Add your description here
Project description
OSS Sustain Guard
Multi-language package sustainability analyzer - Evaluate your dependencies' health with 24 metrics including Contributor Redundancy, Maintainer Retention, and Security Signals.
📌 Quick Notes:
- Local caching - Popular packages served from efficient local cache for faster results
- SSL verification - Use
--insecureflag to disable SSL verification for development/testing only- Package resolution - If a package cannot be resolved to a GitHub repository, it will be skipped with a notification
- Full documentation - https://onukura.github.io/oss-sustain-guard/
💡 Project Philosophy
OSS Sustain Guard is designed to spark thoughtful conversations about open-source sustainability, not to pass judgment on projects. Our mission is to raise awareness about the challenges maintainers face and encourage the community to think together about how we can better support the open-source ecosystem.
We believe that:
- 🌱 Sustainability matters - Open-source projects need ongoing support to thrive
- 🤝 Community support is essential - For community-driven projects, we highlight funding opportunities to help users give back
- 📊 Transparency helps everyone - By providing objective metrics, we help maintainers and users make informed decisions
- 🎯 Respectful evaluation - We distinguish between corporate-backed and community-driven projects, recognizing their different sustainability models
- 💝 Supporting maintainers - When available, we display funding links for community projects to encourage direct support
This tool is meant to be a conversation starter about OSS sustainability, not a judgment. Every project has unique circumstances, and metrics are just one part of the story.
🎯 Key Features
- 24 Sustainability Metrics - Comprehensive evaluation across maintainer health, development activity, community engagement, project maturity, and security (all metrics scored 0-10)
- Optional Dependents Analysis - Downstream dependency metrics (informational, not affecting total score)
- 5 CHAOSS-Aligned Models - Risk, Sustainability, Community Engagement, Project Maturity, and Contributor Experience
- Metric-Weighted Scoring - Configurable scoring profiles with integer weights per metric, normalized to 0-100 scale
- Multi-Language Support - Python, JavaScript, Go, Rust, PHP, Java, Kotlin, C#, Ruby
- Community Support Awareness - Displays funding links for community-driven projects
- Local Caching - Efficient local cache for faster repeated checks
- CI/CD Integration - GitHub Actions, Pre-commit hooks
- Zero Configuration - Works out of the box
🚀 Quick Start
# Install
pip install oss-sustain-guard
# Set GitHub token (required for all package analysis)
export GITHUB_TOKEN='your_token_here' # Get from: https://github.com/settings/tokens/new
# Check a single package
os4g check requests
# Check multiple packages (auto-detect language)
os4g check django flask numpy
# Multi-language support
os4g check python:requests npm:react rust:tokio r:ggplot2 haskell:text swift:apple/swift-nio
# Auto-detect from manifest files
os4g check --include-lock
# Scan recursively (great for monorepos)
os4g check --recursive
📚 Documentation
For detailed usage, configuration, and features, see our documentation site:
- Getting Started - Installation and basic usage
- Scoring Profiles - Different evaluation perspectives
- GitHub Actions Integration - CI/CD setup
- Pre-Commit Hooks - Automated checks
- Exclude Packages - Configuration
- FAQ - Common questions
Supported Ecosystems
Python, JavaScript, Go, Rust, PHP, Java, Kotlin, C#, Ruby, R, Haskell, Swift, Dart, Elixir, Perl
See Getting Started for ecosystem-specific syntax.
24 Sustainability Metrics
Evaluated across 5 categories:
- Maintainer Health (25%) - Contributor diversity and retention
- Development Activity (20%) - Release rhythm and recent activity
- Community Engagement (20%) - Issue/PR responsiveness
- Project Maturity (15%) - Documentation and governance
- Security & Funding (20%) - Security posture and sustainability
Score interpretation: 80-100 (Healthy) | 50-79 (Monitor) | 0-49 (Needs Attention)
Special Features
-
🎁 Gratitude Vending Machine - Discover community projects that need support
os4g gratitude --top 5
-
� Community Funding Links - Auto-displays funding options for community-driven projects
🤝 Contributing
See CONTRIBUTING.md for development setup, testing, code style, and architecture documentation.
�📝 Documentation
-
Scoring Profiles Guide - Different evaluation perspectives
-
Pre-Commit Integration - Hook configuration
-
GitHub Actions Guide - CI/CD setup
-
Exclude Packages Guide - Package filtering
📄 License
MIT License
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file oss_sustain_guard-0.13.2.tar.gz.
File metadata
- Download URL: oss_sustain_guard-0.13.2.tar.gz
- Upload date:
- Size: 370.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
74cac911d6af785b684c96bdaafdd0a3045febf94aa229c5a581280605bdfd8b
|
|
| MD5 |
07b7a9cc74ebe708bbda3bdcfbefba78
|
|
| BLAKE2b-256 |
33238b2cb001aad3c21ebd8f0b66dd206bb605c8a42dcacf8a95fb87829fa443
|
Provenance
The following attestation bundles were made for oss_sustain_guard-0.13.2.tar.gz:
Publisher:
publish.yml on onukura/oss-sustain-guard
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
oss_sustain_guard-0.13.2.tar.gz -
Subject digest:
74cac911d6af785b684c96bdaafdd0a3045febf94aa229c5a581280605bdfd8b - Sigstore transparency entry: 782753736
- Sigstore integration time:
-
Permalink:
onukura/oss-sustain-guard@ccbbda044a0766ed1b6ce1d6e5906a1b28f1bea4 -
Branch / Tag:
refs/tags/v0.13.2 - Owner: https://github.com/onukura
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@ccbbda044a0766ed1b6ce1d6e5906a1b28f1bea4 -
Trigger Event:
push
-
Statement type:
File details
Details for the file oss_sustain_guard-0.13.2-py3-none-any.whl.
File metadata
- Download URL: oss_sustain_guard-0.13.2-py3-none-any.whl
- Upload date:
- Size: 98.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f8b8457180159841c3d04444c55245f3d58b30eb901a40d6690eec2a6c291c0d
|
|
| MD5 |
2fe06ee0d719a0480ab4477a484ea8a9
|
|
| BLAKE2b-256 |
18fbc6c044eb9f9d9c4da940b797798d8ded24b92744c28d02abe0dc229bea77
|
Provenance
The following attestation bundles were made for oss_sustain_guard-0.13.2-py3-none-any.whl:
Publisher:
publish.yml on onukura/oss-sustain-guard
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
oss_sustain_guard-0.13.2-py3-none-any.whl -
Subject digest:
f8b8457180159841c3d04444c55245f3d58b30eb901a40d6690eec2a6c291c0d - Sigstore transparency entry: 782753755
- Sigstore integration time:
-
Permalink:
onukura/oss-sustain-guard@ccbbda044a0766ed1b6ce1d6e5906a1b28f1bea4 -
Branch / Tag:
refs/tags/v0.13.2 - Owner: https://github.com/onukura
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@ccbbda044a0766ed1b6ce1d6e5906a1b28f1bea4 -
Trigger Event:
push
-
Statement type: