ALICE (Automated Learning and Intelligence for Causation and Economics) is a Microsoft Research project aimed at applying Artificial Intelligence concepts to economic decision making. One of its goals is to build a toolkit that combines state-of-the-art machine learning techniques with econometrics in order to bring automation to complex causal inference problems. To date, the ALICE Python SDK (econml) implements orthogonal machine learning algorithms such as the double machine learning work of Chernozhukov et al. This toolkit is designed to measure the causal effect of some treatment variable(s) t on an outcome variable y, controlling for a set of features x.
py-why/EconML 的健康指数为 100 分中的 89 分,处于「优秀」区间。 其得分最高的类别是Engineering Quality(96/100),最低的是AI Readiness(47/100)。 最近一次更新在 1 天前。 近期的大部分工作由 1 位贡献者完成。
指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均,再依据公开记录的分布进行校准,使各等级具有百分位含义;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 34(存在风险)的上限。
每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。
加权总体分 75 经校准后在公布的指数量表上为 89(记录校准 2026-08-02)。
| 注册表 | 软件包 | 版本 | 月下载量 | 版本数 | 最近发布 | 标签 |
|---|---|---|---|---|---|---|
| PyPI | econml | 0.17.0 | - | 35 | 12 天前 | treatment-effect |
项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?
| 36/36 | 推送新近度 — 最近一次推送于 1 天前 |
| 9.7/36 | 提交节奏 — 52 周中有 14 周有提交 |
| 14/18 | 提交量 — 最近一年 35 次提交 |
| 10/10 | OpenSSF Scorecard:Maintained — 19 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10 |
| commits_last_year | 35 |
| human_commit_share | 0.93 |
| days_since_last_push | 1 |
| active_weeks_last_year | 14 |
| 27/27 | 有发布版本 — 已发布 35 个发布版本 |
| 36/36 | 发布时效 — 最近一次发布版本于 8 天前 |
| 12.6/27 | 发布节奏 — 约每 201.8 天发布一次 |
| 0/10 | OpenSSF Scorecard:Signed-Releases — 无数据 |
| releases_count | 35 |
| latest_release_tag | v0.17.0 |
| releases_from_tags | 否 |
| days_since_latest_release | 8 |
| mean_days_between_releases | 201.8 |
项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?
| 59.6/60 | 星标 — 4,752 个星标 |
| 24.3/25 | 复刻 — 821 个复刻 |
| 10.7/15 | 关注者 — 85 位关注者 |
| forks | 821 |
| stars | 4,752 |
| watchers | 85 |
| growth_state | unverified |
| growth_factor_pct | 100 |
| growth_unverified_reason | no_history |
| 22.5/22.5 | README |
| 16.9/22.5 | 许可证 — 存在许可证文件,但不是可识别的许可证 |
| 0/18 | CONTRIBUTING 指南 |
| 0/13.5 | 行为准则 |
| 0/7.2 | 议题模板 |
| 0/6.3 | PR 模板 |
| has_readme | 是 |
| has_license | 是 |
| readme_badges | 4 |
| has_contributing | 否 |
| has_issue_template | 否 |
| has_code_of_conduct | 否 |
| readme_badge_services | github.com, shields.io |
| has_pull_request_template | 否 |
项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?
| 9/54 | 巴士系数 — 1 位贡献者贡献了半数提交 |
| 7.2/22.5 | 提交分布 — 头号贡献者编写了 68% 的提交 |
| 13.5/13.5 | 贡献者广度 — 49 位贡献者 |
| 10/10 | OpenSSF Scorecard:Contributors — project has 9 contributing companies or organizations |
| bus_factor | 1 |
| contributors_sampled | 49 |
| top_contributor_share | 0.678 |
| 16.5/42 | 议题解决 — 39% 的议题已关闭 |
| 25.4/30 | PR 接受 — 已裁定的 PR 中 331/391 已合并 |
| 0/13 | Newcomer PR acceptance — 30 天内首次贡献者的 PR 已合并 0/2 |
| 15/15 | OpenSSF Scorecard:Code-Review — all changesets reviewed |
| merged_prs | 331 |
| open_issues | 380 |
| closed_issues | 245 |
| prs_merged_7d | 0 |
| prs_decided_7d | 1 |
| prs_merged_30d | 6 |
| prs_decided_30d | 9 |
| issue_closed_ratio | 0.392 |
| closed_unmerged_prs | 60 |
| first_time_authors_30d | 2 |
| first_time_prs_merged_30d | 0 |
| first_time_prs_decided_30d | 2 |
| 30/30 | 所有权背书 — 组织持有 |
| 0/20 | 已验证域名 — 未读取该组织的域名验证状态 |
| 21.7/25 | 所有者影响力 — py-why 有 1,055 位关注者 |
| 17.4/25 | 既往记录 — 14 个公开仓库,账户约 4 年 |
| followers | 1,055 |
| owner_type | Organization |
| is_verified | — |
| owner_login | py-why |
| public_repos | 14 |
| account_age_days | 1,617 |
| 25/25 | 已发布且可解析 — pypi 上有 1 个软件包 |
| 35/35 | 发布时效 — 最近一次发布于 12 天前 |
| 20/20 | 版本历史 — 35 个已发布版本 |
| 20/20 | 未被弃用 — 活跃,未被弃用或撤回 |
| packages | econml |
| ecosystems | pypi |
| any_deprecated | 否 |
| min_days_since_publish | 12 |
基础的工程与文档实践是否到位?
| 24/24 | CI 工作流 — 3 个工作流 |
| 24/24 | 存在测试 |
| 16/16 | Linter 配置 |
| 9.6/9.6 | Pre-commit 钩子 |
| 0/6.4 | .editorconfig |
| 20/20 | OpenSSF Scorecard:CI-Tests — 16 out of 16 merged PRs checked by a CI test -- score normalized to 10 |
| has_ci | 是 |
| has_tests | 是 |
| has_editorconfig | 否 |
| has_linter_config | 是 |
| has_precommit_config | 是 |
| 30/30 | README |
| 25/25 | 文档目录 |
| 15/15 | 文档 / 主页站点 — https://www.microsoft.com/en-us/research/project/alice/ |
| 10/10 | 仓库描述 |
| 10/10 | 主题标签 — 6 个主题标签 |
| 10/10 | Wiki |
| topics | machine-learning, economics, causal-inference, causality, econometrics, treatment-effects |
| has_wiki | 是 |
| homepage | https://www.microsoft.com/en-us/research/project/alice/ |
| docs_site | https://www.microsoft.com/en-us/research/project/alice/ |
| has_readme | 是 |
| has_docs_dir | 是 |
| has_description | 是 |
可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?
| 7.5/7.5 | Binary-Artifacts — no binaries found in the repo |
| 6/7.5 | Branch-Protection — branch protection is not maximal on development and all release branches |
| 2.5/2.5 | CI-Tests — 16 out of 16 merged PRs checked by a CI test -- score normalized to 10 |
| 0/2.5 | CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected |
| 7.5/7.5 | Code-Review — all changesets reviewed |
| 2.5/2.5 | Contributors — project has 9 contributing companies or organizations |
| 10/10 | Dangerous-Workflow — no dangerous workflow patterns detected |
| 0/7.5 | Dependency-Update-Tool — no update tool detected |
| 0/5 | Fuzzing — project is not fuzzed |
| 2.2/2.5 | 许可证 — license file detected |
| 7.5/7.5 | Maintained — 19 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10 |
| 5/5 | Packaging — packaging workflow detected |
| 0/5 | Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| 0/5 | SAST — SAST tool is not run on all commits -- score normalized to 0 |
| 5/5 | Security-Policy — security policy file detected |
| 0/7.5 | Signed-Releases — 无数据 |
| 0/7.5 | Token-Permissions — detected GitHub workflow tokens with excessive permissions |
| 7.5/7.5 | Vulnerabilities — 0 existing vulnerabilities detected |
| source | openssf_scorecard |
| checks_evaluated | 17 |
| scorecard_version | v5.5.0 |
| checks_inconclusive | 1 |
| scorecard_aggregate | 6.5 |
| 35/35 | 直接依赖不含已知公告 — 没有直接依赖携带已知公告 |
| 25/25 | 间接依赖不含已知公告 — 没有间接依赖携带已知公告 |
| 0/40 | 没有长期未处理的公告 — 没有公告带有发布日期 |
| source | osv |
| advisories | 0 |
| affected_packages | 0 |
| assessed_packages | 20 |
| unassessed_packages | 0 |
| affected_by_severity | none |
| direct_affected_packages | 0 |
该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?权重刻意设小(4%):代理工具链是一项真实的维护信号,但完全不具备的仓库仍可达到 100/100。
| 0/45 | 代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则 |
| 0/15 | 机器可读文档(llms.txt) |
| 24.7/40 | 可读的提交历史 — 93 次人类提交中有 43 次说明了意图(结构化标题或解释性正文) |
| has_llms_txt | 否 |
| llms_txt_url | — |
| legible_history_share | 0.462 |
| agent_instruction_files | — |
| agent_instruction_max_bytes | — |
| 0/18 | 一条命令的引导启动 |
| 22/22 | 自动化测试 |
| 11/11 | Lint / 格式化配置 |
| 0/11 | 静态类型检查 |
| 0/10 | 可复现环境 |
| 10/10 | 已体现的代理实践 — 最近 100 次提交中有 15 次由代理编写或署名代理 |
| 0/8 | 自动化维护 — 未观察到自动依赖更新 |
| 0/10 | OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| has_nix | 否 |
| has_tests | 是 |
| lockfiles | — |
| has_dockerfile | 否 |
| typed_language | 否 |
| bootstrap_files | — |
| has_devcontainer | 否 |
| has_linter_config | 是 |
| typecheck_configs | — |
| agent_commit_share | 0.15 |
| toolchain_manifests | — |
| dependency_bot_commit_share | 0 |
| 0/45 | 可类型检查的代码 — Jupyter Notebook,未配置类型检查 |
| 50.3/55 | 可控的文件大小 — 采样的 139 个源文件中有 12 个超过 60KB |
| primary_language | Jupyter Notebook |
| largest_source_bytes | 144,560 |
| source_files_sampled | 139 |
| oversized_source_files | 12 |
| 0/40 | API 模式(OpenAPI/GraphQL/proto) — 不适用于此类软件 |
| 0/20 | MCP 服务器 — 不适用于此类软件 |
| 40/40 | 可运行示例 — notebooks |
| example_dirs | notebooks |
| has_mcp_signal | 否 |
| api_schema_files | — |
| interfaces_expected_of | — |
每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。
每个点涵盖 8 天。
来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。
| 10 | Binary-Artifacts | no binaries found in the repo |
| 8 | Branch-Protection | branch protection is not maximal on development and all release branches |
| 10 | CI-Tests | 16 out of 16 merged PRs checked by a CI test -- score normalized to 10 |
| 0 | CII-Best-Practices | no effort to earn an OpenSSF best practices badge detected |
| 10 | Code-Review | all changesets reviewed |
| 10 | Contributors | project has 9 contributing companies or organizations |
| 10 | Dangerous-Workflow | no dangerous workflow patterns detected |
| 0 | Dependency-Update-Tool | no update tool detected |
| 0 | Fuzzing | project is not fuzzed |
| 9 | License | license file detected |
| 10 | Maintained | 19 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10 |
| 10 | Packaging | packaging workflow detected |
| 0 | Pinned-Dependencies | dependency not pinned by hash detected -- score normalized to 0 |
| 0 | SAST | SAST tool is not run on all commits -- score normalized to 0 |
| 10 | Security-Policy | security policy file detected |
| 不适用 | Signed-Releases | no releases found |
| 0 | Token-Permissions | detected GitHub workflow tokens with excessive permissions |
| 10 | Vulnerabilities | 0 existing vulnerabilities detected |
| 注册表 | 软件包 | 版本约束 | 清单文件 |
|---|---|---|---|
| PyPI | numpy | >= 2.0.2 | pyproject.toml |
| PyPI | numba | >= 0.60.0 | pyproject.toml |
| PyPI | scipy | >= 1.13.1 | pyproject.toml |
| PyPI | scikit-learn | >= 1.6.0, < 1.10 | pyproject.toml |
| PyPI | sparse | >= 0.15.4 | pyproject.toml |
| PyPI | joblib | >= 1.4.2 | pyproject.toml |
| PyPI | statsmodels | >= 0.14.4 | pyproject.toml |
| PyPI | pandas | >= 2.2.3 | pyproject.toml |
| PyPI | shap | >= 0.46.0 | pyproject.toml |
| PyPI | lightgbm | >= 4.5.0 | pyproject.toml |
| PyPI | packaging | >= 24.2 | pyproject.toml |
来自 GitHub 依赖图的完整解析依赖集合:11 个直接依赖与 7 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。
| 注册表 | 软件包 | 版本 | 关系 |
|---|---|---|---|
| PyPI | joblib | — | 直接 |
| PyPI | lightgbm | — | 直接 |
| PyPI | numba | — | 直接 |
| PyPI | numpy | — | 直接 |
| PyPI | packaging | — | 直接 |
| PyPI | pandas | — | 直接 |
| PyPI | scikit-learn | — | 直接 |
| PyPI | scipy | — | 直接 |
| PyPI | shap | — | 直接 |
| PyPI | sparse | — | 直接 |
| PyPI | statsmodels | — | 直接 |
| PyPI | cython | — | 间接 |
| PyPI | dowhy | — | 间接 |
| PyPI | graphviz | — | 间接 |
| PyPI | matplotlib | — | 间接 |
| PyPI | ray | — | 间接 |
| PyPI | setuptools | — | 间接 |
| PyPI | wheel | — | 间接 |
安装 pypi:econml@0.17.0 会引入 20 个包(直接与传递):其中 0 个存在已知公告,0 个为直接依赖。
没有已知公告影响已评估的依赖。
公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。
发现这份报告有不准确之处,或有想法要分享?错误的测量、未识别的工具、建议、疑问——都欢迎提出。每条消息都会被阅读并得到回复。