A pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files
py-pdf/pypdf має індекс здоров’я 87 зі 100, що відповідає смузі «Відмінний». Найвищий показник — Vitality (94/100), найнижчий — AI Readiness (51/100). Останнє оновлення було 20 днів тому. Більшість нещодавньої роботи виконують 3 учасники.
Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.
Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.
За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.
| Реєстр | Пакет | Версія | Завантажень / міс | Версії | Остання публікація |
|---|---|---|---|---|---|
| PyPI | pypdf | 6.14.2 | - | 108 | 27 днів тому |
Чи живий проєкт — чи пишеться код і чи виходять релізи?
| 28.8/36 | Свіжість push — останній push 20 дн. тому |
| 33.2/36 | Ритм комітів — 48/52 тижнів із комітами |
| 18/18 | Обсяг комітів — 348 комітів за останній рік |
| 10/10 | OpenSSF Scorecard: Maintained — 30 commit(s) and 20 issue activity found in the last 90 days -- score normalized to 10 |
| commits_last_year | 348 |
| human_commit_share | — |
| days_since_last_push | 20 |
| active_weeks_last_year | 48 |
| 27/27 | Випускає релізи — опубліковано 100 релізів |
| 36/36 | Свіжість релізів — останній реліз 27 дн. тому |
| 27/27 | Ритм релізів — реліз кожні ~3,7 дн. |
| 0/10 | OpenSSF Scorecard: Signed-Releases — немає даних |
| releases_count | 100 |
| latest_release_tag | 6.14.2 |
| releases_from_tags | ні |
| days_since_latest_release | 27 |
| mean_days_between_releases | 3,7 |
Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?
| 60/60 | Зірки — 10 123 зірок |
| 25/25 | Форки — 1 601 форків |
| 11.9/15 | Спостерігачі — 142 спостерігачів |
| forks | 1 601 |
| stars | 10 123 |
| watchers | 142 |
| growth_state | unverified |
| growth_factor_pct | 100 |
| growth_unverified_reason | no_history |
| 22.5/22.5 | README |
| 16.9/22.5 | Ліцензія — файл ліцензії наявний, не є визнаною ліцензією |
| 18/18 | Настанови CONTRIBUTING |
| 0/13.5 | Кодекс поведінки |
| 0/7.2 | Шаблон issue |
| 0/6.3 | Шаблон PR |
| has_readme | так |
| has_license | так |
| has_contributing | так |
| has_issue_template | ні |
| has_code_of_conduct | ні |
| has_pull_request_template | ні |
Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?
| 36/54 | Бас-фактор — на 3 контриб’ютор(ів) припадає половина всіх комітів |
| 15/22.5 | Розподіл комітів — головний контриб’ютор — автор 33% комітів |
| 13.5/13.5 | Широта контриб’юторів — 100 контриб’юторів |
| 10/10 | OpenSSF Scorecard: Contributors — project has 19 contributing companies or organizations |
| bus_factor | 3 |
| contributors_sampled | 100 |
| top_contributor_share | 0,334 |
| 43.5/46.8 | Вирішення issue — закрито 93% issue |
| 32.3/38.3 | Прийняття PR — злито 1 748/2 071 вирішених PR |
| 9/15 | OpenSSF Scorecard: Code-Review — Found 17/28 approved changesets -- score normalized to 6 |
| merged_prs | 1 748 |
| open_issues | 97 |
| closed_issues | 1 319 |
| issue_closed_ratio | 0,931 |
| closed_unmerged_prs | 323 |
| 30/30 | Підтримка власника — у власності організації |
| 0/20 | Верифікований домен |
| 17/25 | Охоплення власника — 228 підписників у py-pdf |
| 16.4/25 | Послужний список — 11 публічних репозиторіїв, вік облікового запису ~4 р. |
| followers | 228 |
| owner_type | Organization |
| is_verified | — |
| owner_login | py-pdf |
| public_repos | 11 |
| account_age_days | 1 569 |
| 25/25 | Опубліковано й доступно — 1 пакет(ів) у pypi |
| 35/35 | Свіжість публікацій — остання публікація 27 дн. тому |
| 20/20 | Історія версій — 108 опублікованих версій |
| 20/20 | Не застарілий — активний, не deprecated і не yanked |
| packages | pypdf |
| ecosystems | pypi |
| any_deprecated | ні |
| min_days_since_publish | 27 |
Чи наявні базові інженерні практики та документація?
| 24/24 | Процеси CI — 9 процес(ів) CI |
| 24/24 | Наявні тести |
| 16/16 | Конфігурація лінтера |
| 9.6/9.6 | Pre-commit-хуки |
| 0/6.4 | .editorconfig |
| 20/20 | OpenSSF Scorecard: CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10 |
| has_ci | так |
| has_tests | так |
| has_editorconfig | ні |
| has_linter_config | так |
| has_precommit_config | так |
| 30/30 | README |
| 25/25 | Каталог документації |
| 15/15 | Сайт документації / домашня сторінка — https://pypdf.readthedocs.io/en/latest/ |
| 10/10 | Опис репозиторію |
| 10/10 | Теми — 8 тем |
| 0/10 | Wiki |
| topics | pypdf2, pdf, python, pdf-parser, pdf-parsing, pdf-manipulation, pdf-documents, help-wanted |
| has_wiki | ні |
| homepage | https://pypdf.readthedocs.io/en/latest/ |
| has_readme | так |
| has_docs_dir | так |
| has_description | так |
Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?
| 7.5/7.5 | Binary-Artifacts — no binaries found in the repo |
| 4.5/7.5 | Branch-Protection — branch protection is not maximal on development and all release branches |
| 2.5/2.5 | CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10 |
| 0/2.5 | CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected |
| 4.5/7.5 | Code-Review — Found 17/28 approved changesets -- score normalized to 6 |
| 2.5/2.5 | Contributors — project has 19 contributing companies or organizations |
| 10/10 | Dangerous-Workflow — no dangerous workflow patterns detected |
| 7.5/7.5 | Dependency-Update-Tool — update tool detected |
| 5/5 | Fuzzing — project is fuzzed |
| 2.2/2.5 | Ліцензія — license file detected |
| 7.5/7.5 | Maintained — 30 commit(s) and 20 issue activity found in the last 90 days -- score normalized to 10 |
| 5/5 | Packaging — packaging workflow detected |
| 1.5/5 | Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3 |
| 5/5 | SAST — SAST tool is run on all commits |
| 5/5 | Security-Policy — security policy file detected |
| 0/7.5 | Signed-Releases — немає даних |
| 7.5/7.5 | Token-Permissions — GitHub workflow tokens follow principle of least privilege |
| 7.5/7.5 | Vulnerabilities — 0 existing vulnerabilities detected |
| source | openssf_scorecard |
| checks_evaluated | 17 |
| scorecard_version | v5.5.0 |
| checks_inconclusive | 1 |
| scorecard_aggregate | 8,7 |
| 35/35 | Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень |
| 0/25 | Непрямі залежності без відомих сповіщень — транзитивний набір не відокремлюється від залежностей розробки й тестування в цьому обсязі |
| 0/40 | Немає задавнених сповіщень — жодне сповіщення не має дати публікації |
| source | osv |
| advisories | 22 |
| affected_packages | 2 |
| assessed_packages | 79 |
| unassessed_packages | 1 |
| affected_by_severity | critical 1, high 1 |
| direct_affected_packages | 0 |
Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.
| 0/45 | Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора |
| 0/15 | Машиночитана документація (llms.txt) |
| 0/40 | Читабельна історія комітів — немає даних |
| has_llms_txt | ні |
| legible_history_share | — |
| agent_instruction_files | — |
| agent_instruction_max_bytes | — |
| 18/18 | Розгортання однією командою — Makefile, docs/Makefile |
| 22/22 | Автоматизовані тести |
| 11/11 | Конфігурація лінтера / форматера |
| 11/11 | Статична перевірка типів — pypdf/py.typed |
| 0/10 | Відтворюване середовище |
| 0/10 | Підтверджена практика роботи з агентами — немає даних |
| 5/8 | Автоматизоване супроводження — автоматизацію залежностей налаштовано, але у вибірці комітів її не видно |
| 3/10 | OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3 |
| has_nix | ні |
| has_tests | так |
| lockfiles | — |
| has_dockerfile | ні |
| typed_language | ні |
| bootstrap_files | Makefile, docs/Makefile |
| has_devcontainer | ні |
| has_linter_config | так |
| typecheck_configs | pypdf/py.typed |
| agent_commit_share | — |
| toolchain_manifests | — |
| dependency_bot_commit_share | 0 |
| 27/45 | Типізований код — Python з конфігурацією перевірки типів (pypdf/py.typed) |
| 50.8/55 | Керовані розміри файлів — 8/104 файлів вихідного коду понад 60 КБ |
| primary_language | Python |
| largest_source_bytes | 447 213 |
| source_files_sampled | 104 |
| oversized_source_files | 8 |
Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).
| 10 | Binary-Artifacts | no binaries found in the repo |
| 6 | Branch-Protection | branch protection is not maximal on development and all release branches |
| 10 | CI-Tests | 25 out of 25 merged PRs checked by a CI test -- score normalized to 10 |
| 0 | CII-Best-Practices | no effort to earn an OpenSSF best practices badge detected |
| 6 | Code-Review | Found 17/28 approved changesets -- score normalized to 6 |
| 10 | Contributors | project has 19 contributing companies or organizations |
| 10 | Dangerous-Workflow | no dangerous workflow patterns detected |
| 10 | Dependency-Update-Tool | update tool detected |
| 10 | Fuzzing | project is fuzzed |
| 9 | License | license file detected |
| 10 | Maintained | 30 commit(s) and 20 issue activity found in the last 90 days -- score normalized to 10 |
| 10 | Packaging | packaging workflow detected |
| 3 | Pinned-Dependencies | dependency not pinned by hash detected -- score normalized to 3 |
| 10 | SAST | SAST tool is run on all commits |
| 10 | Security-Policy | security policy file detected |
| н/д | Signed-Releases | no releases found |
| 10 | Token-Permissions | GitHub workflow tokens follow principle of least privilege |
| 10 | Vulnerabilities | 0 existing vulnerabilities detected |
| Реєстр | Пакет | Обмеження версії | Маніфест |
|---|---|---|---|
| PyPI | typing_extensions | >= 4.0 | pyproject.toml |
Повний розв'язаний набір залежностей із графа залежностей GitHub: 3 прямих і 77 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.
| Реєстр | Пакет | Версія | Зв'язок |
|---|---|---|---|
| PyPI | typing-extensions | — | пряма |
| PyPI | typing-extensions | 4.12.2 | пряма |
| PyPI | typing-extensions | 4.15.0 | пряма |
| PyPI | alabaster | 1.0.0 | непряма |
| PyPI | arabic-reshaper | 3.0.0 | непряма |
| PyPI | babel | 2.16.0 | непряма |
| PyPI | build | 1.2.2.post1 | непряма |
| PyPI | certifi | 2024.8.30 | непряма |
| PyPI | cffi | 2.0.0 | непряма |
| PyPI | cfgv | 3.4.0 | непряма |
| PyPI | charset-normalizer | 3.4.0 | непряма |
| PyPI | click | 8.1.7 | непряма |
| PyPI | coverage | 7.13.0 | непряма |
| PyPI | coverage | 7.6.1 | непряма |
| PyPI | cryptography | 48.0.1 | непряма |
| PyPI | defusedxml | 0.7.1 | непряма |
| PyPI | distlib | 0.3.9 | непряма |
| PyPI | docutils | 0.20.1 | непряма |
| PyPI | docutils | 0.21.2 | непряма |
| PyPI | exceptiongroup | 1.2.2 | непряма |
| PyPI | execnet | 2.1.1 | непряма |
| PyPI | filelock | 3.20.3 | непряма |
| PyPI | flit | 3.11.0 | непряма |
| PyPI | flit-core | 3.11.0 | непряма |
| PyPI | fonttools | 4.61.0 | непряма |
| PyPI | fpdf2 | 2.8.1 | непряма |
| PyPI | identify | 2.6.1 | непряма |
| PyPI | idna | 3.15 | непряма |
| PyPI | imagesize | 1.4.1 | непряма |
| PyPI | importlib-metadata | 8.5.0 | непряма |
| PyPI | iniconfig | 2.0.0 | непряма |
| PyPI | jinja2 | 3.1.6 | непряма |
| PyPI | markdown-it-py | 3.0.0 | непряма |
| PyPI | markupsafe | 3.0.1 | непряма |
| PyPI | mdit-py-plugins | 0.4.2 | непряма |
| PyPI | mdurl | 0.1.2 | непряма |
| PyPI | mypy | 1.17.0 | непряма |
| PyPI | mypy-extensions | 1.0.0 | непряма |
| PyPI | myst-parser | 4.0.0 | непряма |
| PyPI | nodeenv | 1.9.1 | непряма |
| PyPI | packaging | 24.1 | непряма |
| PyPI | pathspec | 1.0.4 | непряма |
| PyPI | pillow | 12.2.0 | непряма |
| PyPI | pip-tools | 7.4.1 | непряма |
| PyPI | platformdirs | 4.3.6 | непряма |
| PyPI | pluggy | 1.5.0 | непряма |
| PyPI | pre-commit | 3.5.0 | непряма |
| PyPI | py-cpuinfo | 9.0.0 | непряма |
| PyPI | pycparser | 2.22 | непряма |
| PyPI | pycryptodome | 3.23.0 | непряма |
| PyPI | pygments | 2.20.0 | непряма |
| PyPI | pyproject-hooks | 1.2.0 | непряма |
| PyPI | pytest | 9.0.3 | непряма |
| PyPI | pytest-benchmark | 5.2.3 | непряма |
| PyPI | pytest-cov | 5.0.0 | непряма |
| PyPI | pytest-socket | 0.7.0 | непряма |
| PyPI | pytest-timeout | 2.3.1 | непряма |
| PyPI | pytest-xdist | 3.6.1 | непряма |
| PyPI | python-bidi | 0.6.10 | непряма |
| PyPI | pyyaml | 6.0.2 | непряма |
| PyPI | requests | 2.33.0 | непряма |
| PyPI | ruff | 0.15.0 | непряма |
| PyPI | snowballstemmer | 2.2.0 | непряма |
| PyPI | sphinx | 8.1.3 | непряма |
| PyPI | sphinx-rtd-theme | 3.0.1 | непряма |
| PyPI | sphinxcontrib-applehelp | 2.0.0 | непряма |
| PyPI | sphinxcontrib-devhelp | 2.0.0 | непряма |
| PyPI | sphinxcontrib-htmlhelp | 2.1.0 | непряма |
| PyPI | sphinxcontrib-jquery | 4.1 | непряма |
| PyPI | sphinxcontrib-jsmath | 1.0.1 | непряма |
| PyPI | sphinxcontrib-qthelp | 2.0.0 | непряма |
| PyPI | sphinxcontrib-serializinghtml | 2.0.0 | непряма |
| PyPI | tomli | 2.0.2 | непряма |
| PyPI | tomli-w | 1.0.0 | непряма |
| PyPI | typeguard | 4.3.0 | непряма |
| PyPI | types-pyyaml | 6.0.12.20250915 | непряма |
| PyPI | urllib3 | 2.7.0 | непряма |
| PyPI | virtualenv | 20.36.1 | непряма |
| PyPI | wheel | 0.46.2 | непряма |
| PyPI | zipp | 3.20.2 | непряма |
Цей репозиторій не публікує пакета, який розпізнає індекс, тож оцінено його власний граф залежностей — 79 пакетів, серед яких є й піниї розробки та тестування, що ніколи не постачаються: 2 мають відомі сповіщення, з них 0 прямі. 1 не вдалося оцінити — немає резолвленої версії, непідтримувана екосистема або поза наведеним переліком пакетів.
| Пакет | Версія | Зв'язок | Критичність | Сповіщень | Виправлено в |
|---|---|---|---|---|---|
| pillow | 12.2.0 | непряма | критична | 21 | 12.3.0 |
| click | 8.1.7 | непряма | висока | 1 | 8.3.3 |
Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.
{
"data": {
"repo": {
"topics": [
"pypdf2",
"pdf",
"python",
"pdf-parser",
"pdf-parsing",
"pdf-manipulation",
"pdf-documents",
"help-wanted"
],
"is_fork": false,
"size_kb": 35412,
"has_wiki": false,
"homepage": "https://pypdf.readthedocs.io/en/latest/",
"languages": {
"Python": 2272203,
"Makefile": 724
},
"pushed_at": "2026-06-30T05:23:02Z",
"created_at": "2012-01-06T17:13:38Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T23:52:16Z",
"description": "A pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": "NOASSERTION",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": null,
"name": null,
"type": "Organization",
"login": "py-pdf",
"company": null,
"location": null,
"followers": 228,
"avatar_url": "https://avatars.githubusercontent.com/u/102914013?v=4",
"created_at": "2022-04-03T15:06:10Z",
"is_verified": null,
"public_repos": 11,
"account_age_days": 1569
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases_count": 100,
"commits_last_year": 348,
"latest_release_at": "2026-06-23T14:18:09Z",
"latest_release_tag": "6.14.2",
"releases_from_tags": false,
"days_since_last_push": 20,
"active_weeks_last_year": 48,
"days_since_latest_release": 27,
"mean_days_between_releases": 3.7
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "pypdf",
"exists": true,
"license": "BSD-3-Clause",
"keywords": [
"Development Status :: 5 - Production/Stable",
"Intended Audience :: Developers",
"Operating System :: OS Independent",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3 :: Only",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Programming Language :: Python :: 3.14",
"Programming Language :: Python :: 3.9",
"Topic :: Software Development :: Libraries :: Python Modules",
"Typing :: Typed"
],
"ecosystem": "pypi",
"matches_repo": true,
"registry_url": "https://pypi.org/project/pypdf/",
"is_deprecated": false,
"latest_version": "6.14.2",
"repository_url": "https://github.com/py-pdf/pypdf",
"versions_count": 108,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": "2014-05-17T22:40:49.200819Z",
"latest_published_at": "2026-06-23T14:18:30.859270Z",
"latest_version_yanked": null,
"days_since_latest_publish": 27
}
]
},
"popularity": {
"forks": 1601,
"stars": 10123,
"watchers": 142,
"open_issues_and_prs": 149
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"docs/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"pypdf/py.typed"
],
"largest_source_bytes": 447213,
"source_files_sampled": 104,
"oversized_source_files": 8,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"pyproject.toml"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "pillow",
"direct": false,
"version": "12.2.0",
"severity": "critical",
"ecosystem": "pypi",
"cvss_score": 9.1,
"advisory_ids": [
"GHSA-45hq-cxwh-f6vc",
"GHSA-4x4j-2g7c-83w6",
"GHSA-5x94-69rx-g8h2",
"GHSA-62p4-gmf7-7g93",
"GHSA-6r8x-57c9-28j4",
"GHSA-8v84-f9pq-wr9x",
"GHSA-9hw9-ch79-4vh6",
"GHSA-fj7v-r99m-22gq",
"GHSA-jjj6-mw9f-p565",
"GHSA-pg7v-jwj7-p798"
],
"fixed_version": "12.3.0",
"advisory_count": 21,
"oldest_advisory_days": 14
},
{
"name": "click",
"direct": false,
"version": "8.1.7",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": 7.2,
"advisory_ids": [
"PYSEC-2026-2132"
],
"fixed_version": "8.3.3",
"advisory_count": 1,
"oldest_advisory_days": 81
}
],
"collected": true,
"truncated": false,
"by_severity": {
"high": 1,
"critical": 1
},
"advisory_count": 22,
"affected_count": 2,
"assessed_count": 79,
"assessed_package": null,
"unassessed_count": 1,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "typing_extensions",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">= 4.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "typing-extensions",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "typing-extensions",
"direct": true,
"version": "4.12.2",
"ecosystem": "pypi"
},
{
"name": "typing-extensions",
"direct": true,
"version": "4.15.0",
"ecosystem": "pypi"
},
{
"name": "alabaster",
"direct": false,
"version": "1.0.0",
"ecosystem": "pypi"
},
{
"name": "arabic-reshaper",
"direct": false,
"version": "3.0.0",
"ecosystem": "pypi"
},
{
"name": "babel",
"direct": false,
"version": "2.16.0",
"ecosystem": "pypi"
},
{
"name": "build",
"direct": false,
"version": "1.2.2.post1",
"ecosystem": "pypi"
},
{
"name": "certifi",
"direct": false,
"version": "2024.8.30",
"ecosystem": "pypi"
},
{
"name": "cffi",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "cfgv",
"direct": false,
"version": "3.4.0",
"ecosystem": "pypi"
},
{
"name": "charset-normalizer",
"direct": false,
"version": "3.4.0",
"ecosystem": "pypi"
},
{
"name": "click",
"direct": false,
"version": "8.1.7",
"ecosystem": "pypi"
},
{
"name": "coverage",
"direct": false,
"version": "7.13.0",
"ecosystem": "pypi"
},
{
"name": "coverage",
"direct": false,
"version": "7.6.1",
"ecosystem": "pypi"
},
{
"name": "cryptography",
"direct": false,
"version": "48.0.1",
"ecosystem": "pypi"
},
{
"name": "defusedxml",
"direct": false,
"version": "0.7.1",
"ecosystem": "pypi"
},
{
"name": "distlib",
"direct": false,
"version": "0.3.9",
"ecosystem": "pypi"
},
{
"name": "docutils",
"direct": false,
"version": "0.20.1",
"ecosystem": "pypi"
},
{
"name": "docutils",
"direct": false,
"version": "0.21.2",
"ecosystem": "pypi"
},
{
"name": "exceptiongroup",
"direct": false,
"version": "1.2.2",
"ecosystem": "pypi"
},
{
"name": "execnet",
"direct": false,
"version": "2.1.1",
"ecosystem": "pypi"
},
{
"name": "filelock",
"direct": false,
"version": "3.20.3",
"ecosystem": "pypi"
},
{
"name": "flit",
"direct": false,
"version": "3.11.0",
"ecosystem": "pypi"
},
{
"name": "flit-core",
"direct": false,
"version": "3.11.0",
"ecosystem": "pypi"
},
{
"name": "fonttools",
"direct": false,
"version": "4.61.0",
"ecosystem": "pypi"
},
{
"name": "fpdf2",
"direct": false,
"version": "2.8.1",
"ecosystem": "pypi"
},
{
"name": "identify",
"direct": false,
"version": "2.6.1",
"ecosystem": "pypi"
},
{
"name": "idna",
"direct": false,
"version": "3.15",
"ecosystem": "pypi"
},
{
"name": "imagesize",
"direct": false,
"version": "1.4.1",
"ecosystem": "pypi"
},
{
"name": "importlib-metadata",
"direct": false,
"version": "8.5.0",
"ecosystem": "pypi"
},
{
"name": "iniconfig",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "jinja2",
"direct": false,
"version": "3.1.6",
"ecosystem": "pypi"
},
{
"name": "markdown-it-py",
"direct": false,
"version": "3.0.0",
"ecosystem": "pypi"
},
{
"name": "markupsafe",
"direct": false,
"version": "3.0.1",
"ecosystem": "pypi"
},
{
"name": "mdit-py-plugins",
"direct": false,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "mdurl",
"direct": false,
"version": "0.1.2",
"ecosystem": "pypi"
},
{
"name": "mypy",
"direct": false,
"version": "1.17.0",
"ecosystem": "pypi"
},
{
"name": "mypy-extensions",
"direct": false,
"version": "1.0.0",
"ecosystem": "pypi"
},
{
"name": "myst-parser",
"direct": false,
"version": "4.0.0",
"ecosystem": "pypi"
},
{
"name": "nodeenv",
"direct": false,
"version": "1.9.1",
"ecosystem": "pypi"
},
{
"name": "packaging",
"direct": false,
"version": "24.1",
"ecosystem": "pypi"
},
{
"name": "pathspec",
"direct": false,
"version": "1.0.4",
"ecosystem": "pypi"
},
{
"name": "pillow",
"direct": false,
"version": "12.2.0",
"ecosystem": "pypi"
},
{
"name": "pip-tools",
"direct": false,
"version": "7.4.1",
"ecosystem": "pypi"
},
{
"name": "platformdirs",
"direct": false,
"version": "4.3.6",
"ecosystem": "pypi"
},
{
"name": "pluggy",
"direct": false,
"version": "1.5.0",
"ecosystem": "pypi"
},
{
"name": "pre-commit",
"direct": false,
"version": "3.5.0",
"ecosystem": "pypi"
},
{
"name": "py-cpuinfo",
"direct": false,
"version": "9.0.0",
"ecosystem": "pypi"
},
{
"name": "pycparser",
"direct": false,
"version": "2.22",
"ecosystem": "pypi"
},
{
"name": "pycryptodome",
"direct": false,
"version": "3.23.0",
"ecosystem": "pypi"
},
{
"name": "pygments",
"direct": false,
"version": "2.20.0",
"ecosystem": "pypi"
},
{
"name": "pyproject-hooks",
"direct": false,
"version": "1.2.0",
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": "9.0.3",
"ecosystem": "pypi"
},
{
"name": "pytest-benchmark",
"direct": false,
"version": "5.2.3",
"ecosystem": "pypi"
},
{
"name": "pytest-cov",
"direct": false,
"version": "5.0.0",
"ecosystem": "pypi"
},
{
"name": "pytest-socket",
"direct": false,
"version": "0.7.0",
"ecosystem": "pypi"
},
{
"name": "pytest-timeout",
"direct": false,
"version": "2.3.1",
"ecosystem": "pypi"
},
{
"name": "pytest-xdist",
"direct": false,
"version": "3.6.1",
"ecosystem": "pypi"
},
{
"name": "python-bidi",
"direct": false,
"version": "0.6.10",
"ecosystem": "pypi"
},
{
"name": "pyyaml",
"direct": false,
"version": "6.0.2",
"ecosystem": "pypi"
},
{
"name": "requests",
"direct": false,
"version": "2.33.0",
"ecosystem": "pypi"
},
{
"name": "ruff",
"direct": false,
"version": "0.15.0",
"ecosystem": "pypi"
},
{
"name": "snowballstemmer",
"direct": false,
"version": "2.2.0",
"ecosystem": "pypi"
},
{
"name": "sphinx",
"direct": false,
"version": "8.1.3",
"ecosystem": "pypi"
},
{
"name": "sphinx-rtd-theme",
"direct": false,
"version": "3.0.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-applehelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-devhelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-htmlhelp",
"direct": false,
"version": "2.1.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-jquery",
"direct": false,
"version": "4.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-jsmath",
"direct": false,
"version": "1.0.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-qthelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-serializinghtml",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "tomli",
"direct": false,
"version": "2.0.2",
"ecosystem": "pypi"
},
{
"name": "tomli-w",
"direct": false,
"version": "1.0.0",
"ecosystem": "pypi"
},
{
"name": "typeguard",
"direct": false,
"version": "4.3.0",
"ecosystem": "pypi"
},
{
"name": "types-pyyaml",
"direct": false,
"version": "6.0.12.20250915",
"ecosystem": "pypi"
},
{
"name": "urllib3",
"direct": false,
"version": "2.7.0",
"ecosystem": "pypi"
},
{
"name": "virtualenv",
"direct": false,
"version": "20.36.1",
"ecosystem": "pypi"
},
{
"name": "wheel",
"direct": false,
"version": "0.46.2",
"ecosystem": "pypi"
},
{
"name": "zipp",
"direct": false,
"version": "3.20.2",
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 80,
"direct_count": 3,
"indirect_count": 77
}
},
"maintainership": {
"issues": {
"open_prs": 52,
"merged_prs": 1748,
"open_issues": 97,
"closed_ratio": 0.931,
"closed_issues": 1319,
"closed_unmerged_prs": 323
},
"bus_factor": 3,
"top_contributors": [
{
"type": "User",
"login": "MartinThoma",
"commits": 723,
"avatar_url": "https://avatars.githubusercontent.com/u/1658117?v=4"
},
{
"type": "User",
"login": "stefan6419846",
"commits": 337,
"avatar_url": "https://avatars.githubusercontent.com/u/96178532?v=4"
},
{
"type": "User",
"login": "j-t-1",
"commits": 251,
"avatar_url": "https://avatars.githubusercontent.com/u/120829237?v=4"
},
{
"type": "User",
"login": "pubpub-zz",
"commits": 238,
"avatar_url": "https://avatars.githubusercontent.com/u/4083478?v=4"
},
{
"type": "User",
"login": "mstamy2",
"commits": 201,
"avatar_url": "https://avatars.githubusercontent.com/u/3945030?v=4"
},
{
"type": "User",
"login": "knowah",
"commits": 43,
"avatar_url": "https://avatars.githubusercontent.com/u/1295856?v=4"
},
{
"type": "User",
"login": "MasterOdin",
"commits": 33,
"avatar_url": "https://avatars.githubusercontent.com/u/1845314?v=4"
},
{
"type": "Bot",
"login": "dependabot[bot]",
"commits": 32,
"avatar_url": "https://avatars.githubusercontent.com/in/29110?v=4"
},
{
"type": "User",
"login": "metsw24-max",
"commits": 24,
"avatar_url": "https://avatars.githubusercontent.com/u/269453219?v=4"
},
{
"type": "User",
"login": "switham",
"commits": 20,
"avatar_url": "https://avatars.githubusercontent.com/u/3654045?v=4"
}
],
"contributors_sampled": 100,
"top_contributor_share": 0.334
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"benchmark.yaml",
"create-github-release.yaml",
"gh-pages-check.yaml",
"github-ci.yaml",
"publish-to-pypi.yaml",
"release.yaml",
"title-check.yaml",
"urls-check.yaml",
"zizmor.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 6,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 6,
"reason": "Found 17/28 approved changesets -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 19 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 20 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 3,
"reason": "dependency not pinned by hash detected -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "efc511b91913306087f700984550f8dcedd6860b",
"ran_at": "2026-07-21T03:00:16Z",
"aggregate_score": 8.7,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/py-pdf/pypdf",
"host": "github.com",
"name": "pypdf",
"owner": "py-pdf"
},
"metrics": {
"overall": {
"key": "overall",
"band": "excellent",
"name": "Overall health",
"note": null,
"notes": [],
"value": 87,
"inputs": {
"security": 90,
"vitality": 94,
"community": 82,
"governance": 79,
"engineering": 92
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 94,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"commits_last_year": 348,
"human_commit_share": null,
"days_since_last_push": 20,
"active_weeks_last_year": 48
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 20 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 20
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "48/52 weeks with commits",
"points": 33.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 48
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "348 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 348
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 20 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 100,
"latest_release_tag": "6.14.2",
"releases_from_tags": false,
"days_since_latest_release": 27,
"mean_days_between_releases": 3.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 27 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 27
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~3.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 3.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "no_commit_sample",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 82,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "excellent",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 97,
"inputs": {
"forks": 1601,
"stars": 10123,
"watchers": 142,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "10,123 stars",
"points": 60,
"status": "met",
"details": [
{
"code": "stars",
"params": {
"count": 10123
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "1,601 forks",
"points": 25,
"status": "met",
"details": [
{
"code": "forks",
"params": {
"count": 1601
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "142 watchers",
"points": 11.9,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 142
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 79,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "good",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"bus_factor": 3,
"contributors_sampled": 100,
"top_contributor_share": 0.334
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "3 contributor(s) cover half of all commits",
"points": 36,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 3
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 33% of commits",
"points": 15,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 33
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "100 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 100
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 19 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"merged_prs": 1748,
"open_issues": 97,
"closed_issues": 1319,
"issue_closed_ratio": 0.931,
"closed_unmerged_prs": 323
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "93% of issues closed",
"points": 43.5,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 93
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "1748/2071 decided PRs merged",
"points": 32.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 1748,
"decided": 2071
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 17/28 approved changesets -- score normalized to 6",
"points": 9,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 63,
"inputs": {
"followers": 228,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "py-pdf",
"public_repos": 11,
"account_age_days": 1569
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "228 followers of py-pdf",
"points": 17,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 228,
"login": "py-pdf"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "11 public repos, account ~4 yr old",
"points": 16.4,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 11
}
},
{
"code": "account_age_years",
"params": {
"years": 4
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"pypdf"
],
"ecosystems": "pypi",
"any_deprecated": false,
"min_days_since_publish": 27
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on pypi",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "pypi"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 27 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 27
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "108 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 108
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 92,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 94,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "9 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 9
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 16,
"status": "met",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 9.6,
"status": "met",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"pypdf2",
"pdf",
"python",
"pdf-parser",
"pdf-parsing",
"pdf-manipulation",
"pdf-documents",
"help-wanted"
],
"has_wiki": false,
"homepage": "https://pypdf.readthedocs.io/en/latest/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://pypdf.readthedocs.io/en/latest/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "8 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 8
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "excellent",
"name": "Security",
"value": 90,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "excellent",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 87,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 8.7
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 17/28 approved changesets -- score normalized to 6",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 19 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 20 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 79 resolved dependencies against OSV; 1 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 79
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 1
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 22,
"affected_packages": 2,
"assessed_packages": 79,
"unassessed_packages": 1,
"affected_by_severity": "critical 1, high 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 79,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 11
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 51,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "critical",
"name": "Agent context & guidance",
"note": "Excluded from scoring (no data or not applicable): Legible commit history. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"legible_commit_history"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"has_llms_txt": false,
"legible_history_share": null,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): Demonstrated agent practice. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"demonstrated_agent_practice"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 78,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [
"Makefile",
"docs/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"pypdf/py.typed"
],
"agent_commit_share": null,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, docs/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, docs/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 11,
"status": "met",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "pypdf/py.typed",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "pypdf/py.typed"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "dependency automation configured, none observed in the sampled commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "dependency_bot_config_only",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "good",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 447213,
"source_files_sampled": 104,
"oversized_source_files": 8
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python with type-check config (pypdf/py.typed)",
"points": 27,
"status": "partial",
"details": [
{
"code": "typecheck_config_language",
"params": {
"files": "pypdf/py.typed",
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "8/104 source files over 60KB",
"points": 50.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 104,
"oversized": 8
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [],
"report_type": "repository",
"generated_at": "2026-07-21T03:00:45.384700Z",
"schema_version": "0.16.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/py-pdf/pypdf.svg",
"full_name": "py-pdf/pypdf",
"license_state": "custom",
"license_spdx": null
}Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.
Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.16.0 — повна методологія · вікі метрик.
Як окремий результат виглядає на тлі всього реєстру: сукупна статистика — PyPI.