astral-sh/ruff vs curlpipe/ox
astral-sh/ruff shows stronger signals overall
As of June 2026, ruff shows healthier maintenance signals than ox. ruff rates Healthy overall while ox rates Mixed. ruff was committed to today with 21+ active contributors, while ox last saw a commit 2 months ago with 2+ active contributors. ruff is MIT-licensed while ox is GPL-2.0-licensed. Neither has known critical or high-severity CVEs in its dependency tree.
Informational only. RepoPilot summarises public signals at the time of analysis. Not professional, security, or legal advice.
astral-sh/ruff →
Healthy across the board
Permissive license, no critical CVEs, actively maintained — safe to depend on.
Has a license, tests, and CI — clean foundation to fork and modify.
Documented and popular — useful reference codebase to read through.
No critical CVEs, sane security posture — runnable as-is.
- ✓Last commit today
- ✓21+ active contributors
- ✓Distributed ownership (top contributor 35% of recent commits)
- ✓MIT licensed
- ✓CI configured
- ✓Tests present
Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against OpenSSF Scorecard
curlpipe/ox →
Single-maintainer risk — review before adopting
copyleft license (GPL-2.0) — review compatibility; top contributor handles 99% of recent commits
Has a license, tests, and CI — clean foundation to fork and modify.
Documented and popular — useful reference codebase to read through.
No critical CVEs, sane security posture — runnable as-is.
- ⚠Small team — 2 contributors active in recent commits
- ⚠Single-maintainer risk — top contributor 99% of recent commits
- ⚠GPL-2.0 is copyleft — check downstream compatibility
- ✓Last commit 2w ago
- ✓2 active contributors
- ✓GPL-2.0 licensed
- ✓CI configured
- ✓Tests present
What would improve this?
- →Use as dependency Concerns → Mixed if: relicense under MIT/Apache-2.0 (rare for established libs)
Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests
Signal-by-signal breakdown
| ruff | ox | |
|---|---|---|
| Stars | 48,249 | 3,700 |
| Last commit | today | 2mo ago |
| License | MIT | GPL-2.0 |
| Open issues | 2,036 | 33 |
| Has tests | ✓ | ✓ |
| Has CI | ✓ | ✓ |
| Test coverage | 100% | 24% |
| Dependency CVEs | No CVEs | No CVEs |
| Architecture grade | — | — |
| Cycles | — | — |
| Bottom-line | Healthy signals | Mixed signals |
Want the full analysis? astral-sh/ruff · curlpipe/ox
Ask AI about astral-sh/ruff vs curlpipe/ox
Open the chat with a comparison question pre-filled.