Free Public Repository Grade

Ask for a letter grade for any public GitHub repository, no account needed. Claim it to show a README badge and join the leaderboard.

Edit on GitHub

Ask for a grade

Open app.launchsafe.com/grade and enter a public GitHub repository, as owner/name or its address. No account is needed. Private, internal or missing repositories answer that the repository is not available. The repository is checked as it is on its default branch.

Paste a public repository and the grade is usually ready in about a minute. You see a letter and four counts, and nothing else.

What a grade is

A grade is a letter and four counts: critical, high, medium and low. Nothing public names a finding, a file or a rule.

GradeRule
ANothing medium or above
BMedium only
COne or two high
DThree or more high
FAnything critical

It counts issues in the code and its dependencies, verified, not scanner noise. It never counts leaked secrets, never counts findings from live tests, and does not count issues the owner marked as false positives. The page also shows which commit was graded and when.

Claim your repository

An organization that linked a public repository through the GitHub App can claim its grade: Projects → your project → Repositories → Public grade. Only an organization that linked it can claim it, and one organization holds a repository's claim at a time. Owners and admins choose:

  • whether the grade is shown on its public page and badge;
  • whether it is listed on the leaderboard.

Hiding it removes it from the page, the badge and the leaderboard at once. The grade comes from your own complete scans of the default branch. A scan that stopped early, did not cover the code and its dependencies, or left paths out does not count.

A newer grade that is worse (more critical or high issues, or new ones) waits up to 14 days before it replaces the one shown, so you can fix first. You can publish it sooner. The badge turns red when new issues appeared.

README badge

Every grade page has the badge's Markdown for your README. It reads "LaunchSafe | grade B", for example, and stays current. It says "not public" while hidden. A badge is cached for a few minutes, so changes take a little while to show.

Leaderboard

app.launchsafe.com/grade/leaderboard lists claimed repositories whose owners chose to list them, best grade first, filtered by language and size.

Limits

Requests are limited per network to protect everyone. A person has to be on the page: asking for a grade needs a human check.

On this page