Cejel OSS trust leaderboard

Run date: 2026-08-19T14:49:46.851Z

Cejel version: @cejel/cejel@0.4.4 (published, npx) · Rubric version: witan-rubric-v17-2026-07-24 (calibrated default, unpinned)

Run environment: Regenerated 2026-08-19 via runPublishedCejelViaNpx (npx --yes @cejel/cejel@0.4.4), executed from a clean PATH with no Homebrew cejel@0.4.1 shadow and a neutral cwd outside any @cejel/cejel-named workspace member. No rubric pin.

History

2026-08-18: scores withdrawn and why

What this board claimed. Every row published on 2026-08-18 (Scorer source version: @cejel/cejel@0.4.3, rubric witan-rubric-v18-prospective-2026-07-25) was described, in the "How to read this board" section, as "produced through the same sealed public-scoring entry point used by npx @cejel/cejel ." — a reproducibility claim: that anyone holding the published package could regenerate these exact numbers from the pinned commits.

What was established. That claim was false. The scores were computed by this project's own internal engine copy (alfred/packages/witan/src, reached via the leaderboard generator's batch.tspublic-scan.tsscoring.ts/rubric.ts/repo-signals.ts), never built from — and independently confirmed to have drifted from — the published @cejel/cejel package: it was missing detector implementations present downstream in the public source (the V19–V22 prospective-rubric detectors), and its certificate-rendering layer never received the 0.4.2/0.4.3 label fixes. A single sample repository's score matching the published package's output was mistaken for proof that the engine itself matched; it did not, and sibling files in the same internal tree had independently drifted.

What was withdrawn. The scores, ranks, verdicts, and comparable figures for every row, including the per-repository certificate pages. Corpus membership and this board's methodology were not withdrawn — the design was never in question, one generation run's provenance was.

Republication condition. Scores return once regenerated by executing the published @cejel/cejel package itself, end to end, for every row — never an internal copy that merely resembles it.

Status: MET, 2026-08-19. Every row on this board was produced by shelling out to npx --yes @cejel/cejel@0.4.4 <path> --out <dir> --quiet against its pinned commit — a fresh npm resolution, no workspace import, no rubric pin, no internal engine anywhere in the path. The reproducibility guard that checks this (rebuilt through the same published-package invocation, rather than the internal comparison that stayed green through the original defect) confirmed every row matches; a second, independent rescore of one row from a separate working directory reproduced byte-identical output. Both are recorded in this regeneration's own record.

How to read this board

Evidence map

Third-party repositories only. Overall score is one axis; coverage shows how much of the rubric Cejel could actually measure.

21 scored · 1 abstention
Ranked (14) Low coverage, unranked (7) Verdict bands withheld pending calibration

Hover, focus, or tap a point for its repository and figures. The abstained repository has no point because Cejel refused to produce a score.

Code trust versus Process trust

Third-party repositories only. The distance between the two points shows where observable engineering evidence and governance discipline diverge.

21 repositories
Code trust Process trust Gap between them

These are each repository’s canonical sub-scores. Low-coverage rows remain visible but are labelled rather than ranked by the chart.

Ranking

This public ranking contains third-party repositories only. It is ordered by "Comparable score (equal measured criteria)": two repository-inapplicable dimensions are excluded uniformly and every remaining measured criterion receives equal weight. Thin buckets therefore cannot take half the headline by construction. Verdict bands are withheld pending calibration. Rows below the coverage floor are excluded from this table. Repositories without enough evidence for any score are excluded here too; see "Unrated — insufficient source or measurable evidence" below — nothing is hidden, only left unordered or unscored.

RankRepositoryCategoryLicenseOverallComparable score (equal measured criteria)Code trustProcess trustCoverageFindingsBandEvidence
1vitetooling-buildMIT3.43.32.84.0code 5/5 · process 3/63Withheld pending calibrationcertificatereportjson
2axioslibrary-jsMIT3.33.22.63.9code 5/5 · process 4/64Withheld pending calibrationcertificatereportjson
3pydanticlibrary-pythonMIT3.23.22.93.5code 3/5 · process 3/61Withheld pending calibrationcertificatereportjson
4svelteframework-webMIT3.13.12.93.3code 4/5 · process 3/62Withheld pending calibrationcertificatereportjson
5zodlibrary-jsMIT3.23.13.13.2code 3/5 · process 3/63Withheld pending calibrationcertificatereportjson
6biomejstooling-buildMIT OR Apache-2.03.03.02.93.0code 3/5 · process 4/61Withheld pending calibrationcertificatereportjson
7requestslibrary-pythonApache-2.02.93.02.43.4code 3/5 · process 4/61Withheld pending calibrationcertificatereportjson
8flaskframework-pythonBSD-3-Clause2.92.82.73.0code 4/5 · process 3/63Withheld pending calibrationcertificatereportjson
9reactframework-webMIT3.02.82.13.9code 5/5 · process 3/64Withheld pending calibrationcertificatereportjson
10scorecardsupply-chain-governanceApache-2.02.92.82.23.6code 4/5 · process 3/63Withheld pending calibrationcertificatereportjson
11vueframework-webMIT2.92.82.43.4code 4/5 · process 3/63Withheld pending calibrationcertificatereportjson
12fmtlibrary-cppMIT2.62.72.03.2code 3/5 · process 4/63Withheld pending calibrationcertificatereportjson
13esbuildtooling-buildMIT2.52.52.62.4code 3/5 · process 3/64Withheld pending calibrationcertificatereportjson
14ripgreplibrary-rustMIT2.12.12.12.0code 3/5 · process 3/64Withheld pending calibrationcertificatereportjson

Our own code — shown for transparency, not ranked

Publisher-owned repositories are disclosed as transparency snapshots outside the calibrated public population. They receive no rank and no verdict band. Alfred is private and cannot be independently reproduced; Cejel is public and independently inspectable.

RepositorySource visibilityCategoryOverallComparable score (equal measured criteria)Code trustProcess trustCoverageFindingsBandEvidence
alfredprivateinternal-substrate3.23.23.13.3code 5/5 · process 4/63Withheld pending calibrationcertificatereportjson
cejelpublicinternal-tool2.82.72.33.2code 5/5 · process 3/64Withheld pending calibrationcertificatereportjson

Unrated — insufficient source or measurable evidence

We publish repositories we cannot score. A row here means either that Cejel established structural source absence or that a real source tree produced zero measurable free-core criteria. The Verdict and Reason columns distinguish those cases. Neither state is a zero or a low number dressed up as a judgment: Cejel issues no score and no rank when the evidence does not support one.

RepositoryCategoryLicenseCoverageVerdictEvidenceReason
carddemomainframe-cobolApache-2.0code 0/5 · process 0/6Insufficient evidencecertificatereportjsonNo free-core rubric criterion produced a measurable signal. Cejel abstains rather than publish a numeric zero for an entirely unmeasured repository. Source coverage: 9 of 250 source-shaped files (3.6%) are criterion-ratable, below the 20% reviewable-source threshold (329 tracked files in total).

Unranked — insufficient coverage

Below the coverage floor: scored on fewer than half of the applicable dimensions, so the score is weaker evidence than a well-covered row. Published in full — same rubric, same numbers — simply not ordered against better-evidenced rows above.

RepositoryCategoryLicenseOverallComparable score (equal measured criteria)Code trustProcess trustCoverageFindingsBandEvidenceReason
djangoframework-pythonBSD-3-Clause3.23.12.63.8code 3/5 · process 2/6 low confidence3Withheld pending calibrationcertificatereportjsonscored on 5 of 11 dimensions — too few to rank
fastapiframework-pythonMIT3.13.13.03.2code 2/5 · process 3/6 low confidence1Withheld pending calibrationcertificatereportjsonscored on 5 of 11 dimensions — too few to rank
expressframework-nodeMIT3.03.02.83.2code 2/5 · process 3/6 low confidence0Withheld pending calibrationcertificatereportjsonscored on 5 of 11 dimensions — too few to rank
sinatraframework-rubyMIT2.42.52.02.8code 2/5 · process 4/6 low confidence3Withheld pending calibrationcertificatereportjsonscored on 6 of 11 dimensions — too few to rank
cobralibrary-goApache-2.02.52.42.62.3code 2/5 · process 2/6 low confidence2Withheld pending calibrationcertificatereportjsonscored on 4 of 11 dimensions — too few to rank
automapperlibrary-csharpMIT2.22.12.02.3code 3/5 · process 2/6 low confidence4Withheld pending calibrationcertificatereportjsonscored on 5 of 11 dimensions — too few to rank
guavalibrary-javaApache-2.01.91.81.62.2code 3/5 · process 2/6 low confidence5Withheld pending calibrationcertificatereportjsonscored on 5 of 11 dimensions — too few to rank

By category

framework-node

framework-python

framework-ruby

framework-web

library-cpp

library-csharp

library-go

library-java

library-js

library-python

library-rust

mainframe-cobol

supply-chain-governance

tooling-build