0

/ 100

GradeC

Solid engineering. The biggest lever is CI. It has gone quiet lately, though.

Top 35% of 5,156 graded repos

Firmware for Passport v1

Top fixes

Highest-impact changes first, ranked by point weight

12 to address
  1. 1
    Tests18pt

    Wire your tests to a documented command (e.g. a test script in your build config) so the suite is reproducible.

  2. 2
    CI/CD14pt

    Add a step like `run: npm test`, `run: pytest`, or `run: tox` to your workflow file.

  3. 3
    CI/CD14pt

    Add `pull_request:` to the workflow `on:` triggers.

  4. 4
    CI/CD14pt

    Add a lint step to catch style issues automatically.

Working through the fixes? Let every push regrade itself.

The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.

Install the GitHub App

Scorecard

Every check, grouped by category and sorted worst-first

Documentation

90

Contributing guide5pt77

CONTRIBUTING guide found.

README12pt90

README is present.

Install and run instructions9pt90

README documents how to install the project.

License6pt100

A license file is present.

Engineering

75

CI/CD14pt40

CI is configured (.github/workflows/validate_and_build.yaml).

Tests18pt80

Test files detected (drivers/display/lcd160cr_test.py).

Reproducibility6pt92

Lockfile present (requirements.txt). Installs are reproducible.

Linting and formatting5pt100

Linter or formatter configured (ports/stm32/boards/Passport/trezor-firmware/.editorconfig).

Issue and PR templates6pt100

Issue or PR templates present.

Project health

69

Activity5pt5

No pushes in over 2 years. Looks unmaintained (−95 pts).

A recent commit signals the project is alive and worth using.

Housekeeping3pt60

.gitignore present.

Dependency manifest6pt100

Dependency manifest found (requirements.txt).

Repository metadata5pt100

Repository has a description.

Repository health signals

Activity, community, and responsiveness at scan time

Activity

  • -
    Commits (30d / 90d)
  • 17
    Forks
  • 11
    Releaseslatest 4y ago

Community

  • 25% - Weak
    Community health
  • 1 bus factorlow
    author own >50% of commits
  • 53
    Watchers

Responsiveness

  • 1d 21h
    Median issue response
  • 2h
    Median PR merge time
  • 10
    Open issues
Repository files31 root entries
  • .githooks
  • .github
    Good: CI is configured (.github/workflows/validate_and_build.yaml).
  • .reuse
  • docs
    Good: A license file is present.
  • drivers
    Good: Test files detected (drivers/display/lcd160cr_test.py).
  • examples
  • extmod
  • lib
    Good: CONTRIBUTING guide found.
    Issue: CONTRIBUTING guide contents could not be read (−28 pts vs a readable file).Fix: Move the file to the repo root or docs/CONTRIBUTING.md so its setup, style, test, and PR sections can be graded.
    Good: Code of conduct present.
    Good: Issue or PR templates present.
  • LICENSES
  • logo
  • mpy-cross
  • ports
    Good: Linter or formatter configured (ports/stm32/boards/Passport/trezor-firmware/.editorconfig).
    Good: Dependabot is configured. Dependencies update automatically.
    Issue: Build artifacts or local files may be committed (ports/stm32/boards/Passport/graphics/.DS_Store) (−40 pts).Fix: Remove them and add to .gitignore.
  • py
  • SECURITY
    Good: Security policy present.
  • tests
  • tools
  • .dockerignore
  • .gitattributes
  • .gitignore
    Good: .gitignore present.
  • .gitmodules
  • .travis.yml
  • DEVELOPMENT.md
  • Dockerfile
    Good: Environment pinned via Dockerfile.
  • Justfile
  • MP-ACKNOWLEDGEMENTS
  • MP-CODECONVENTIONS.md
  • MP-CODEOFCONDUCT.md
  • MP-CONTRIBUTING.md
  • MP-README.md
    Good: README is present.
    Good: README is well structured with multiple sections.
    Good: README includes screenshots or visuals. Great for first impressions.
    Good: README has code examples.
    Good: README links to a live demo or deployed app.
    Issue: No status badges in the README (−10 pts).Fix: Add CI/build status badges from shields.io or your CI provider to signal project health.
    Good: README documents how to install the project.
    Good: README documents how to run the project.
  • README.md
  • requirements.txt
    Good: Lockfile present (requirements.txt). Installs are reproducible.
    Good: Dependency manifest found (requirements.txt).
RepoGrade badge preview

Add this badge to your README

It updates automatically each time the repo is re-graded.

[![RepoGrade](https://www.repo-grade.com/api/badge/foundation-devices/passport-firmware)](https://www.repo-grade.com/report/foundation-devices/passport-firmware)

More graded C repos