0

/ 100

GradeB

Polished work that hasn't found its audience yet.

Top 16% of 5,156 graded repos

Microsoft Authentication Library (MSAL) for JS

Top fixes

Highest-impact changes first, ranked by point weight

12 to address
  1. 1
    README12pt

    Show a quick-start snippet so contributors can see what using your project looks like.

  2. 2
    README12pt

    Add CI/build status badges from shields.io or your CI provider to signal project health.

  3. 3
    Install and run instructions9pt

    Add a .env.example listing all required environment variables so contributors know what to set up.

  4. 4
    Reproducibility6pt

    Add a Dockerfile, .nvmrc, or .python-version to pin the runtime version and make the environment reproducible.

Working through the fixes? Let every push regrade itself.

The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.

Install the GitHub App

Scorecard

Every check, grouped by category and sorted worst-first

Documentation

87

README12pt75

README is present.

Install and run instructions9pt90

README documents how to install the project.

Contributing guide5pt92

Contributing guide is detailed and thorough.

License6pt100

Licensed under MIT.

Engineering

99

Reproducibility6pt90

Lockfile present (package-lock.json). Installs are reproducible.

Tests18pt100

Test files detected (extensions/msal-node-extensions/jest.config.js).

CI/CD14pt100

CI is configured (.github/workflows/build-test-pr.yml).

Linting and formatting5pt100

Linter or formatter configured (.editorconfig).

Issue and PR templates6pt100

Issue or PR templates present.

Project health

61

Activity5pt5

No pushes in over 2 years. Looks unmaintained (−95 pts).

A recent commit signals the project is alive and worth using.

Housekeeping3pt60

.gitignore present.

Dependency manifest6pt75

Dependency manifest found (package.json).

Repository metadata5pt100

Repository has a description.

Repository health signals

Activity, community, and responsiveness at scan time

Activity

  • -
    Commits (30d / 90d)
  • 0
    Forks
  • 0
    Releases

Community

  • -
    Community health
  • -
    authors own >50% of commits
  • 0
    Watchers

Responsiveness

  • -
    Median issue response
  • -
    Median PR merge time
  • 0
    Open issues
Repository files36 root entries
  • .github
    Good: CI is configured (.github/workflows/build-test-pr.yml).
    Good: Dependabot covers 8 ecosystems (npm, npm, npm, npm, npm, npm, npm, npm). Dependencies stay current.
    Good: Issue or PR templates present.
  • .vscode
  • build
  • change
  • docs
  • experimental
  • extensions
    Good: Test files detected (extensions/msal-node-extensions/jest.config.js).
  • lib
  • maintenance
  • release-scripts
  • samples
    Issue: Build artifacts or local files may be committed (samples/msal-core-samples/react-sample-app/.env) (−40 pts).Fix: Remove them and add to .gitignore.
  • .babelrc
  • .beachballrc
  • .browserslistrc
  • .editorconfig
    Good: Linter or formatter configured (.editorconfig).
  • .eslintignore
  • .eslintrc.json
  • .gitattributes
  • .gitignore
    Good: .gitignore present.
  • .nojekyll
  • .npmrc
  • 1p-sync.yml
  • azure-pipelines.yml
  • codecov.yml
  • CODEOWNERS
  • contributing.md
    Good: Contributing guide is detailed and thorough.
    Good: Contributing guide includes setup/install instructions.
    Issue: Contributing guide lacks a code style section (−8 pts).Fix: Describe your linting/formatting rules and how to run them.
    Good: Contributing guide explains how to run tests.
    Good: Contributing guide describes the PR/review workflow.
    Good: Contributing guide includes code examples.
  • lerna.json
  • LICENSE
    Good: Licensed under MIT.
  • package-lock.json
    Good: Lockfile present (package-lock.json). Installs are reproducible.
  • package.json
    Good: Dependency manifest found (package.json).
  • README.md
    Good: README is present.
    Good: README is well structured with multiple sections.
    Good: README includes screenshots or visuals. Great for first impressions.
    Issue: README has no code examples (−15 pts).Fix: Show a quick-start snippet so contributors can see what using your project looks like.
    Good: README links to a live demo or deployed app.
    Issue: No status badges in the README (−10 pts).Fix: Add CI/build status badges from shields.io or your CI provider to signal project health.
    Good: README documents how to install the project.
    Good: README documents how to run the project.
  • roadmap.md
  • SECURITY.md
    Good: Security policy present.
  • tsconfig.json
  • typedoc.json
  • yarn.lock
RepoGrade badge preview

Add this badge to your README

It updates automatically each time the repo is re-graded.

[![RepoGrade](https://www.repo-grade.com/api/badge/karin-at-msft/microsoft-authentication-library-for-js)](https://www.repo-grade.com/report/karin-at-msft/microsoft-authentication-library-for-js)

More graded TypeScript repos