RepoPilot

keras-team/keras vs sapientinc/hrm

keras-team/keras shows stronger signals overall

As of June 2026, keras shows healthier maintenance signals than hrm. keras rates Healthy overall while hrm rates Mixed. keras was committed to today with 25+ active contributors, while hrm last saw a commit 2 months ago with 5+ active contributors. Both use the Apache-2.0 license. Neither has known critical or high-severity CVEs in its dependency tree.

Informational only. RepoPilot summarises public signals at the time of analysis. Not professional, security, or legal advice.

keras-team/keras

Healthy

Healthy across all four use cases

HealthyDependency

Permissive license, no critical CVEs, actively maintained — safe to depend on.

HealthyFork & modify

Has a license, tests, and CI — clean foundation to fork and modify.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

HealthyDeploy as-is

No critical CVEs, sane security posture — runnable as-is.

  • Scorecard: known vulnerabilities detected (scored 0/10 by OpenSSF)
  • Last commit 1d ago
  • 25+ active contributors
  • Distributed ownership (top contributor 14% of recent commits)
  • Apache-2.0 licensed
  • CI configured
  • Tests present

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against OpenSSF Scorecard

sapientinc/hrm

Mixed

Mixed signals — read the receipts

MixedDependency

no tests detected; no CI workflows detected

HealthyFork & modify

Has a license, tests, and CI — clean foundation to fork and modify.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

MixedDeploy as-is

Scorecard "Branch-Protection" is 0/10; no CI workflows detected

  • Concentrated ownership — top contributor handles 50% of recent commits
  • No CI workflows detected
  • No test directory detected
  • Scorecard: default branch unprotected (0/10)
  • Last commit 7w ago
  • 5 active contributors
  • Apache-2.0 licensed

What would improve this?

  • Use as dependency MixedHealthy if: add a test suite
  • Deploy as-is MixedHealthy if: bring "Branch-Protection" to ≥3/10 (see scorecard report)

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against OpenSSF Scorecard

Signal-by-signal breakdown

kerashrm
Stars64,09712,432
Last committoday2mo ago
LicenseApache-2.0Apache-2.0
Open issues21976
Has tests
Has CI
Test coverage1%0%
Dependency CVEsNo CVEsNo CVEs
Architecture grade
Cycles
Bottom-lineHealthy signalsMixed signals

Want the full analysis? keras-team/keras · sapientinc/hrm

Ask AI about keras-team/keras vs sapientinc/hrm

Open the chat with a comparison question pre-filled.