Skip to content
CAI
Software that uses CAICheck a score

github/github-mcp-server

53.4

Adequate · 24 September 2026

47k

lines of production code

Go

with TypeScript

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a GitHub Model Context Protocol (MCP) server that exposes GitHub APIs as tools for AI agents, covering areas such as repository management, code scanning, and GitHub Actions. It provides a robust infrastructure for secure OAuth authentication, request handling, and tool discovery, while also offering a React-based UI framework for interactive MCP applications like issue and pull request creation.

How it got here

2025 — Infrastructure modernization and security hardening

19 changes.

This period focused on modernizing the project's infrastructure by migrating to a new module path, upgrading to Go 1.25, and replacing the legacy server entry point with a new Inventory-based tool management system. Significant effort was dedicated to security and reliability, introducing path traversal protection, content sanitization, structured error handling, and robust OAuth authorization flows. The release also expanded functionality with new GitHub Actions and code scanning tools, while establishing comprehensive testing, documentation automation, and development utility scripts.

2026 — HTTP transport and OAuth infrastructure

13 changes.

This period focused on establishing a robust HTTP transport layer for the MCP server, introducing comprehensive OAuth 2.0 support including scope enforcement, token management, and protected resource metadata discovery. The work also involved restructuring the HTTP middleware and context handling to support secure, scalable request processing and dynamic feature flags. Additionally, a new React-based UI framework was introduced to provide dedicated applications for interacting with GitHub resources like issues and pull requests.

Features

Add I/O logging wrapper for debugging

A new IOLogger component has been added to the logging package to wrap io.Reader and io.Writer streams. When used, it transparently logs the data being read from and written to these streams using the standard library's slog logger, which aids in debugging data flow without altering the underlying I/O behavior.

pkg/log · high confidence

Add raw file API client with path traversal protection

The new \pkg/raw\ package provides a client for fetching raw file content from GitHub repositories, supporting retrieval by branch, tag, or commit SHA. It includes security validation that rejects URL components containing \..\ path segments (including those introduced via percent-encoding) to prevent path traversal attacks, and integrates with the \go-github/v89\ library for HTTP operations.

pkg/raw · high confidence

Add ring buffer for truncating large GitHub Actions job logs

The \pkg/buffer\ package now includes a new \ProcessResponseAsRingBufferToEnd\ function that efficiently processes HTTP response bodies by retaining only the last N log lines using a ring buffer. This prevents memory exhaustion when handling extremely large logs, such as those from GitHub Actions, by enforcing a 10MB per-line limit and truncating oversized lines with a marker. The implementation includes comprehensive tests covering edge cases like empty bodies, exact size boundaries, and ring buffer rotation with truncated lines.

pkg/buffer · high confidence

Add script to generate MCP configuration matrices for diff testing

A new Go script, \script/print-mcp-diff-configs\, has been added to generate the JSON configuration matrix used by the \mcp-server-diff\ GitHub Action. This tool emits configuration entries covering default settings, read-only modes, specific toolsets (repos, issues, context, pull requests), and feature flags. It supports two output transports: \stdio\ (generating CLI arguments) and \http-headers\ (generating X-MCP-\* headers for a shared HTTP server), ensuring that both local and remote server invocation modes are tested against the same logical configuration set.

script/print-mcp-diff-configs · high confidence

Add tool search CLI

Introduces a new tool search capability in the \pkg/tooldiscovery\ package, allowing users to find relevant tools via free-text queries. The implementation uses a weighted scoring system that considers matches in tool names, descriptions, and input parameter names, with fuzzy matching as a tie-breaker. Results are sorted by relevance and limited by a configurable maximum (default 3). Tests verify correct behavior for empty queries, name-based searches, and parameter-name matching across different schema formats.

pkg/tooldiscovery · high confidence

Added translation helper framework for configurable string overrides

A new translation helper package has been introduced to allow users to override default application strings via environment variables or a JSON configuration file. The helper function checks for environment variables prefixed with GITHUB\MCP\ (e.g., GITHUB\_MCP\_KEY) and falls back to a JSON config file named github-mcp-server-config.json, enabling runtime customization of text without code changes. It also provides a mechanism to dump the resolved translation map back to the JSON file for persistence.

pkg/translations · high confidence

Automated documentation generation and OAuth scope listing commands

The server now includes a \generate-docs\ command that automatically updates the README, remote server documentation, and feature-flag/Insiders documentation sections by analyzing the current tool inventory and feature flags. It also adds a \list-scopes\ command that outputs the OAuth challenge scopes required by enabled tools in text, JSON, or summary formats. These changes improve transparency around tool capabilities and authentication requirements without altering the server's runtime behavior.

cmd/github-mcp-server · high confidence

Introduce Inventory pattern for tool, resource, and prompt management

The server now uses a new Inventory system in \pkg/inventory\ to manage tools, resources, and prompts. This system provides a builder-based API for configuring the server's capabilities, including support for toolsets, feature flags, and read-only modes. It introduces a \ForMCPRequest\ method that optimizes registration by only including items relevant to the specific MCP method being called (e.g., only the specific tool for \tools/call\), reducing overhead. The inventory also handles deterministic sorting of items and generates server instructions based on enabled toolsets.

pkg/inventory · high confidence

Introduce MCP Apps UI framework and initial GitHub user profile view

Adds a new React-based UI layer for MCP Apps, including a reusable AppProvider that handles host theme synchronization and a useMcpApp hook that manages tool execution, result rendering, and link opening via the host's capabilities. This location specifically delivers the 'get-me' app, which displays a GitHub user profile card with avatar, bio details, and repository stats, along with supporting components like a MarkdownEditor and a FeedbackFooter.

ui/src · high confidence

Introduce OAuth 2.0 Protected Resource Metadata support for HTTP mode

The HTTP server now implements RFC 9728 Protected Resource Metadata, advertising supported OAuth scopes and the authorization server URL at the \/.well-known/oauth-protected-resource\ path. This allows MCP clients to automatically discover the correct OAuth configuration. The implementation respects the \--gh-host\ (AuthorizationServer) configuration, defaults to GitHub's OAuth server, and includes a \TrustProxyHeaders\ option to safely handle \X-Forwarded-Host\ and \X-Forwarded-Proto\ headers when deployed behind a trusted proxy.

pkg/http/oauth · high confidence

Introduce content sanitization for titles and bodies

Added a new \pkg/sanitize\ package that cleans user-authored text to prevent rendering issues and security risks. The \Sanitize\ function processes content bodies by stripping invisible Unicode characters (such as zero-width spaces and BiDi controls), filtering code-fence metadata, and sanitizing HTML tags using the \bluemonday\ library. A separate \PlainText\ function handles titles and other plain-text surfaces by neutralizing angle brackets and nested HTML entities to ensure safe display without HTML interpretation.

pkg/sanitize · high confidence

Introduce mcpcurl CLI tool for dynamic MCP server interaction

A new command-line utility, \mcpcurl\, is added to the \cmd/mcpcurl\ directory. It connects to an MCP server via stdio, dynamically retrieves the available tool schemas, and generates corresponding CLI subcommands for execution. The tool supports parameter validation based on the server's schema, handles JSON-RPC error responses, and includes a \--pretty\ flag to format JSON/JSONL output. Installation instructions and usage examples are provided in the new README.

cmd/mcpcurl · high confidence

Introduces per-call OAuth scope enforcement and discovery

The \pkg/scopes\ package now provides the infrastructure for checking and resolving OAuth scopes on a per-tool-call basis. It includes a fetcher that retrieves the \X-OAuth-Scopes\ header from the GitHub API to discover a token's capabilities, a scope map that links tools to their required scope policies, and a hierarchy that allows parent scopes (like \repo\) to satisfy child requirements (like \public\_repo\). This enables the server to validate that a user's token has the necessary permissions for specific actions and to challenge for additional scopes when needed.

pkg/scopes · high confidence

New API host resolution and MCP tool result utilities in pkg/utils

This change introduces new utility packages in pkg/utils that enhance how the application connects to GitHub and handles Model Context Protocol (MCP) responses. The new api.go module provides a structured APIHostResolver that correctly resolves REST, GraphQL, upload, and raw file URLs for GitHub.com, GitHub Enterprise Cloud (GHEC), and GitHub Enterprise Server (GHES), including support for subdomain isolation and preserving loopback ports/IPv6 brackets. It also enforces HTTPS for remote GHEC/GHES hosts to prevent cleartext credential transmission, while allowing HTTP for local loopback addresses. Additionally, result.go adds helper functions for constructing MCP CallToolResult objects, including a new awaiting-form-submission result type that signals to agents that an interactive UI form is being shown and the operation has not yet been performed. The token.go module adds logic to parse and classify GitHub authorization tokens by their prefixes (personal access, fine-grained, OAuth, and GitHub App tokens).

pkg/utils · high confidence

New GitHub Actions, Code Quality, and Code Scanning tools

This change introduces new MCP tools for GitHub Actions, Code Quality, and Code Scanning. The \actions.go\ file adds a consolidated \actions\_list\ tool that supports multiple methods (e.g., \list\_workflows\, \list\_workflow\_runs\, \get\_workflow\_job\_logs\) and includes minimal response types to reduce payload size. The \code\_quality.go\ file adds a \get\_code\_quality\_finding\ tool to retrieve details of specific code quality findings. The \code\_scanning.go\ file adds \get\_code\_scanning\_alert\ and \list\_code\_scanning\_alerts\ tools for managing code scanning alerts, with appropriate security scopes and IFC labeling. Tests are provided for all new tools.

pkg/github · high confidence

New HTTP endpoint for MCP Server Card discovery

The GitHub MCP Server now exposes a public, no-auth HTTP endpoint at /server-card that serves a static metadata document (Server Card) describing the server's identity, repository, and streamable-HTTP transport. This allows clients to discover and connect to the server before the protocol handshake. The response is served as application/mcp-server-card+json, supports content negotiation, caching via ETags, and CORS headers, and is designed to be mounted alongside the existing MCP endpoint without requiring authentication.

pkg/http/servercard · high confidence

New HTTP header constants and parsing utilities

This change introduces a new \pkg/http/headers\ package that centralizes standard HTTP header names (such as Authorization, Content-Type, ETag, and various X-Forwarded headers) alongside specific constants for MCP (Model Context Protocol) headers like Mcp-Method, Mcp-Name, and Mcp-Param-\*. It also adds a \ParseCommaSeparated\ utility function to safely split and trim comma-separated header values, along with corresponding unit tests for this parsing logic.

pkg/http/headers · high confidence

New HTTP transport layer with scoped auth, ETag caching, and GraphQL features

The HTTP transport package has been replaced with a modular set of RoundTripper implementations. BearerAuthTransport now scopes tokens to configured GitHub hosts to prevent credential leakage on redirects, and supports per-request token providers for OAuth flows. ETagTransport adds conditional GET support with a bounded LRU cache to reduce bandwidth and rate-limit usage for repeated requests. GraphQLFeaturesTransport injects feature headers from context to enable non-GA API capabilities, and UserAgentTransport standardizes the User-Agent header.

pkg/http/transport · high confidence

New MCP Apps for creating and editing issues and pull requests

This change introduces new UI applications for GitHub MCP tools, providing dedicated interfaces for creating and editing issues and pull requests. The \issue-write\ app allows users to compose issues with support for custom fields, labels, assignees, and milestones, while the \pr-write\ and \pr-edit\ apps provide forms for creating and modifying pull requests, including branch selection, reviewer management, and draft status. These apps integrate with the host environment via the \open-link\ capability to open created or edited items in the browser.

ui/src/apps/issue-write · high confidence

New development and release utility scripts

This change introduces a suite of new shell scripts to streamline the development workflow and release process. The \script/build-ui\ script automates the installation and build of the MCP App UIs. A new \script/conformance-test\ script allows developers to compare server behavior between branches by building binaries, running MCP JSON-RPC list commands, and generating detailed diff reports. The \script/fetch-icons\ script downloads Octicon SVGs, converts them to PNGs for light and dark themes, and generates embedded data URIs. Release management is supported by \script/tag-release\, which handles semantic version validation, branch checks, and tag creation. Compliance is improved with \script/licenses\ and \script/licenses-check\, which generate architecture-specific license reports and verify they are up to date. Additional utilities include \script/generate-docs\ for server documentation, \script/list-scopes\ for OAuth scope analysis, \script/prettyprint-log\ for colored log visualization, and \script/lint\ for running golangci-lint. The \script/get-me\ script is updated to follow the MCP protocol's initialize/initialized handshake sequence.

script · high confidence

Removals

Removal of the cmd/server entry point

The main server entry point located at cmd/server/main.go has been removed from the codebase. This change eliminates the local implementation of the Cobra command-line interface, Viper configuration binding, and the stdio server startup logic that previously handled logging initialization and GitHub MCP server execution.

cmd/server · high confidence

Behavioural changes

Centralized request context for tokens, features, and MCP metadata

The \pkg/context\ package now provides a unified set of context helpers to carry request-specific state throughout the application. This includes authentication details (token info and scopes), feature flags (GraphQL, HTTP header-based, and UI support), operational modes (read-only, lockdown, insiders), and MCP-specific metadata (method info, toolsets, tools, and excluded tools). By storing these values in the context, the system avoids redundant parsing and enables downstream components to make decisions based on the current request's capabilities and constraints.

pkg/context · high confidence

GitHub MCP server tool definitions updated

The tool specification snapshots in \pkg/github/\_\toolsnaps\\_\ have been regenerated to reflect the current set of available GitHub MCP tools. This update includes new tools for managing GitHub Actions workflows (such as \actions\_get\, \actions\_list\, and \actions\_run\_trigger\), handling pull request reviews and comments (including \add\_comment\_to\_pending\_review\ and \add\_pull\_request\_review\_comment\), and managing issues with sub-issues and reactions. It also introduces governance capabilities via \create\_repository\_ruleset\ and \custom\_properties\_read/write\, as well as Copilot assignment tools (\assign\_copilot\_to\_issue\ and \assign\_copilot\_to\_issue\_with\_intent\). These changes ensure that the tool schemas, input parameters, and descriptions in this directory are synchronized with the latest server implementation.

pkg/github/\\toolsnaps\\_ · high confidence_

Harden OAuth authorization with multi-round-trip elicitation and host-scoped tokens

The server now supports multi-round-trip OAuth authorization, allowing clients to handle authorization prompts via elicitation (URL or form mode) instead of requiring a browser redirect, which improves compatibility with MCP clients that cannot open external links. Additionally, bearer tokens are now strictly scoped to the configured GitHub hosts, preventing accidental leakage to redirect targets, and default OAuth credentials are injected at build time via ldflags to simplify user setup.

internal · high confidence

Introduce new HTTP handler with configurable request limits and OAuth overrides

The HTTP server now uses a new handler implementation that enforces a configurable maximum request body size (defaulting to 5 MiB) to prevent oversized payloads before MCP parsing. It also supports overriding the OAuth authorization server URL via the --authorization-server flag, which is useful when deploying behind an OAuth proxy. Additionally, the handler validates static tool configurations at startup, failing immediately if invalid tools are specified, and includes a shared schema cache to reduce reflection overhead.

pkg/http · high confidence

Lockdown mode now uses per-identity cached repository access checks

The lockdown feature now caches repository access metadata (private status and push permissions) to improve performance, while ensuring that these checks are strictly isolated per user identity. The cache is scoped using a hashed identity digest so that decisions made under one user's credentials are never served to another, and entries expire after a default 20-minute TTL. Trusted bots like Copilot are excluded from these filtering checks.

pkg/lockdown · high confidence

New HTTP middleware layer for MCP request handling

The HTTP middleware package has been restructured with a new set of handlers that enforce a 5 MiB request body limit, configure CORS to allow browser-based MCP clients, parse MCP JSON-RPC envelopes early to enable tool filtering, extract and validate user tokens (including PATs and OAuth tokens), and enforce per-call OAuth scope challenges. Additionally, request configuration middleware now supports feature flags via both headers and URL query parameters, allowing dynamic feature selection for headerless hosted connections.

pkg/http/middleware · high confidence

Octicons are now embedded as offline data URIs for faster, offline icon loading

The \pkg/octicons\ package now embeds Octicon PNGs directly as base64 data URIs (light and dark variants) instead of relying on external URLs. This change enables offline icon rendering and reduces load times for users. The \Icons\ function returns MCP Icon objects with these embedded sources, and the \Sizes\ field is intentionally omitted to maintain backward compatibility with older MCP clients.

pkg/octicons · high confidence

Structured GitHub error tracking with improved rate-limit messaging

The error handling layer now introduces dedicated error types (GitHubAPIError, GitHubGraphQLError, GitHubRawAPIError) and a context-based mechanism to accumulate and retrieve these errors across the request lifecycle. This allows middleware and downstream components to inspect detailed error information without relying solely on context propagation. Additionally, when a GitHub API rate limit is hit, the system now detects specific rate-limit errors and returns user-friendly messages that include the exact retry time or a generic wait instruction, rather than a generic failure message.

pkg/errors · high confidence

Unified UI build script for faster, portable builds

The UI build process now uses a single Node.js script (ui/scripts/build.mjs) to build all four applications (get-me, issue-write, pr-write, pr-edit) in one Vite process, replacing the previous serial invocations. This change reduces startup overhead by avoiding repeated Vite and plugin initialization for each app and removes the dependency on cross-env for environment variable handling, resulting in faster and more portable builds.

ui/scripts · high confidence

Test coverage

Added end-to-end test suite for the GitHub MCP Server

Added a new end-to-end test suite that validates the black-box behavior of the \github-mcp-server\ by building its Docker image, running it, and interacting with the live GitHub API via stdio. The tests are gated behind the \e2e\ build tag and require the \GITHUB\_MCP\_SERVER\_E2E\_TOKEN\ environment variable. The suite also supports an in-process debugging mode via the \GITHUB\_MCP\_SERVER\_E2E\_DEBUG\ environment variable, which bypasses Docker integration to allow breakpoint debugging of the MCP server internals.

e2e · high confidence

Dependencies

Major dependency upgrades and Go module migration

The Go module has been migrated from \github.com/github/mcp-server-playground\ to \github.com/github/github-mcp-server\ and upgraded to Go 1.25.12. Key dependency updates include \google/go-github\ from v69 to v89, \modelcontextprotocol/go-sdk\ to v1.7.0, \go-chi/chi/v5\ to v5.3.2, \spf13/cobra\ to v1.10.2, \spf13/viper\ to v1.21.0, and \google/jsonschema-go\ to v0.4.3. The UI \package.json\ introduces \@modelcontextprotocol/ext-apps\ v1.7.2, \@primer/octicons-react\ v19.0.0, \react-markdown\ v10.1.0, and \remark-gfm\ v4.0.1, while upgrading build tools to Vite v8.0.16 and \@vitejs/plugin-react\ v6.0.2.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 49 → 53 (+4.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 41 → 44 (+2.7)
  • Architecture 100 → 96 (-3.9)
  • Maturity 64 → 64 (-0.1)
  • Readiness 51 → 78 (+27.2)
  • Security 74 → 84 (+10.1)
  • Accessibility 48 → 48 (+0.0)

Resolved (213)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 10) (pkg/github/issues.go)
  • Duplicated block (10 lines × 13) (pkg/github/projects.go)
  • Duplicated block (10 lines × 13) (pkg/github/pullrequests.go)
  • Duplicated block (10 lines × 2) (pkg/github/actions.go)
  • Duplicated block (10 lines × 2) (pkg/github/copilot.go)
  • Duplicated block (10 lines × 2) (pkg/github/copilot.go)
  • Duplicated block (10 lines × 2) (pkg/github/dependabot.go)
  • Duplicated block (10 lines × 2) (pkg/github/discussions.go)
  • Duplicated block (10 lines × 2) (pkg/github/gists.go)
  • Duplicated block (10 lines × 2) (pkg/github/issue_fields.go)
  • Duplicated block (10 lines × 2) (pkg/github/issues.go)
  • Duplicated block (10 lines × 2) (pkg/github/issues.go)
  • Duplicated block (10 lines × 2) (pkg/github/issues_granular.go)
  • Duplicated block (10 lines × 2) (pkg/github/minimal_types.go)
  • Duplicated block (10 lines × 2) (pkg/github/projects.go)
  • Duplicated block (10 lines × 2) (pkg/github/pullrequests_granular.go)
  • Duplicated block (10 lines × 2) (pkg/github/repositories.go)
  • Duplicated block (10 lines × 2) (pkg/github/repositories.go)
  • …and 193 more

New (445)

  • App.CreateIssueApp (cognitive 293) (ui/src/apps/issue-write/App.tsx)
  • App.CreateIssueApp (cyclomatic 259) (ui/src/apps/issue-write/App.tsx)
  • App.CreatePRApp (cognitive 129) (ui/src/apps/pr-write/App.tsx)
  • App.CreatePRApp (cyclomatic 113) (ui/src/apps/pr-write/App.tsx)
  • App.EditPRApp (cognitive 121) (ui/src/apps/pr-edit/App.tsx)
  • App.EditPRApp (cyclomatic 102) (ui/src/apps/pr-edit/App.tsx)
  • App.normalizeIssueFieldEntry (cyclomatic 23) (ui/src/apps/issue-write/App.tsx)
  • App.normalizeIssueFieldValues (cognitive 18) (ui/src/apps/issue-write/App.tsx)
  • Dependency pinned to a stale untagged commit: github.com/muesli/cache2go
  • Dependency pinned to a stale untagged commit: github.com/shurcooL/graphql
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (10 lines × 17) (pkg/github/find_duplicate.go)
  • Duplicated block (10 lines × 2) (pkg/github/issues.go)
  • Duplicated block (10 lines × 2) (pkg/github/issues.go)
  • Duplicated block (10 lines × 2) (pkg/github/issues.go)
  • Duplicated block (10 lines × 2) (pkg/github/issues_granular.go)
  • Duplicated block (10 lines × 2) (pkg/github/notifications.go)
  • Duplicated block (10 lines × 2) (pkg/github/projects.go)
  • Duplicated block (10 lines × 2) (pkg/github/pullrequests.go)
  • Duplicated block (10 lines × 2) (pkg/github/pullrequests.go)
  • …and 425 more

Changes since last survey

  • 129 commits — 86 feature/other, 43 fixes

By area

  • pkg/github — 63 commits
  • pkg/http — 24 commits
  • (root) — 12 commits
  • .github/workflows — 7 commits
  • ui/package-lock.json — 5 commits
  • pkg/sanitize — 4 commits
  • cmd/github-mcp-server — 2 commits
  • pkg/errors — 2 commits
  • pkg/lockdown — 2 commits
  • pkg/raw — 2 commits
  • pkg/utils — 2 commits
  • agent-plugin/mcp.json — 1 commit
  • e2e/e2e_test.go — 1 commit
  • internal/ghmcp — 1 commit
  • pkg/inventory — 1 commit

Notable commits

  • fix: Fix e2e harness compilation against go-github v89 and go-sdk v1.7 (#3187)
  • fix: Fix static tools validation fallback
  • fix: Revert "ci(lint): skip remote config schema verification"
  • fix: fix(actions): avoid malformed response on log download failure
  • fix: fix(auth): scope tokens across GitHub clients
  • fix: fix(auth): validate reviewer scope arguments
  • fix: fix(copilot): explain review request denials instead of forwarding a bare 404
  • fix: fix(copilot): keep rate limit denials out of the review permission hint
  • fix: fix(errors): safely format GitHub validation failures
  • fix: fix(http): allow projected MCP headers in preflights (#3167)
  • fix: fix(http): fail startup on invalid static tools
  • fix: fix(http): make server lockdown mode an upper bound over requests (#3112)
  • fix: fix(http): preserve CORS across OAuth routes
  • fix: fix(http): terminate unknown resource metadata routes
  • fix: fix(issues): allow delete:false in issue_write issue_fields
  • fix: fix(issues): fall back on unsupported field schemas
  • fix: fix(issues): flatten issue comment input schema
  • fix: fix(issues): harden GHES schema fallback
  • fix: fix(issues): narrow search field enrichment fallback
  • fix: fix(issues): preserve delete field semantics
  • …and 109 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

github/github-mcp-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 85598ba6e1256f7ebf4867b95d63b833c4549264 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.