RepoPilot

astral-sh/ruff vs guillaumegomez/sysinfo

astral-sh/ruff shows stronger signals overall

As of June 2026, ruff shows healthier maintenance signals than sysinfo. ruff rates Healthy overall while sysinfo rates Mixed. ruff was committed to today with 21+ active contributors, while sysinfo was committed to 2 days ago with 10+ active contributors. Both use the MIT license. Neither has known critical or high-severity CVEs in its dependency tree.

Informational only. RepoPilot summarises public signals at the time of analysis. Not professional, security, or legal advice.

astral-sh/ruff

Healthy

Healthy across the board

HealthyDependency

Permissive license, no critical CVEs, actively maintained — safe to depend on.

HealthyFork & modify

Has a license, tests, and CI — clean foundation to fork and modify.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

HealthyDeploy as-is

No critical CVEs, sane security posture — runnable as-is.

  • Last commit today
  • 21+ active contributors
  • Distributed ownership (top contributor 35% of recent commits)
  • MIT licensed
  • CI configured
  • Tests present

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against OpenSSF Scorecard

guillaumegomez/sysinfo

Mixed

Single-maintainer risk — review before adopting

HealthyDependency

Permissive license, no critical CVEs, actively maintained — safe to depend on.

HealthyFork & modify

Has a license, tests, and CI — clean foundation to fork and modify.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

MixedDeploy as-is

Scorecard "Branch-Protection" is 0/10; 3 cyclic import chains — pervasive coupling

  • Single-maintainer risk — top contributor 82% of recent commits
  • Scorecard: default branch unprotected (0/10)
  • Last commit 1d ago
  • 10 active contributors
  • MIT licensed
  • CI configured
  • Tests present

What would improve this?

  • Deploy as-is MixedHealthy if: bring "Branch-Protection" to ≥3/10 (see scorecard report)

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against dependency CVEs from deps.dev and OpenSSF Scorecard

Signal-by-signal breakdown

ruffsysinfo
Stars48,2492,712
Last committoday2d ago
LicenseMITMIT
Open issues2,03660
Has tests
Has CI
Test coverage100%19%
Dependency CVEsNo CVEsNo CVEs
Architecture gradeB
Cycles3
Bottom-lineHealthy signalsMixed signals

Want the full analysis? astral-sh/ruff · guillaumegomez/sysinfo

Ask AI about astral-sh/ruff vs guillaumegomez/sysinfo

Open the chat with a comparison question pre-filled.