Dependency health score
Each direct dependency gets a score from 0 to 100 built from six categories. A category whose data isn't available (for example, no linked GitHub repository) is left out and the others are re-weighted, rather than guessing.
Categories
| Category | Weight | Measures |
|---|---|---|
| Maintenance | 25% | Days since the latest release or push to the repository, whichever is newer |
| Bus factor | 20% | How many contributors wrote half of all commits |
| Community | 15% | GitHub stars |
| Adoption | 15% | Weekly downloads |
| License | 15% | Whether the license is known and allowed |
| Dependencies | 10% | Known vulnerabilities in the latest version and the number of direct dependencies |
Maintenance
| Last activity | Score |
|---|---|
| 180 days or less | 100 |
| 181 to 365 days | 85 |
| 1 to 2 years | 60 |
| 2 to 4 years | 35 |
| More than 4 years | 15 |
| Repository archived | 5 |
Bus factor
The smallest number of contributors who together wrote half of the repository's commits.
| Contributors | Score |
|---|---|
| 1 | 25 |
| 2 | 50 |
| 3 or 4 | 75 |
| 5 or more | 100 |
Community
25 × log10(stars + 1), capped at 100: about 50 for 100 stars, 75 for 1,000 and 100 from 10,000.
Adoption
20 × log10(weekly downloads + 1), capped at 100: 60 for 1,000 weekly downloads, 80 for 10,000 and 100 from 100,000. crates.io reports downloads over 90 days, which dagsec divides by 13.
License
| License | Score |
|---|---|
| Known and not blocked | 100 |
| Unknown | 50 |
| Blocked by the scoring blocklist | 0 |
The scoring blocklist defaults to AGPL-3.0 and GPL-2.0 and can be changed in .pkgriskrc.toml. It affects only the score. To fail a scan on a license, use a license policy.
Dependencies
| Latest version | Score |
|---|---|
| Has any known vulnerability | 0 |
| No known vulnerability, 0 to 10 direct dependencies | 100 |
| 11 to 50 direct dependencies | 80 |
| More than 50 | 50 |
The threshold
A dependency scoring below fail-under fails the scan. The default is 40; change it with the Action's fail-under input, GitLab's DAGSEC_FAIL_UNDER variable or the CLI's --fail-under flag.
Which dependencies are scored
Direct dependencies of npm (package.json dependencies), crates.io (Cargo.toml [dependencies] and [workspace.dependencies]) and PyPI (requirements.txt). Go, Maven and NuGet packages are checked for vulnerabilities but not scored in scans; the MCP check_package tool does score them.