Loading...
Loading...
Compare original and translation side by side
github.com/lgtm-hq/py-lintrogithub.com/lgtm-hq/py-lintroundefinedundefined
Also check the
[scorecard viewer](https://scorecard.dev/viewer/?uri=github.com/lgtm-hq/py-lintro).
同时查看[评分卡查看器](https://scorecard.dev/viewer/?uri=github.com/lgtm-hq/py-lintro)。| Check | Score | Root Cause |
|---|---|---|
| Code-Review | 0/10 | Single maintainer — PRs by |
| Token-Permissions | 0/10 | Workflows escalate to |
| Signed-Releases | 0/10 | PyPI attestations and Docker provenance exist but scorecard expects Sigstore signatures or |
| Pinned-Dependencies | -1 (error) | |
| Fuzzing | 0/10 | No OSS-Fuzz or ClusterFuzzLite integration. |
| CI-Tests | 5/10 | Tests detected on only ~57% of merged PRs. Bot/release PRs (from |
| Security-Policy | 4/10 | SECURITY.md uses a personal email instead of GitHub's private vulnerability reporting. |
| Contributors | 3/10 | Single human contributor. Inherent to the project — cannot easily change. |
| CII-Best-Practices | 2/10 | OpenSSF Best Practices badge was "InProgress". User reported 99% complete as of 2026-02-20 — scorecard may lag. |
| Vulnerabilities | 7/10 | Open Dependabot alerts (11 at baseline). |
| SAST | 8/10 | CodeQL configured but may not cover all commit paths. |
| Branch-Protection | 6/10 | Allstar configured but |
| Dependency-Update-Tool | 10/10 | Renovate configured and active. |
| Maintained | 10/10 | Active development. |
| Dangerous-Workflow | 10/10 | No dangerous patterns. |
| Binary-Artifacts | 10/10 | Clean. |
| Packaging | 10/10 | OIDC trusted publishing to PyPI. |
| License | 10/10 | MIT. |
| 检查项 | 评分 | 根本原因 |
|---|---|---|
| Code-Review | 0/10 | 单一维护者——TurboCoder13提交的PR没有独立的人工审核者。CodeRabbit(AI机器人)的审核不计入在内。 |
| Token-Permissions | 0/10 | 工作流在任务级别提升至 |
| Signed-Releases | 0/10 | 存在PyPI证明和Docker溯源,但评分卡要求GitHub Release工件本身带有Sigstore签名或使用 |
| Pinned-Dependencies | -1(错误) | Dockerfile中的 |
| Fuzzing | 0/10 | 未集成OSS-Fuzz或ClusterFuzzLite。 |
| CI-Tests | 5/10 | 仅约57%的合并PR执行了测试。机器人/发布PR(来自 |
| Security-Policy | 4/10 | SECURITY.md使用个人邮箱而非GitHub的私有漏洞报告渠道。 |
| Contributors | 3/10 | 仅一位人类贡献者。这是项目固有属性,难以轻易改变。 |
| CII-Best-Practices | 2/10 | OpenSSF最佳实践徽章处于“InProgress”状态。截至2026-02-20,用户报告已完成99%——评分卡可能存在延迟。 |
| Vulnerabilities | 7/10 | 存在未处理的Dependabot警报(基线时有11个)。 |
| SAST | 8/10 | 已配置CodeQL,但可能未覆盖所有提交路径。 |
| Branch-Protection | 6/10 | 已配置Allstar,但 |
| Dependency-Update-Tool | 10/10 | 已配置并启用Renovate。 |
| Maintained | 10/10 | 开发活动活跃。 |
| Dangerous-Workflow | 10/10 | 未发现危险模式。 |
| Binary-Artifacts | 10/10 | 无问题。 |
| Packaging | 10/10 | 已通过OIDC可信发布至PyPI。 |
| License | 10/10 | MIT许可证。 |
FROM ${TOOLS_IMAGE}FROM ${TOOLS_IMAGE}undefinedundefined
At baseline, these were **disabled** (not scored by scorecard but still worth tracking):
- `secret_scanning`
- `secret_scanning_push_protection`
- `dependabot_security_updates`
基线时,以下功能处于**禁用**状态(评分卡未纳入评分,但仍值得跟踪):
- `secret_scanning`
- `secret_scanning_push_protection`
- `dependabot_security_updates`undefinedundefined| Check | Baseline | Current | Delta | Notes |
|---|---|---|---|---|
| ... | ... | ... | ... | ... |
| Check | Baseline | Current | Delta | Notes |
|---|---|---|---|---|
| ... | ... | ... | ... | ... |
undefinedundefinedEdit skills/scorecard/SKILL.mdEdit skills/scorecard/SKILL.md