How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade C reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Full methodology →
Signals refreshed2026-06-22 00:01 UTC·Repo last pushed 46 days ago
Rank Trend
2026-06-202026-06-21
Activity & Reach
Stars
3.0k
Forks
678
Last Push
2026-05-07
46 days ago
Commits (4 wk)
0
Downloads (7d)
—
HN mentions (30d)
—
Open Issues
386
Rank Change
=
was #174
Analysis
HVTrust Dimensions
52.5 / 100 · 100.0% confidence
Safety / IntegrityOSSF, provenance, signatures
11.5 / 25
Identity / ProvenanceListing and build link
10.8 / 18
TransparencyLicense and public checks
12.9 / 17
MaintenanceFreshness and commits
8.9 / 20
AdoptionStars and downloads
8.4 / 20
Activity Inputs
53.1 / 100
StarsRepository reach
20.9 / 30
FreshnessLast push recency
18.6 / 25
ActivityRecent commits
0.0 / 25
CommunityFork signal
13.2 / 20
Supply Chain Trust
Package Provenance
None
No package attestations found
OSSF Scorecard
5.2 / 10
OpenSSF Scorecard · scanned Jun 20, 2026
Signed Commits
100%
of last 100 commits verified
Code-Review8
Dangerous-Workflow10
Maintained1
CII-Best-Practices0
Token-Permissions0
Binary-Artifacts10
Packaging10
License10
Fuzzing0
Branch-Protection-1
Signed-Releases-1
Security-Policy9
Pinned-Dependencies0
SAST0
Is Habitat-Lab safe?
Public trust evidence for Habitat-Lab is thin: several supply-chain signals are missing or weak. This does not mean the project is unsafe — it means an outside observer cannot easily verify the usual integrity checks. Treat with extra scrutiny.
Does Habitat-Lab publish package provenance?
No published build provenance is currently detected for Habitat-Lab. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does Habitat-Lab have an OpenSSF Scorecard?
Habitat-Lab has an OpenSSF Scorecard score of 5.2/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is Habitat-Lab actively maintained?
Slowing down. Last push was 46 days ago — keep an eye on whether activity resumes.
What license does Habitat-Lab use?
Habitat-Lab ships under MIT. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are Habitat-Lab's commits signed?
100% of the last 100 commits to Habitat-Lab are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.
Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.
HVTrust currently ranks supply-chain and project-integrity trust only. This public view shows a compact AI-agent surface snapshot from repo docs and manifests. These fields are descriptive context and do not affect the production HVTrust rank. An experimental local preview remains available in Score Lab →, and the policy boundary is tracked on the roadmap →
MCP Server Support
None detected
No MCP server signal detected.
Detailed evidence is not shown in the public view.
External Service Dependencies
None detected
No clear third-party provider dependency detected.
Credential signal:
No explicit API-key/config marker detected.
Tool / Plugin Surface
high confidence
2 tags
Broad capability areas detected.
code
shell
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
MCP signal live
External deps live
Tool / plugin surface live
Package provenance drift live
Maintain Habitat-Lab?
HVTrust scores Habitat-Lab from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.
Data sources
GitHub REST API (repo, commits, stars, forks, license) · OpenSSF Scorecard CLI
Each agent's signals refresh once daily across 6 staggered batches. Methodology v3.2 · Raw JSON