0
/ 100
Polished and well engineered. Punching above its star count.
RFC3161 Timestamp Authority
Top fixes
Highest-impact changes first, ranked by point weight
- 1Install and run instructions9pt
Add a .env.example listing all required environment variables so contributors know what to set up.
- 2Issue and PR templates6pt
Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
- 3Issue and PR templates6pt
A SECURITY.md explains how to responsibly disclose vulnerabilities. Worth adding once the project has real users.
- 4Contributing guide5pt
Add a CONTRIBUTING.md telling newcomers how to get involved. Include setup, code style, test, and PR instructions.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
82
No CONTRIBUTING.md found (−47 pts base + up to −53 pts more for content).
→ Add a CONTRIBUTING.md telling newcomers how to get involved. Include setup, code style, test, and PR instructions.
README documents how to install the project.
README is present.
Licensed under Apache-2.0.
Engineering
88
No issue or PR templates found (−100 pts).
→ Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
Test files detected (cmd/timestamp-cli/app/pflags_test.go).
CI is configured (.github/workflows/build-snapshot.yaml).
Formatting enforced (.golangci.yml).
Lockfile present (go.sum). Installs are reproducible.
Project health
100
Dependency manifest found (go.mod).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- -Commits (30d / 90d)
- 60Forks
- 31Releaseslatest 3y ago
Community
- -Community health
- -authors own >50% of commits
- 136Watchers
Responsiveness
- 11d 13hMedian issue response
- 3d 24hMedian PR merge time
- 9Open issues
Repository files25 root entries
- .githubGood: CI is configured (.github/workflows/build-snapshot.yaml).Good: Dependabot covers 4 ecosystems (gomod, gomod, github-actions, docker). Dependencies stay current.
- cmdGood: Test files detected (cmd/timestamp-cli/app/pflags_test.go).
- docs
- hack
- pkg
- release
- test
- .gitignoreGood: .gitignore present.
- .golangci.ymlGood: Formatting enforced (.golangci.yml).
- .goreleaser.yml
- .ko.yaml
- CHANGELOG.md
- CODE_OF_CONDUCT.mdGood: Code of conduct present.
- codecov.yml
- CODEOWNERS
- CONTRIBUTORS.md
- COPYRIGHT.txt
- docker-compose.yml
- DockerfileGood: Environment pinned via Dockerfile.
- go.modGood: Dependency manifest found (go.mod).
- go.sumGood: Lockfile present (go.sum). Installs are reproducible.
- LICENSEGood: Licensed under Apache-2.0.
- Makefile
- openapi.yaml
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/sigstore/timestamp-authority)