RepoGates vs OpenSSF Scorecard

Scorecard is free, open source, and for what it measures it is the closest thing to a standard. Here is what it measures, what it does not, and when the free one is enough.

The short answer. Scorecard measures how a project is run: branch protection, pinned dependencies, signed releases, dangerous CI workflows, committed binaries. RepoGates asks whether a repository's publisher is who it looks like and what runs when you open it. The first is hygiene, the second is provenance, and a purpose-built malicious repository can have excellent hygiene. If you are grading your own project, or choosing between established ones, Scorecard is free and you should use it. If you are deciding whether to download a stranger's repository, it was not built for that question — and RepoGates reads Scorecard anyway, as one of its 22 checks.

What Scorecard is

The OpenSSF Scorecard is about twenty automated checks, run by the OpenSSF on a schedule against the projects it covers and published through a free API, with a CLI and a GitHub Action for running it yourself. Each check scores 0 to 10: Branch-Protection, Code-Review, Pinned-Dependencies, Signed-Releases, Token-Permissions, Maintained, License, Dangerous-Workflow, Binary-Artifacts and the rest. It is good work, it is free, and it is the right tool for the job it describes: telling a maintainer, or a consumer choosing between maintained projects, how carefully a project is run.

Hygiene is not provenance

The repository vetting standard RepoGates is built on reads Scorecard asymmetrically — a low score is disqualifying and a high score is meaningless — because Scorecard does not ask the question a campaign exploits. A repository published last week by an account created last week can pin every dependency, protect its main branch and sign its releases, and ship a trojan as the signed release. Nothing in a hygiene score is lowered by that.

And the campaigns live where Scorecard is mostly absent. Its public results cover the projects it scans; the great majority of GitHub — including nearly every fresh repository — has no entry. FakeGit published roughly 7,600 repositories from about 6,600 fabricated accounts; a young repository from a young account is exactly the shape that has no Scorecard result to read. A missing entry is not evidence of anything, in either direction.

Side by side

OpenSSF ScorecardRepoGates
The questionHow carefully is this project run?Should I trust this repository enough to download it?
PriceFree, open sourceFree for 10 repositories within 14 days; Personal $69 a year
CoverageThe projects it scans; any public repository if you run the CLI yourself with a GitHub tokenAny public GitHub repository you open, on demand
Owner account ageNoYes (C1) — a 45-point finding under 90 days
Stars against historyNoYes (C3)
Maintenance, licence, contributorsYes — Maintained, License, ContributorsYes (C5–C7)
Committed binariesYes — Binary-ArtifactsYes (C15), and Scorecard's own result read as C8
Dangerous CI workflowsYes — Dangerous-WorkflowRead from Scorecard (C8)
Branch protection, code review, signed releases, pinningYes — this is its coreNo
Binaries attached to releasesWhether releases are signedWhat is attached (C9) — the FakeGit delivery path
What runs when a folder opensNodevcontainer, editor tasks, build scripts, bare repositories, .envrc (C10–C17)
Agent configuration filesNoCLAUDE.md, .cursorrules, MCP launch configs, hidden Unicode (C18–C21)
That an AI assistant sent youNoYes, in the browser only (C22)
Acts at download timeNo — it is a reportHolds a browser download while the verdict is fetched, and cancels one your policy blocks

Scorecard's column is from its published checks as read for our coverage matrix, 13 August 2026. Read the project's own documentation for today's list.

How RepoGates uses Scorecard

As check C8, weighted as a second opinion on hygiene. If Dangerous-Workflow or Binary-Artifacts scores under 5 out of 10, the finding is HIGH and costs 8 points; an overall score under 3 is MEDIUM and costs 4. A good score adds nothing. A repository Scorecard has never scanned gets a note — no Scorecard entry — and no finding. C8 contributes nothing to the FakeGit catch rate, and its page says so, because fresh campaign repositories have no entry to read.

When Scorecard is enough

When it is not

Check it yourself

Scorecard's result for any project it covers is public:

curl -s https://api.scorecard.dev/projects/github.com/OWNER/REPO | jq '{score, checks: [.checks[] | {name, score}]}'

A 404 means unscanned, not bad. Then ask the question Scorecard does not — how old is the owner?

gh api users/OWNER --jq '{created_at, public_repos, followers}'

What RepoGates does not cover

RepoGates gates browser-initiated downloads — Download ZIP, release-asset archives, Save Link As. It does not see git clone, package managers, curl, or fetches made by AI agents outside the browser. A browser extension cannot observe other processes, and a PASS is not a statement that the code is good.

Questions

OpenSSF Scorecard is free. Why pay for RepoGates? Because they answer different questions. Scorecard measures how a project is run — branch protection, pinned dependencies, signed releases, dangerous CI workflows, committed binaries. A purpose-built malicious repository can score well on all of it, and most fresh repositories, which is where the campaigns live, have no Scorecard entry at all. RepoGates asks who published the repository and since when, whether its popularity matches its history, what is attached to its releases, what runs when you open it, and whether an AI assistant sent you. If your question is hygiene, Scorecard is free and good. If it is whether to trust a stranger's repository, Scorecard was not built to answer it.

Does RepoGates use Scorecard? Yes, as one of its 22 checks (C8). If Scorecard's Dangerous-Workflow or Binary-Artifacts check scores under 5 out of 10, that costs 8 points; an overall score under 3 costs 4. A good Scorecard adds nothing, and a repository Scorecard has never scanned gets a note, not a finding — a low score is disqualifying, a high score is not evidence of anything.

Does a high Scorecard mean a repository is safe? No, and the same is true of a RepoGates PASS. Scorecard measures process hygiene; a repository can protect its branches, pin its dependencies and sign its releases while shipping a trojan as the signed release. A RepoGates PASS means none of its 22 checks fired at a level your policy acts on — not that the code is good.

Add RepoGates to Chrome or Edge How C8 reads Scorecard

Numbers on this page: Island and BleepingComputer, July 2026 (FakeGit); weights and thresholds from the product's policy and scoring tables; our coverage matrix of 22 checks against about 45 products, 13 August 2026. OpenSSF Scorecard is a project of the Open Source Security Foundation; this page is our reading of its public documentation. Also compare: RepoGates vs Socket.dev.