Skip to content

Dependency health score ​

Each direct dependency gets a score from 0 to 100 built from six categories. A category whose data isn't available (for example, no linked GitHub repository) is left out and the others are re-weighted, rather than guessing.

Categories ​

CategoryWeightMeasures
Maintenance25%Days since the latest release or push to the repository, whichever is newer
Bus factor20%How many contributors wrote half of all commits
Community15%GitHub stars
Adoption15%Weekly downloads
License15%Whether the license is known and allowed
Dependencies10%Known vulnerabilities in the latest version and the number of direct dependencies

Maintenance ​

Last activityScore
180 days or less100
181 to 365 days85
1 to 2 years60
2 to 4 years35
More than 4 years15
Repository archived5

Bus factor ​

The smallest number of contributors who together wrote half of the repository's commits.

ContributorsScore
125
250
3 or 475
5 or more100

Community ​

25 × log10(stars + 1), capped at 100: about 50 for 100 stars, 75 for 1,000 and 100 from 10,000.

Adoption ​

20 × log10(weekly downloads + 1), capped at 100: 60 for 1,000 weekly downloads, 80 for 10,000 and 100 from 100,000. crates.io reports downloads over 90 days, which dagsec divides by 13.

License ​

LicenseScore
Known and not blocked100
Unknown50
Blocked by the scoring blocklist0

The scoring blocklist defaults to AGPL-3.0 and GPL-2.0 and can be changed in .pkgriskrc.toml. It affects only the score. To fail a scan on a license, use a license policy.

Dependencies ​

Latest versionScore
Has any known vulnerability0
No known vulnerability, 0 to 10 direct dependencies100
11 to 50 direct dependencies80
More than 5050

The threshold ​

A dependency scoring below fail-under fails the scan. The default is 40; change it with the Action's fail-under input, GitLab's DAGSEC_FAIL_UNDER variable or the CLI's --fail-under flag.

Which dependencies are scored ​

Direct dependencies of npm (package.json dependencies), crates.io (Cargo.toml [dependencies] and [workspace.dependencies]) and PyPI (requirements.txt). Go, Maven and NuGet packages are checked for vulnerabilities but not scored in scans; the MCP check_package tool does score them.