Good shape overall. A few tweaks would push it into the top tier.
Tracking OpenClaw CVEs
Documentation
74
No CONTRIBUTING.md found (−47 pts base + up to −53 pts more for content).
→ Add a CONTRIBUTING.md telling newcomers how to get involved. Include setup, code style, test, and PR instructions.
README is present.
README documents how to install the project.
Licensed under MIT.
Engineering
62
No linter or formatter config found.
→ Add a linter config such as .eslintrc.json, .prettierrc, ruff.toml, or .golangci.yml to enforce consistent code style.
No issue or PR templates found (−100 pts).
→ Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
Lockfile present (requirements.txt). Installs are reproducible.
Test files detected (tests).
CI is configured (.github/workflows/tests.yml).
Project health
100
Dependency manifest found (requirements.txt).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- —Commits (30d / 90d)
- 8Forks
- 0Releases
Community
- —Community health
- —authors own >50% of commits
- 165Watchers
Responsiveness
- —Median issue response
- —Median PR merge time
- 1Open issues
Repository files17 root entries
- .githubGood: CI is configured (.github/workflows/tests.yml).
- cve-records
- templates
- testsGood: Test files detected (tests).
- .gitignoreGood: .gitignore present.
- ADVISORIES.md
- CHANGELOG.md
- cve-pipeline-status.json
- cves.json
- ghsa-advisories-full.json
- ghsa-advisories.json
- LICENSEGood: Licensed under MIT.
- README.mdGood: README is present.Good: README is well structured with multiple sections.Issue: No screenshots or images in the README (−20 pts).Fix: Add a GIF, screenshot, or logo image. It is the fastest way to show what your project does.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- repo-only-ghsas.json
- requirements.txtGood: Lockfile present (requirements.txt). Installs are reproducible.Good: Dependency manifest found (requirements.txt).
- SECURITY.mdGood: Security policy present.
- update_readme.py