Skip to the main content
The Repo Vitals mark: a pulse that ends in a commitREPO VITALS

applicable weight 65%

no1se-pi/custodes

Language: Shell
branch main
imported from GitHub

A system for static and dynamic analysis of commits and logs to prevent secret leaks and detect attacks using static analysis and local AI.

Open on SourceCraftDownload report (Markdown)snapshot 8 October 2026signal coverage 65%analysed 27 September 2026 at 21:42 UTC — not all categories measured

What the 100 is made of

category weight
Documentation 20Activity 20Security 20CI/CD 15Issues 15Code health 10

The light segments — Security: will appear with a member token; Issues: the tracker is empty or not set up. The rest share their weight for now.

Six categories

earned / weight
Documentation and best practices
18.5 / 30.8
scored
Project activity
24.6 / 30.8
scored
Securitywill appear with a member token
no data
CI/CDsignal coverage 50%
0–11.5 / 23.1
partial
Issuesthe tracker is empty or not set up
no data
Code health
15.4 / 15.4
scored
States:
scored
partial
no data
weight goes to the rest
collection failed
interval, not zero
Not measured: CI runs
closed by the platform
will become a group once access opens

Strengths

what's already done
  • Almost no marked debt in the code
  • The README introduces the project
  • Commits span the whole year (38 commits)
  • Work goes on without long pauses (7 weeks)
  • The license file is in place

What affected the score

Penalties

Documentation and best practices

  • −3
    Dockerfilemissing
  • −3
    dependency lockfilemissing
  • −3
    review policyno protection
  • −1
    contributing guidemissing
  • −1
    branch protection policyno protection
  • −1
    share of short commit messages — 39%

Project activity

  • −4
    top author's share of commits — 92%
  • −1
    unique authors — 3 authors
  • −1
    last commit — 67 days
  • −1
    last release — 67 days
  • −<1
    weekly activity — 7 weeks

CI/CD

  • −12
    SourceCraft CI configurationmissing

Not measured — interval width

Not a penalty: the lower bound of the score counts the metric as zero, the upper bound as full

CI/CD

  • up to −12
    CI runsdata not collected

What will raise the score

by strength of impact
  • CI/CD
    +12
    add a SourceCraft CI configuration (.sourcecraft/ci.yaml); the service does not see external CISourceCraft CI configurationwhy: the build and the checks are reproducible for whoever takes the code
  • Activity
    +4
    share the work with other contributorstop author's share of commits — 92%why: the work does not rest on a single person
  • Documentation
    +3
    containerize the project — add a DockerfileDockerfilewhy: a newcomer can tell how to run the project and where to look
  • add a dependency lockfile+3
  • set up a review policy+3
  • add a contributing guide+1
  • set up a branch protection policy+1
  • bring in a second maintainer+1
  • write meaningful commit messages+1
  • make a commit soon+1
  • publish a release or tag a version+1
  • spread work across more weeks instead of bursts+<1