77
/ 100
Good shape overall. A few tweaks would push it into the top tier.
Attestation and Secret Delivery Components
Top fixes
Highest-impact changes first, ranked by point weight
- 1CI/CD14pt
Add a lint step to catch style issues automatically.
- 2CI/CD14pt
Add `tsc --noEmit`, `mypy`, or `cargo check` to catch type errors before they merge.
- 3CI/CD14pt
Upload coverage to Codecov, Coveralls, or report it with `--coverage` flags.
- 4Install and run instructions9pt
Add a section showing how to start or use the project.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
69
No CONTRIBUTING.md found (−47 pts base + up to −53 pts more for content).
→ Add a CONTRIBUTING.md telling newcomers how to get involved. Include setup, code style, test, and PR instructions.
README documents how to install the project.
README is present.
Licensed under Apache-2.0.
Engineering
73
No Rust linting or formatting enforced.
→ Add `cargo clippy -- -D warnings` and `cargo fmt --check` as CI steps, and optionally a rustfmt.toml for project-specific style rules.
No issue or PR templates found (−100 pts).
→ Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
CI is configured (.github/workflows/build-and-push-staged-images.yml).
Test files detected (attestation-service/tests).
Lockfile present (Cargo.lock). Installs are reproducible.
Project health
100
Dependency manifest found (Cargo.toml).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- -Commits (30d / 90d)
- 158Forks
- 17Releaseslatest 1y ago
Community
- 75% - GoodCommunity health
- 3 bus factorauthors own >50% of commits
- 166Watchers
Responsiveness
- 3d 11hMedian issue response
- 1d 3hMedian PR merge time
- 123Open issues
Repository files25 root entries
- .devcontainer
- .githubGood: CI is configured (.github/workflows/build-and-push-staged-images.yml).Good: Dependabot covers 3 ecosystems (devcontainers, cargo, github-actions). Dependencies stay current.
- attestation-serviceGood: Test files detected (attestation-service/tests).Good: Environment pinned via attestation-service/docker/as-grpc/Dockerfile.
- deployment
- deps
- hack
- integration-tests
- kbs
- protos
- rvps
- tools
- .dockerignore
- .gitignoreGood: .gitignore present.
- .lycheeignore
- AGENTS.md
- Cargo.lockGood: Lockfile present (Cargo.lock). Installs are reproducible.
- Cargo.tomlGood: Dependency manifest found (Cargo.toml).
- CODEOWNERS
- DEVELOPMENT.md
- docker-compose.yml
- LICENSEGood: Licensed under Apache-2.0.
- Makefile
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Issue: No run or usage instructions found (−45 pts).Fix: Add a section showing how to start or use the project.
- release-guide.md
- rust-toolchain.toml
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/confidential-containers/trustee)