applicable weight 65%
github2sourcecraft/cyclonedx-gomod
Language: Go
branch main
mirror
Creates CycloneDX Software Bill of Materials (SBOM) from Go modules
Open on SourceCraftDownload report (Markdown)snapshot 8 October 2026signal coverage 65%analysed 23 September 2026 at 21:23 UTC — part unavailable
What the 100 is made of
category weightDocumentation 20Activity 20Security 20CI/CD 15Issues 15Code health 10
The light segments — Security: will appear with a member token; Issues: the tracker is empty or not set up. The rest share their weight for now.
Six categories
earned / weightDocumentation and best practicessignal coverage 83%25.6–30.8 / 30.8
partial
Project activity26.4 / 30.8
scored
Securitywill appear with a member token
no data
CI/CDsignal coverage 50%0–11.5 / 23.1
partial
Issuesthe tracker is empty or not set up
no data
Code health0–15.4 / 15.4
collection failed
States:weight goes to the restinterval, not zero
scored
partial
no data
collection failed
Not measured: CI runswill become a group once access opens
closed by the platform
Not measured: docs directory, contributing guide, TODO/FIXME densitythe platform's window was truncated: a deep file or a recent version may have fallen outside it
couldn't see it
Strengths
what's already done- The README introduces the project
- Commits span the whole year (124 commits)
- Work goes on without long pauses (10 weeks)
- A team works on the project (8 authors)
- Commits are fresh (31 days)
What affected the score
Penalties
Project activity
- −3last release — 250 days
- −1top author's share of commits — 60%
- −<1last commit — 31 days
CI/CD
- −12SourceCraft CI configurationmissing
Not measured — interval width
Not a penalty: the lower bound of the score counts the metric as zero, the upper bound as full
Documentation and best practices
- up to −3docs directorydata not collected
- up to −2contributing guidedata not collected
CI/CD
- up to −12CI runsdata not collected
Code health
- up to −15TODO/FIXME densitydata not collected
What will raise the score
by strength of impact- add a SourceCraft CI configuration (.sourcecraft/ci.yaml); the service does not see external CISourceCraft CI configurationwhy: the build and the checks are reproducible for whoever takes the code+12CI/CD
- publish a release or tag a versionlast release — 250 dayswhy: the build and the checks are reproducible for whoever takes the code+3Activity
- share the work with other contributorstop author's share of commits — 60%why: the work does not rest on a single person+1Activity
- make a commit soon+<1