80
/ 100
Good shape overall. A few tweaks would push it into the top tier.
Code analyzer for C# and VB.NET projects
Top fixes
Highest-impact changes first, ranked by point weight
- 1Tests18pt
Wire your tests to a documented command (e.g. a test script in your build config) so the suite is reproducible.
- 2CI/CD14pt
Add a step like `run: npm test`, `run: pytest`, or `run: tox` to your workflow file.
- 3CI/CD14pt
Add `pull_request:` to the workflow `on:` triggers.
- 4CI/CD14pt
Add a lint step to catch style issues automatically.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
82
No CONTRIBUTING.md found (−47 pts base + up to −53 pts more for content).
→ Add a CONTRIBUTING.md telling newcomers how to get involved. Include setup, code style, test, and PR instructions.
README documents how to install the project.
README is present.
Licensed under Other.
Engineering
72
CI is configured (.github/workflows/LabelIssue.yml).
Lockfile present (analyzers/src/RuleDescriptorGenerator/packages.lock.json). Installs are reproducible.
Test files detected (analyzers/tests).
.NET formatting configured (.editorconfig).
Issue or PR templates present.
Project health
100
Dependency manifest found (pom.xml).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- -Commits (30d / 90d)
- 242Forks
- 194Releaseslatest 10y ago
Community
- 62% - FairCommunity health
- 6 bus factorauthors own >50% of commits
- 909Watchers
Responsiveness
- 10d 23hMedian issue response
- <1hMedian PR merge time
- 243Open issues
Repository files21 root entries
- .githubGood: CI is configured (.github/workflows/LabelIssue.yml).Good: Issue or PR templates present.
- analyzersGood: Test files detected (analyzers/tests).Good: Lockfile present (analyzers/src/RuleDescriptorGenerator/packages.lock.json). Installs are reproducible.
- docs
- scripts
- sonar-csharp-core
- sonar-csharp-plugin
- sonar-dotnet-core
- sonar-vbnet-core
- sonar-vbnet-plugin
- .editorconfigGood: .NET formatting configured (.editorconfig).
- .gitattributes
- .gitignoreGood: .gitignore present.
- .globalconfig
- .mcp.json
- azure-pipelines.yml
- global.json
- LICENSE.txtGood: Licensed under Other.
- NOTICE.txt
- pom.xmlGood: Dependency manifest found (pom.xml).
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- SECURITY.mdGood: Security policy present.
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/sonarsource/sonar-dotnet)