеться код і чи виходять релізи?
| 0/36 | Свіжість push — останній push 1 786 дн. тому |
| 0/36 | Ритм комітів — 0/52 тижнів із комітами |
| 0/18 | Обсяг комітів — 0 комітів за останній рік |
| 0/10 | OpenSSF Scorecard: Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0 |
| commits_last_year | 0 |
| human_commit_share | — |
| days_since_last_push | 1 786 |
| active_weeks_last_year | 0 |
| 16.2/27 | Випускає релізи — 4 тегів версій (без релізів GitHub) |
| 0/36 | Свіжість релізів — останній реліз 2 393 дн. тому |
| 5.4/27 | Ритм релізів — реліз кожні ~632,7 дн. |
| 0/10 | OpenSSF Scorecard: Signed-Releases — немає даних |
| releases_count | 4 |
| latest_release_tag | 0.2.1 |
| releases_from_tags | так |
| days_since_latest_release | 2 393 |
| mean_days_between_releases | 632,7 |
Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?
| 34.2/60 | Зірки — 130 зірок |
| 10.7/25 | Форки — 20 форків |
| 2.7/15 | Спостерігачі — 4 спостерігачів |
| forks | 20 |
| stars | 130 |
| watchers | 4 |
| growth_state | organic |
| growth_factor_pct | 100 |
| 22.5/22.5 | README |
| 22.5/22.5 | Ліцензія — визнана ліцензія (MIT) |
| 0/18 | Настанови CONTRIBUTING |
| 0/13.5 | Кодекс поведінки |
| 0/7.2 | Шаблон issue |
| 0/6.3 | Шаблон PR |
| has_readme | так |
| has_license | так |
| has_contributing | ні |
| has_issue_template | ні |
| has_code_of_conduct | ні |
| has_pull_request_template | ні |
Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?
| 9/54 | Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів |
| 7.2/22.5 | Розподіл комітів — головний контриб’ютор — автор 68% комітів |
| 13.5/13.5 | Широта контриб’юторів — 11 контриб’юторів |
| 10/10 | OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10 |
| bus_factor | 1 |
| contributors_sampled | 11 |
| top_contributor_share | 0,678 |
| 11.7/46.8 | Вирішення issue — закрито 25% issue |
| 35.1/38.3 | Прийняття PR — злито 11/12 вирішених PR |
| 7.5/15 | OpenSSF Scorecard: Code-Review — Found 9/18 approved changesets -- score normalized to 5 |
| merged_prs | 11 |
| open_issues | 9 |
| closed_issues | 3 |
| issue_closed_ratio | 0,25 |
| closed_unmerged_prs | 1 |
| 30/30 | Підтримка власника — у власності організації |
| 0/20 | Верифікований домен |
| 6.1/25 | Охоплення власника — 6 підписників у prospector-dev |
| 8/25 | Послужний список — 3 публічних репозиторіїв, вік облікового запису ~1 р. |
| followers | 6 |
| owner_type | Organization |
| is_verified | — |
| owner_login | prospector-dev |
| public_repos | 3 |
| account_age_days | 652 |
Чи наявні базові інженерні практики та документація?
| 24/24 | Процеси CI — 1 процес(ів) CI |
| 24/24 | Наявні тести |
| 16/16 | Конфігурація лінтера — tox.ini |
| 0/9.6 | Pre-commit-хуки |
| 0/6.4 | .editorconfig |
| 0/20 | OpenSSF Scorecard: CI-Tests — 0 out of 9 merged PRs checked by a CI test -- score normalized to 0 |
| has_ci | так |
| has_tests | так |
| has_editorconfig | ні |
| has_linter_config | так |
| has_precommit_config | ні |
| 30/30 | README |
| 0/25 | Каталог документації |
| 0/15 | Сайт документації / домашня сторінка |
| 10/10 | Опис репозиторію |
| 0/10 | Теми |
| 10/10 | Wiki |
| topics | — |
| has_wiki | так |
| homepage | — |
| has_readme | так |
| has_docs_dir | ні |
| has_description | так |
Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?
Сигнал ґрунтується на публічних локаціях, самостійно вказаних у профілях. Він не визначає національність, громадянство, наміри, санкційний статус чи надійність людини.
Як оцінюється юрисдикційна пов’язаність| 7.5/7.5 | Binary-Artifacts — no binaries found in the repo |
| 0/7.5 | Branch-Protection — branch protection not enabled on development/release branches |
| 0/2.5 | CI-Tests — 0 out of 9 merged PRs checked by a CI test -- score normalized to 0 |
| 0/2.5 | CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected |
| 3.8/7.5 | Code-Review — Found 9/18 approved changesets -- score normalized to 5 |
| 2.5/2.5 | Contributors — project has 3 contributing companies or organizations -- score normalized to 10 |
| 10/10 | Dangerous-Workflow — no dangerous workflow patterns detected |
| 0/7.5 | Dependency-Update-Tool — no update tool detected |
| 0/5 | Fuzzing — project is not fuzzed |
| 2.5/2.5 | Ліцензія — license file detected |
| 0/7.5 | Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0 |
| 0/5 | Packaging — немає даних |
| 0/5 | Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| 0/5 | SAST — SAST tool is not run on all commits -- score normalized to 0 |
| 0/5 | Security-Policy — security policy file not detected |
| 0/7.5 | Signed-Releases — немає даних |
| 0/7.5 | Token-Permissions — detected GitHub workflow tokens with excessive permissions |
| 7.5/7.5 | Vulnerabilities — 0 existing vulnerabilities detected |
| source | openssf_scorecard |
| checks_evaluated | 16 |
| scorecard_version | v5.5.0 |
| checks_inconclusive | 2 |
| scorecard_aggregate | 3,6 |
| high_risk_jurisdiction_cap | 49 |
| high_risk_jurisdiction_multiplier | 75 |
| security_posture_after_multiplier | 28 |
| security_posture_before_jurisdiction | 37 |
Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.
| 0/45 | Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора |
| 0/15 | Машиночитана документація (llms.txt) |
| 0/40 | Читабельна історія комітів — немає даних |
| has_llms_txt | ні |
| legible_history_share | — |
| agent_instruction_files | — |
| agent_instruction_max_bytes | — |
| 0/18 | Розгортання однією командою |
| 22/22 | Автоматизовані тести |
| 11/11 | Конфігурація лінтера / форматера — tox.ini |
| 0/11 | Статична перевірка типів |
| 0/10 | Відтворюване середовище |
| 0/10 | Підтверджена практика роботи з агентами — немає даних |
| 0/8 | Автоматизоване супроводження — немає даних |
| 0/10 | OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| has_nix | ні |
| has_tests | так |
| lockfiles | — |
| has_dockerfile | ні |
| typed_language | ні |
| bootstrap_files | — |
| has_devcontainer | ні |
| has_linter_config | так |
| typecheck_configs | — |
| agent_commit_share | — |
| toolchain_manifests | — |
| dependency_bot_commit_share | — |
| 0/45 | Типізований код — Python без конфігурації перевірки типів |
| 55/55 | Керовані розміри файлів — 0/20 файлів вихідного коду понад 60 КБ |
| primary_language | Python |
| largest_source_bytes | 3 155 |
| source_files_sampled | 20 |
| oversized_source_files | 0 |
Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.
Кожна точка охоплює 12 днів.
Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).
| 10 | Binary-Artifacts | no binaries found in the repo |
| 0 | Branch-Protection | branch protection not enabled on development/release branches |
| 0 | CI-Tests | 0 out of 9 merged PRs checked by a CI test -- score normalized to 0 |
| 0 | CII-Best-Practices | no effort to earn an OpenSSF best practices badge detected |
| 5 | Code-Review | Found 9/18 approved changesets -- score normalized to 5 |
| 10 | Contributors | project has 3 contributing companies or organizations -- score normalized to 10 |
| 10 | Dangerous-Workflow | no dangerous workflow patterns detected |
| 0 | Dependency-Update-Tool | no update tool detected |
| 0 | Fuzzing | project is not fuzzed |
| 10 | License | license file detected |
| 0 | Maintained | 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0 |
| н/д | Packaging | packaging workflow not detected |
| 0 | Pinned-Dependencies | dependency not pinned by hash detected -- score normalized to 0 |
| 0 | SAST | SAST tool is not run on all commits -- score normalized to 0 |
| 0 | Security-Policy | security policy file not detected |
| н/д | Signed-Releases | no releases found |
| 0 | Token-Permissions | detected GitHub workflow tokens with excessive permissions |
| 10 | Vulnerabilities | 0 existing vulnerabilities detected |
Повний розв'язаний набір залежностей із графа залежностей GitHub: 0 прямих і 0 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.
| Реєстр | Пакет | Версія | Зв'язок |
|---|
Звірка сповіщень не відбулася для цього звіту: No resolved dependencies to assess
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 51,
"has_wiki": true,
"homepage": null,
"languages": {
"Python": 9294
},
"pushed_at": "2021-08-29T14:44:21Z",
"created_at": "2013-12-25T12:22:20Z",
"owner_type": "Organization",
"updated_at": "2026-07-10T22:49:17Z",
"description": "Looks at Python code to search for things which look \"dodgy\" such as passwords or diffs",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "master",
"license_spdx_raw": "MIT",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": null,
"name": null,
"type": "Organization",
"login": "prospector-dev",
"company": null,
"location": null,
"followers": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/183985870?v=4",
"created_at": "2024-10-06T11:00:42Z",
"is_verified": null,
"public_repos": 3,
"account_age_days": 652
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases_count": 4,
"commits_last_year": 0,
"latest_release_at": "2019-12-31T16:43:17Z",
"latest_release_tag": "0.2.1",
"releases_from_tags": true,
"days_since_last_push": 1786,
"active_weeks_last_year": 0,
"days_since_latest_release": 2393,
"mean_days_between_releases": 632.7
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "dodgy",
"exists": true,
"license": "MIT",
"keywords": [
"check",
"for",
"suspicious",
"code",
"Development Status :: 7 - Inactive",
"Environment :: Console",
"Intended Audience :: Developers",
"License :: OSI Approved :: MIT License",
"Operating System :: Unix",
"Programming Language :: Python :: 3.4",
"Programming Language :: Python :: 3.5",
"Programming Language :: Python :: 3.6",
"Programming Language :: Python :: 3.7",
"Programming Language :: Python :: 3.8",
"Topic :: Software Development :: Quality Assurance"
],
"ecosystem": "pypi",
"matches_repo": false,
"registry_url": "https://pypi.org/project/dodgy/",
"is_deprecated": false,
"latest_version": "0.2.1",
"repository_url": "https://github.com/landscapeio/dodgy",
"versions_count": 10,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 672926,
"first_published_at": "2013-12-26T13:33:30.497186Z",
"latest_published_at": "2019-12-31T16:44:59.472867Z",
"latest_version_yanked": null,
"days_since_latest_publish": 2393
}
]
},
"popularity": {
"forks": 20,
"stars": 130,
"watchers": 4,
"star_history": {
"days": [
{
"date": "2013-12-26",
"count": 1
},
{
"date": "2013-12-30",
"count": 1
},
{
"date": "2014-02-21",
"count": 1
},
{
"date": "2014-04-09",
"count": 1
},
{
"date": "2014-05-27",
"count": 1
},
{
"date": "2014-07-23",
"count": 2
},
{
"date": "2014-08-09",
"count": 1
},
{
"date": "2014-08-20",
"count": 1
},
{
"date": "2014-09-25",
"count": 1
},
{
"date": "2014-10-19",
"count": 2
},
{
"date": "2014-10-24",
"count": 1
},
{
"date": "2014-10-29",
"count": 1
},
{
"date": "2014-10-30",
"count": 2
},
{
"date": "2014-11-03",
"count": 1
},
{
"date": "2015-01-28",
"count": 1
},
{
"date": "2015-02-06",
"count": 1
},
{
"date": "2015-03-18",
"count": 1
},
{
"date": "2015-04-27",
"count": 1
},
{
"date": "2015-04-29",
"count": 1
},
{
"date": "2015-05-20",
"count": 1
},
{
"date": "2016-02-05",
"count": 1
},
{
"date": "2016-02-08",
"count": 1
},
{
"date": "2016-04-13",
"count": 1
},
{
"date": "2016-04-23",
"count": 1
},
{
"date": "2016-08-04",
"count": 1
},
{
"date": "2016-08-23",
"count": 1
},
{
"date": "2017-02-23",
"count": 1
},
{
"date": "2017-03-21",
"count": 1
},
{
"date": "2017-07-17",
"count": 1
},
{
"date": "2017-08-16",
"count": 2
},
{
"date": "2017-08-30",
"count": 1
},
{
"date": "2017-10-11",
"count": 5
},
{
"date": "2017-11-09",
"count": 1
},
{
"date": "2018-01-03",
"count": 1
},
{
"date": "2018-03-18",
"count": 1
},
{
"date": "2018-03-24",
"count": 1
},
{
"date": "2018-03-27",
"count": 2
},
{
"date": "2018-03-29",
"count": 2
},
{
"date": "2018-04-07",
"count": 1
},
{
"date": "2018-08-22",
"count": 1
},
{
"date": "2018-09-10",
"count": 1
},
{
"date": "2018-09-18",
"count": 1
},
{
"date": "2018-10-02",
"count": 1
},
{
"date": "2018-11-17",
"count": 1
},
{
"date": "2018-12-28",
"count": 1
},
{
"date": "2019-01-09",
"count": 1
},
{
"date": "2019-01-10",
"count": 1
},
{
"date": "2019-02-18",
"count": 1
},
{
"date": "2019-03-20",
"count": 1
},
{
"date": "2019-05-25",
"count": 1
},
{
"date": "2019-06-23",
"count": 1
},
{
"date": "2019-06-27",
"count": 1
},
{
"date": "2019-07-13",
"count": 1
},
{
"date": "2019-09-06",
"count": 1
},
{
"date": "2019-11-01",
"count": 1
},
{
"date": "2019-12-10",
"count": 1
},
{
"date": "2019-12-16",
"count": 1
},
{
"date": "2020-01-03",
"count": 1
},
{
"date": "2020-01-05",
"count": 1
},
{
"date": "2020-01-08",
"count": 1
},
{
"date": "2020-03-17",
"count": 1
},
{
"date": "2020-03-18",
"count": 1
},
{
"date": "2020-03-19",
"count": 1
},
{
"date": "2020-04-01",
"count": 1
},
{
"date": "2020-04-08",
"count": 1
},
{
"date": "2020-04-21",
"count": 1
},
{
"date": "2020-04-26",
"count": 1
},
{
"date": "2020-06-10",
"count": 1
},
{
"date": "2020-09-05",
"count": 1
},
{
"date": "2020-09-21",
"count": 1
},
{
"date": "2020-10-14",
"count": 1
},
{
"date": "2020-12-09",
"count": 1
},
{
"date": "2021-01-05",
"count": 1
},
{
"date": "2021-01-18",
"count": 1
},
{
"date": "2021-04-28",
"count": 1
},
{
"date": "2021-05-21",
"count": 1
},
{
"date": "2021-07-01",
"count": 1
},
{
"date": "2021-08-07",
"count": 1
},
{
"date": "2021-10-07",
"count": 1
},
{
"date": "2021-10-10",
"count": 1
},
{
"date": "2021-10-21",
"count": 1
},
{
"date": "2021-12-06",
"count": 1
},
{
"date": "2021-12-23",
"count": 1
},
{
"date": "2021-12-27",
"count": 1
},
{
"date": "2022-02-02",
"count": 1
},
{
"date": "2022-02-13",
"count": 1
},
{
"date": "2022-02-16",
"count": 1
},
{
"date": "2022-02-17",
"count": 1
},
{
"date": "2022-03-23",
"count": 1
},
{
"date": "2022-04-05",
"count": 1
},
{
"date": "2022-04-07",
"count": 1
},
{
"date": "2022-04-25",
"count": 1
},
{
"date": "2022-05-08",
"count": 1
},
{
"date": "2022-05-19",
"count": 1
},
{
"date": "2022-07-31",
"count": 1
},
{
"date": "2022-08-11",
"count": 1
},
{
"date": "2022-09-25",
"count": 1
},
{
"date": "2022-10-23",
"count": 1
},
{
"date": "2022-11-25",
"count": 1
},
{
"date": "2023-06-11",
"count": 1
},
{
"date": "2023-07-05",
"count": 1
},
{
"date": "2023-08-15",
"count": 1
},
{
"date": "2023-10-24",
"count": 1
},
{
"date": "2023-11-09",
"count": 1
},
{
"date": "2023-12-01",
"count": 1
},
{
"date": "2024-01-09",
"count": 1
},
{
"date": "2024-03-29",
"count": 1
},
{
"date": "2024-06-27",
"count": 1
},
{
"date": "2024-07-30",
"count": 1
},
{
"date": "2024-10-05",
"count": 1
},
{
"date": "2024-12-26",
"count": 1
},
{
"date": "2025-01-23",
"count": 2
},
{
"date": "2025-03-13",
"count": 1
},
{
"date": "2025-09-19",
"count": 1
},
{
"date": "2025-12-11",
"count": 1
},
{
"date": "2026-01-02",
"count": 1
},
{
"date": "2026-06-09",
"count": 1
},
{
"date": "2026-07-01",
"count": 1
},
{
"date": "2026-07-10",
"count": 1
}
],
"complete": true,
"collected": 130,
"total_stars": 130
},
"open_issues_and_prs": 11
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"largest_source_bytes": 3155,
"source_files_sampled": 20,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"setup.py"
],
"advisories": {
"error": "No resolved dependencies to assess",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [],
"collected": true,
"truncated": false,
"total_count": 0,
"direct_count": 0,
"indirect_count": 0
}
},
"maintainership": {
"issues": {
"open_prs": 2,
"merged_prs": 11,
"open_issues": 9,
"closed_ratio": 0.25,
"closed_issues": 3,
"closed_unmerged_prs": 1
},
"bus_factor": 1,
"top_contributors": [
{
"type": "User",
"login": "carlio",
"commits": 40,
"avatar_url": "https://avatars.githubusercontent.com/u/682175?v=4"
},
{
"type": "User",
"login": "LiamDeacon-NATS",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/51312339?v=4"
},
{
"type": "User",
"login": "Liam-Deacon",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/3184694?v=4"
},
{
"type": "User",
"login": "9seconds",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/831613?v=4"
},
{
"type": "User",
"login": "CJ-Wright",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/6740689?v=4"
},
{
"type": "User",
"login": "blueyed",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/9766?v=4"
},
{
"type": "User",
"login": "jdorel",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/20277513?v=4"
},
{
"type": "User",
"login": "tirkarthi",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/3972343?v=4"
},
{
"type": "User",
"login": "movermeyer",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/1459385?v=4"
},
{
"type": "User",
"login": "sobolevn",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/4660275?v=4"
}
],
"contributors_sampled": 11,
"top_contributor_share": 0.678
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"pythonpackage.yml"
],
"has_docs_dir": false,
"linter_configs": [
"tox.ini"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 0,
"reason": "0 out of 9 merged PRs checked by a CI test -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 5,
"reason": "Found 9/18 approved changesets -- score normalized to 5",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 3 contributing companies or organizations -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "b3fbaf05b106f7c3da8160e38c704f695613ff4d",
"ran_at": "2026-07-21T03:55:59Z",
"aggregate_score": 3.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/prospector-dev/dodgy",
"host": "github.com",
"name": "dodgy",
"owner": "prospector-dev"
},
"metrics": {
"overall": {
"key": "overall",
"band": "critical",
"name": "Overall health",
"note": "High-Risk Jurisdiction Policy applies a 75% multiplier to weighted overall health and gives it an At risk ceiling of 49.",
"notes": [
{
"code": "jurisdiction_overall_adjustment",
"params": {
"cap": 49,
"pct": 75
}
}
],
"value": 28,
"inputs": {
"security": 28,
"vitality": 10,
"community": 49,
"governance": 46,
"engineering": 58,
"high_risk_jurisdiction_cap": 49,
"high_risk_jurisdiction_multiplier": 75,
"weighted_overall_before_jurisdiction": 38,
"overall_after_jurisdiction_multiplier": 28
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "critical",
"name": "Vitality",
"value": 10,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "critical",
"name": "Development activity",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"commits_last_year": 0,
"human_commit_share": null,
"days_since_last_push": 1786,
"active_weeks_last_year": 0
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 1786 days ago",
"points": 0,
"status": "missed",
"details": [
{
"code": "push_recency",
"params": {
"days": 1786
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "0/52 weeks with commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 0
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "0 commits in the last year",
"points": 0,
"status": "missed",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 0
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "critical",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 24,
"inputs": {
"releases_count": 4,
"latest_release_tag": "0.2.1",
"releases_from_tags": true,
"days_since_latest_release": 2393,
"mean_days_between_releases": 632.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "4 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 4
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 2393 days ago",
"points": 0,
"status": "missed",
"details": [
{
"code": "release_recency",
"params": {
"days": 2393
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~632.7 days",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 632.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "no_commit_sample",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 49,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 48,
"inputs": {
"forks": 20,
"stars": 130,
"watchers": 4,
"growth_state": "organic",
"growth_factor_pct": 100
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "130 stars",
"points": 34.2,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 130
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "20 forks",
"points": 10.7,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 20
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "4 watchers",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 4
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 46,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 11,
"top_contributor_share": 0.678
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 68% of commits",
"points": 7.2,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 68
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "11 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 11
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"merged_prs": 11,
"open_issues": 9,
"closed_issues": 3,
"issue_closed_ratio": 0.25,
"closed_unmerged_prs": 1
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "25% of issues closed",
"points": 11.7,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 25
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "11/12 decided PRs merged",
"points": 35.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 11,
"decided": 12
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 9/18 approved changesets -- score normalized to 5",
"points": 7.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 44,
"inputs": {
"followers": 6,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "prospector-dev",
"public_repos": 3,
"account_age_days": 652
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "6 followers of prospector-dev",
"points": 6.1,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 6,
"login": "prospector-dev"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "3 public repos, account ~1 yr old",
"points": 8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 3
}
},
{
"code": "account_age_years",
"params": {
"years": 1
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 58,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "tox.ini",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tox.ini"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "0 out of 9 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "critical",
"name": "Security",
"value": 28,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized. High-Risk Jurisdiction Policy applies a 75% multiplier to Security posture and gives it an At risk ceiling of 49.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "jurisdiction_posture_adjustment",
"params": {
"cap": 49,
"pct": 75
}
}
],
"value": 28,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 3.6,
"high_risk_jurisdiction_cap": 49,
"high_risk_jurisdiction_multiplier": 75,
"security_posture_after_multiplier": 28,
"security_posture_before_jurisdiction": 37
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "0 out of 9 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 9/18 approved changesets -- score normalized to 5",
"points": 3.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "good",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 75,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": true,
"exposures": [
{
"role": "contributor_organization",
"count": 1,
"country": "Russia"
}
],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 18
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "Russia: contributor_organization (1)",
"points": 75,
"status": "partial",
"details": [
{
"code": "jurisdiction_exposure",
"params": {
"role": "contributor_organization",
"count": 1,
"country": "Russia"
}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "critical",
"name": "AI Readiness",
"value": 29,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "critical",
"name": "Agent context & guidance",
"note": "Excluded from scoring (no data or not applicable): Legible commit history. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"legible_commit_history"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"has_llms_txt": false,
"legible_history_share": null,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): Demonstrated agent practice, Automated maintenance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"demonstrated_agent_practice",
"automated_maintenance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 40,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": null,
"toolchain_manifests": [],
"dependency_bot_commit_share": null
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "tox.ini",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tox.ini"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 3155,
"source_files_sampled": 20,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/20 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 20,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"pypi package 'dodgy' points at a different repository (https://github.com/landscapeio/dodgy); excluded from ecosystem scoring"
],
"report_type": "repository",
"generated_at": "2026-07-21T03:56:14.357209Z",
"schema_version": "0.17.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/prospector-dev/dodgy.svg",
"full_name": "prospector-dev/dodgy",
"license_state": "standard",
"license_spdx": "MIT"
}Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.
Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.17.0 — повна методологія · вікі метрик.
Як окремий результат виглядає на тлі всього реєстру: сукупна статистика — PyPI.