Skip to content

Scores

The program's repositories against the scale, scored on 2026-09-28 by scripts/score.py, one run per repository from a local clone with platform access.

This file is written by scripts/render_scores.py, and scripts/render_scores.py --check fails when the committed copy no longer matches what the scorer produces. It is a checkpoint command rather than a pipeline gate, because it reads clones and the platform that a runner does not have, which is why this document sits at level 3 of its own scale and not at 4.

manifest-identity: 3.5 of 5 across 12 rules (application)

Rule Level Evidence
readme 4 README.md present; this scorer runs in CI
license 4 LICENSE present; this scorer runs in CI
security-policy 4 SECURITY.md present; this scorer runs in CI
contributing 4 CONTRIBUTING.md present; this scorer runs in CI
decisions-record 4 74 numbered entries; a test recounts them
commit-subjects 4 all 17 recent subjects lead with an identifier; CI walks the messages
pinned-actions 5 all 28 uses are pinned by commit; a workflow audit gates it; proven: https://github.com/manifest-identity/manifest-identity/actions/runs/33565119678
ci-gate 4 10 required checks on the mainline: analyze (actions), analyze (python), application, container, doctrine, floor, links, secrets, workflows, writing
dependency-updates 3 update automation configured
run-instructions 1 README has a run section with a command block
troubleshooting 1 README names the likely failures
counted-figures 4 4 bold figures; a test recounts them from the source
generated-artifact-parity n/a not applicable to an application repository

build-doctrine: 3.7 of 5 across 10 rules (doctrine)

Rule Level Evidence
readme 4 README.md present; this scorer runs in CI
license 4 LICENSE present; this scorer runs in CI
security-policy 4 SECURITY.md present; this scorer runs in CI
contributing 4 CONTRIBUTING.md present; this scorer runs in CI
decisions-record 4 34 numbered entries; a test recounts them
commit-subjects 3 all 16 recent subjects lead with an identifier; verified by this scorer
pinned-actions 4 all 15 uses are pinned by commit; a workflow audit gates it
ci-gate 4 5 required checks on the mainline: analyze, links, prose, secrets, workflows
dependency-updates 3 update automation configured
run-instructions n/a not applicable to a doctrine repository
troubleshooting n/a not applicable to a doctrine repository
counted-figures n/a not applicable to a doctrine repository
generated-artifact-parity 3 render_scores.py verifies the generated artifact, checked on demand

aws-azure-security-mapping: 2.9 of 5 across 9 rules (reference)

Rule Level Evidence
readme 3 README.md present; checked on demand by this scorer
license 3 LICENSE present; checked on demand by this scorer
security-policy 3 SECURITY.md present; checked on demand by this scorer
contributing 3 CONTRIBUTING.md present; checked on demand by this scorer
decisions-record n/a not applicable to a reference repository
commit-subjects 3 all 3 recent subjects lead with an identifier; verified by this scorer
pinned-actions 3 the one use is pinned by commit; verified by this scorer
ci-gate 4 1 required check on the mainline: table
dependency-updates n/a not applicable to a reference repository
run-instructions 0 README has no run section
troubleshooting n/a not applicable to a reference repository
counted-figures n/a not applicable to a reference repository
generated-artifact-parity 4 render_table.py verifies the generated artifact and CI runs it

SampleDiagrams: 2.0 of 5 across 3 rules (diagrams)

Rule Level Evidence
readme 3 README.md present; checked on demand by this scorer
license 3 LICENSE present; checked on demand by this scorer
security-policy n/a not applicable to a diagrams repository
contributing n/a not applicable to a diagrams repository
decisions-record n/a not applicable to a diagrams repository
commit-subjects 0 2 of 3 recent subjects lack a leading identifier
pinned-actions n/a not applicable to a diagrams repository
ci-gate n/a not applicable to a diagrams repository
dependency-updates n/a not applicable to a diagrams repository
run-instructions n/a not applicable to a diagrams repository
troubleshooting n/a not applicable to a diagrams repository
counted-figures n/a not applicable to a diagrams repository
generated-artifact-parity n/a not applicable to a diagrams repository

anki-decks: 2.1 of 5 across 9 rules (study)

Rule Level Evidence
readme 3 README.md present; checked on demand by this scorer
license 3 LICENSE present; checked on demand by this scorer
security-policy 3 SECURITY.md present; checked on demand by this scorer
contributing 3 CONTRIBUTING.md present; checked on demand by this scorer
decisions-record n/a not applicable to a study repository
commit-subjects 3 all 12 recent subjects lead with an identifier; verified by this scorer
pinned-actions 3 the one use is pinned by commit; verified by this scorer
ci-gate 1 workflows exist but nothing is required to merge
dependency-updates n/a not applicable to a study repository
run-instructions 0 README has no run section
troubleshooting n/a not applicable to a study repository
counted-figures n/a not applicable to a study repository
generated-artifact-parity 0 no parity check for generated artifacts

secure-expense-mvp: 1.6 of 5 across 11 rules (application)

Rule Level Evidence
readme 3 README.md present; checked on demand by this scorer
license 3 LICENSE present; checked on demand by this scorer
security-policy 3 SECURITY.md present; checked on demand by this scorer
contributing n/a excluded: finished on purpose; the README says so and no contributions are invited
decisions-record 0 no DECISIONS.md
commit-subjects 0 5 of 10 recent subjects lack a leading identifier
pinned-actions 4 all 5 uses are pinned by commit; a workflow audit gates it
ci-gate 1 workflows exist but nothing is required to merge
dependency-updates 3 update automation configured
run-instructions 1 README has a run section with a command block
troubleshooting 0 README has no troubleshooting section
counted-figures 0 README states no figures
generated-artifact-parity n/a not applicable to an application repository

tltaylor1: 1.5 of 5 across 2 rules (profile)

Rule Level Evidence
readme 3 README.md present; checked on demand by this scorer
license n/a not applicable to a profile repository
security-policy n/a not applicable to a profile repository
contributing n/a not applicable to a profile repository
decisions-record n/a not applicable to a profile repository
commit-subjects 0 5 of 25 recent subjects lack a leading identifier
pinned-actions n/a not applicable to a profile repository
ci-gate n/a not applicable to a profile repository
dependency-updates n/a not applicable to a profile repository
run-instructions n/a not applicable to a profile repository
troubleshooting n/a not applicable to a profile repository
counted-figures n/a not applicable to a profile repository
generated-artifact-parity n/a not applicable to a profile repository