aboutcode-org/vulnerablecode
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
In plain words
Outside PRs: 8 in 10 merged. More than half of outside PRs got no reply.
Outside PRs merged
81%
13 merged, 3 closed, 13 still open
Higher than 46% of 559 other measured repositories
First human reply
Mostly unanswered
median of 29 outside PRs, 18 unanswered
Time to merge
Not enough data
13 of 29 outside PRs merged
Outside PRs opened 30 to 120 days ago, so each has had time to be answered. A figure needs at least 5 pull requests, otherwise it reads "Not enough data". How this is calculated · A number looks wrong?
Your first steps here
If you have never contributed to this project, do these in order.
- 1
Read the README
No contributing guide was found, so the README is where setup is explained.
Open the README - 2
Find something small
No first issue is free right now. Look for a typo, a missing test or an unclear error message, or ask where help is wanted.
Browse open issues - 3
Know where to ask
Questions go to the project's slack, or on the issue itself. Not in private messages.
Open it - 4
Open a small pull request
Link the issue in it. Too few outside pull requests here to say how long a reply takes.
What happens to an outside pull request
Every pull request opened by someone outside the core team, 30 to 120 days ago.
- Opened by outsiders29100%
- Got a human reply1138%
- Merged1345%
Time to first reply
After 2 days, 7% of outside PRs had a reply from a person. After a week, 17%. Bots do not count.
The last 52 weeks
Outside pull requests opened each week, and how many of them have been merged.
Starter issues
Issues labelled for beginners, with their real state. Available means open, unassigned, no linked pull request, nobody has claimed it in the last 14 days, and it was updated in the last 60 days.
- Available
- 0
- Claimed
- 0
- Has a pull request
- 9
- Stale
- 0
- Has a pull requestReplace OSSindex with new Sonatype Guide#2311
- Has a pull requestAdd data in CSAF format from https://github.com/cisagov/CSAF #1315
- Has a pull requestIngest github ecosystems#1039
When replies arrive
All maintainers counted together. Shown only when at least 3 people replied in the last 90 days, so it never describes one person.
Replies are most likely between 16:00 and 19:00 (India time).
Show as table
| Hour (India time) | Replies, all weekdays |
|---|---|
| 00:00 | 2 |
| 01:00 | 1 |
| 02:00 | 1 |
| 03:00 | 1 |
| 04:00 | 1 |
| 05:00 | 1 |
| 06:00 | 1 |
| 07:00 | 1 |
| 08:00 | 0 |
| 09:00 | 0 |
| 10:00 | 0 |
| 11:00 | 0 |
| 12:00 | 0 |
| 13:00 | 3 |
| 14:00 | 5 |
| 15:00 | 2 |
| 16:00 | 3 |
| 17:00 | 6 |
| 18:00 | 3 |
| 19:00 | 1 |
| 20:00 | 2 |
| 21:00 | 2 |
| 22:00 | 2 |
| 23:00 | 2 |
How to start
Stack
Similar repositories
Same main language (Python), most shared frameworks and topics first, then the faster reply.
Panel: The powerful data exploration & web app framework for Python
- First reply
- 8 h