developer workflowsossf/scorecard: Run a Local Repository Risk Audit Before You Trust a Green Badge
Run OpenSSF Scorecard locally, preserve the exact revision and findings, and decide which repository risks require investigation before adoption.
Read the guide
AI ops and monitoringGitHub Actions GITHUB_TOKEN Audit: Reduce Workflow Permissions Before a Third-Party Action Runs
Audit GitHub Actions token permissions job by job, pin third-party actions, and test the workflow after removing write access it does not need.
Read the guide
agent tools and workflowsmodelcontextprotocol/servers: Audit an MCP Server Before Giving It Files, Tokens, or Network Access
Audit an MCP server’s tools, credentials, file reach, and network side effects before connecting it to an AI client or production account.
Read the guide
GitHub AI project watchlistComfy-Org/ComfyUI: Test Workflow Portability Before Installing Custom Nodes
Test a ComfyUI workflow on a clean profile, record models and dependencies, and identify custom-node lock-in before a graph becomes hard to reproduce.
Read the guide
Open-source AI comparisonsollama/ollama vs ggml-org/llama.cpp: Choose a Local Model Server With a Measured Workload
Compare Ollama and llama.cpp using one pinned model, repeatable prompts, latency, memory, concurrency, API needs, and recovery behavior.
Read the guide
model release analysisEvaluate a Coding Agent With One Bug, One Test, and a Diff You Can Review
Evaluate a coding agent on one real bug with a frozen repository, hidden test, clean-diff rubric, cost record, and reproducible review artifacts.
Read the guide