89
/ 100
Polished and well engineered. Punching above its star count.
Open source compliance automation for SOC 2, GDPR, ISO27001, NIST 800-53, and more
Top fixes
Highest-impact changes first, ranked by point weight
- 1CI/CD14pt
Add a step like `run: npm test`, `run: pytest`, or `run: tox` to your workflow file.
- 2CI/CD14pt
Add `pull_request:` to the workflow `on:` triggers.
- 3CI/CD14pt
Add a lint step to catch style issues automatically.
- 4CI/CD14pt
Add `tsc --noEmit`, `mypy`, or `cargo check` to catch type errors before they merge.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
96
CONTRIBUTING guide found.
README is present.
README documents how to install the project.
Licensed under Apache-2.0.
Engineering
81
CI is configured (.github/workflows/labeler.yaml).
Lockfile present (go.sum). Installs are reproducible.
Test files detected (.buildkite/tests).
Formatting enforced (.golangci.yaml).
Issue or PR templates present.
Project health
100
Dependency manifest found (go.mod).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- -Commits (30d / 90d)
- 48Forks
- 574Releaseslatest 1y ago
Community
- 100% - GoodCommunity health
- -authors own >50% of commits
- 264Watchers
Responsiveness
- 12hMedian issue response
- <1hMedian PR merge time
- 27Open issues
Repository files30 root entries
- .buildkiteGood: Test files detected (.buildkite/tests).
- .githubGood: CONTRIBUTING guide found.Issue: CONTRIBUTING guide contents could not be read (−28 pts vs a readable file).Fix: Move the file to the repo root or docs/CONTRIBUTING.md so its setup, style, test, and PR sections can be graded.Good: CI is configured (.github/workflows/labeler.yaml).Good: Issue or PR templates present.
- .task
- assets
- cli
- cmd
- common
- config
- db
- dockerGood: Environment pinned via docker/Dockerfile.
- fga
- internal
- jsonschema
- pkg
- .gitattributes
- .gitignoreGood: .gitignore present.
- .golangci.yamlGood: Formatting enforced (.golangci.yaml).
- .goreleaser.yaml
- .pre-commit-config.yaml
- .typos.toml
- .yamlfmt
- go.modGood: Dependency manifest found (go.mod).
- go.sumGood: Lockfile present (go.sum). Installs are reproducible.
- go.work
- LICENSEGood: Licensed under Apache-2.0.
- main.go
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- renovate.json
- sonar-project.properties
- Taskfile.yaml
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/theopenlane/core)