Good shape overall. A few tweaks would push it into the top tier.
The MITRE Security Automation Framework (SAF) Command Line Interface (CLI) brings together applications, techniques, libraries, and tools developed by MITRE and the security community to streamline security automation for systems and DevOps pipelines
Documentation
70
No CONTRIBUTING.md found (−47 pts base + up to −53 pts more for content).
→ Add a CONTRIBUTING.md telling newcomers how to get involved. Include setup, code style, test, and PR instructions.
README is present.
README documents how to install the project.
Licensed under Other.
Engineering
79
No issue or PR templates found (−100 pts).
→ Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
CI is configured (.github/workflows/build-macos.yml).
Lockfile present (package-lock.json). Installs are reproducible.
Test files detected (test).
Linter or formatter configured (.editorconfig).
Project health
97
Dependency manifest found (package.json).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- —Commits (30d / 90d)
- 43Forks
- 102Releaseslatest 4y ago
Community
- —Community health
- —authors own >50% of commits
- 181Watchers
Responsiveness
- 4d 17hMedian issue response
- <1hMedian PR merge time
- 200Open issues
Repository files35 root entries
- .githubGood: CI is configured (.github/workflows/build-macos.yml).Good: Dependabot configured for npm.
- .vscode
- bin
- docs
- src
- testGood: Test files detected (test).
- _config.yml
- .deepsource.toml
- .editorconfigGood: Linter or formatter configured (.editorconfig).
- .env-example
- .gitignoreGood: .gitignore present.
- .nvmrc
- CNAME
- DockerfileGood: Environment pinned via Dockerfile.
- eslint.config.js
- LICENSE.mdGood: Licensed under Other.
- oclif-theme.json
- pack-hdf-converters.bat
- pack-hdf-converters.sh
- pack-heimdall-lite.bat
- pack-heimdall-lite.sh
- pack-inspec-objects.bat
- pack-inspec-objects.sh
- pack-inspecjs.bat
- pack-inspecjs.sh
- package-lock.jsonGood: Lockfile present (package-lock.json). Installs are reproducible.
- package.jsonGood: Dependency manifest found (package.json).
- README.mdGood: README is present.Good: README is well structured with multiple sections.Issue: No screenshots or images in the README (−20 pts).Fix: Add a GIF, screenshot, or logo image. It is the fastest way to show what your project does.Good: README has code examples.Good: README links to a live demo or deployed app.Issue: No status badges in the README (−10 pts).Fix: Add CI/build status badges from shields.io or your CI provider to signal project health.Good: README documents how to install the project.Good: README documents how to run the project.
- release-prep.ps1
- release-prep.sh
- saf-cli.code-workspace
- saf.spec
- tsconfig.json
- VERSION
- vitest.config.ts