Free Public Repository Grade
Ask for a letter grade for any public GitHub repository, no account needed. Claim it to show a README badge and join the leaderboard.
Ask for a grade
Open app.launchsafe.com/grade and enter a public GitHub repository, as owner/name or its address. No account is needed. Private, internal or missing repositories answer that the repository is not available. The repository is checked as it is on its default branch.
Paste a public repository and the grade is usually ready in about a minute. You see a letter and four counts, and nothing else.
What a grade is
A grade is a letter and four counts: critical, high, medium and low. Nothing public names a finding, a file or a rule.
| Grade | Rule |
|---|---|
| A | Nothing medium or above |
| B | Medium only |
| C | One or two high |
| D | Three or more high |
| F | Anything critical |
It counts issues in the code and its dependencies, verified, not scanner noise. It never counts leaked secrets, never counts findings from live tests, and does not count issues the owner marked as false positives. The page also shows which commit was graded and when.
Claim your repository
An organization that linked a public repository through the GitHub App can claim its grade: Projects → your project → Repositories → Public grade. Only an organization that linked it can claim it, and one organization holds a repository's claim at a time. Owners and admins choose:
- whether the grade is shown on its public page and badge;
- whether it is listed on the leaderboard.
Hiding it removes it from the page, the badge and the leaderboard at once. The grade comes from your own complete scans of the default branch. A scan that stopped early, did not cover the code and its dependencies, or left paths out does not count.
A newer grade that is worse (more critical or high issues, or new ones) waits up to 14 days before it replaces the one shown, so you can fix first. You can publish it sooner. The badge turns red when new issues appeared.
README badge
Every grade page has the badge's Markdown for your README. It reads "LaunchSafe | grade B", for example, and stays current. It says "not public" while hidden. A badge is cached for a few minutes, so changes take a little while to show.
Leaderboard
app.launchsafe.com/grade/leaderboard lists claimed repositories whose owners chose to list them, best grade first, filtered by language and size.
Limits
Requests are limited per network to protect everyone. A person has to be on the page: asking for a grade needs a human check.