Run environment: Regenerated 2026-08-19 via runPublishedCejelViaNpx (npx --yes @cejel/cejel@0.4.4), executed from a clean PATH with no Homebrew cejel@0.4.1 shadow and a neutral cwd outside any @cejel/cejel-named workspace member. No rubric pin.
What this board claimed. Every row published on 2026-08-18 (Scorer source version:
@cejel/cejel@0.4.3, rubric witan-rubric-v18-prospective-2026-07-25) was
described, in the "How to read this board" section, as "produced through the same sealed
public-scoring entry point used by npx @cejel/cejel ." — a reproducibility
claim: that anyone holding the published package could regenerate these exact numbers from the
pinned commits.
What was established. That claim was false. The scores were computed by this project's
own internal engine copy (alfred/packages/witan/src, reached via the leaderboard
generator's batch.ts → public-scan.ts →
scoring.ts/rubric.ts/repo-signals.ts), never built from —
and independently confirmed to have drifted from — the published @cejel/cejel
package: it was missing detector implementations present downstream in the public source (the
V19–V22 prospective-rubric detectors), and its certificate-rendering layer never received the
0.4.2/0.4.3 label fixes. A single sample repository's score matching the published package's
output was mistaken for proof that the engine itself matched; it did not, and sibling files in the
same internal tree had independently drifted.
What was withdrawn. The scores, ranks, verdicts, and comparable figures for every row, including the per-repository certificate pages. Corpus membership and this board's methodology were not withdrawn — the design was never in question, one generation run's provenance was.
Republication condition. Scores return once regenerated by executing the published
@cejel/cejel package itself, end to end, for every row — never an internal copy that
merely resembles it.
Status: MET, 2026-08-19. Every row on this board was produced by shelling out to
npx --yes @cejel/cejel@0.4.4 <path> --out <dir> --quiet against its pinned
commit — a fresh npm resolution, no workspace import, no rubric pin, no internal engine anywhere
in the path. The reproducibility guard that checks this (rebuilt through the same
published-package invocation, rather than the internal comparison that stayed green through the
original defect) confirmed every row matches; a second, independent rescore of one row from a
separate working directory reproduced byte-identical output. Both are recorded in this
regeneration's own record.
Third-party repositories only. Overall score is one axis; coverage shows how much of the rubric Cejel could actually measure.
Hover, focus, or tap a point for its repository and figures. The abstained repository has no point because Cejel refused to produce a score.
Third-party repositories only. The distance between the two points shows where observable engineering evidence and governance discipline diverge.
These are each repository’s canonical sub-scores. Low-coverage rows remain visible but are labelled rather than ranked by the chart.
| Rank | Repository | Category | License | Overall | Comparable score (equal measured criteria) | Code trust | Process trust | Coverage | Findings | Band | Evidence |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | vite | tooling-build | MIT | 3.4 | 3.3 | 2.8 | 4.0 | code 5/5 · process 3/6 | 3 | Withheld pending calibration | certificatereportjson |
| 2 | axios | library-js | MIT | 3.3 | 3.2 | 2.6 | 3.9 | code 5/5 · process 4/6 | 4 | Withheld pending calibration | certificatereportjson |
| 3 | pydantic | library-python | MIT | 3.2 | 3.2 | 2.9 | 3.5 | code 3/5 · process 3/6 | 1 | Withheld pending calibration | certificatereportjson |
| 4 | svelte | framework-web | MIT | 3.1 | 3.1 | 2.9 | 3.3 | code 4/5 · process 3/6 | 2 | Withheld pending calibration | certificatereportjson |
| 5 | zod | library-js | MIT | 3.2 | 3.1 | 3.1 | 3.2 | code 3/5 · process 3/6 | 3 | Withheld pending calibration | certificatereportjson |
| 6 | biomejs | tooling-build | MIT OR Apache-2.0 | 3.0 | 3.0 | 2.9 | 3.0 | code 3/5 · process 4/6 | 1 | Withheld pending calibration | certificatereportjson |
| 7 | requests | library-python | Apache-2.0 | 2.9 | 3.0 | 2.4 | 3.4 | code 3/5 · process 4/6 | 1 | Withheld pending calibration | certificatereportjson |
| 8 | flask | framework-python | BSD-3-Clause | 2.9 | 2.8 | 2.7 | 3.0 | code 4/5 · process 3/6 | 3 | Withheld pending calibration | certificatereportjson |
| 9 | react | framework-web | MIT | 3.0 | 2.8 | 2.1 | 3.9 | code 5/5 · process 3/6 | 4 | Withheld pending calibration | certificatereportjson |
| 10 | scorecard | supply-chain-governance | Apache-2.0 | 2.9 | 2.8 | 2.2 | 3.6 | code 4/5 · process 3/6 | 3 | Withheld pending calibration | certificatereportjson |
| 11 | vue | framework-web | MIT | 2.9 | 2.8 | 2.4 | 3.4 | code 4/5 · process 3/6 | 3 | Withheld pending calibration | certificatereportjson |
| 12 | fmt | library-cpp | MIT | 2.6 | 2.7 | 2.0 | 3.2 | code 3/5 · process 4/6 | 3 | Withheld pending calibration | certificatereportjson |
| 13 | esbuild | tooling-build | MIT | 2.5 | 2.5 | 2.6 | 2.4 | code 3/5 · process 3/6 | 4 | Withheld pending calibration | certificatereportjson |
| 14 | ripgrep | library-rust | MIT | 2.1 | 2.1 | 2.1 | 2.0 | code 3/5 · process 3/6 | 4 | Withheld pending calibration | certificatereportjson |
| Repository | Source visibility | Category | Overall | Comparable score (equal measured criteria) | Code trust | Process trust | Coverage | Findings | Band | Evidence |
|---|---|---|---|---|---|---|---|---|---|---|
| alfred | private | internal-substrate | 3.2 | 3.2 | 3.1 | 3.3 | code 5/5 · process 4/6 | 3 | Withheld pending calibration | certificatereportjson |
| cejel | public | internal-tool | 2.8 | 2.7 | 2.3 | 3.2 | code 5/5 · process 3/6 | 4 | Withheld pending calibration | certificatereportjson |
| Repository | Category | License | Coverage | Verdict | Evidence | Reason |
|---|---|---|---|---|---|---|
| carddemo | mainframe-cobol | Apache-2.0 | code 0/5 · process 0/6 | Insufficient evidence | certificatereportjson | No free-core rubric criterion produced a measurable signal. Cejel abstains rather than publish a numeric zero for an entirely unmeasured repository. Source coverage: 9 of 250 source-shaped files (3.6%) are criterion-ratable, below the 20% reviewable-source threshold (329 tracked files in total). |
| Repository | Category | License | Overall | Comparable score (equal measured criteria) | Code trust | Process trust | Coverage | Findings | Band | Evidence | Reason |
|---|---|---|---|---|---|---|---|---|---|---|---|
| django | framework-python | BSD-3-Clause | 3.2 | 3.1 | 2.6 | 3.8 | code 3/5 · process 2/6 low confidence | 3 | Withheld pending calibration | certificatereportjson | scored on 5 of 11 dimensions — too few to rank |
| fastapi | framework-python | MIT | 3.1 | 3.1 | 3.0 | 3.2 | code 2/5 · process 3/6 low confidence | 1 | Withheld pending calibration | certificatereportjson | scored on 5 of 11 dimensions — too few to rank |
| express | framework-node | MIT | 3.0 | 3.0 | 2.8 | 3.2 | code 2/5 · process 3/6 low confidence | 0 | Withheld pending calibration | certificatereportjson | scored on 5 of 11 dimensions — too few to rank |
| sinatra | framework-ruby | MIT | 2.4 | 2.5 | 2.0 | 2.8 | code 2/5 · process 4/6 low confidence | 3 | Withheld pending calibration | certificatereportjson | scored on 6 of 11 dimensions — too few to rank |
| cobra | library-go | Apache-2.0 | 2.5 | 2.4 | 2.6 | 2.3 | code 2/5 · process 2/6 low confidence | 2 | Withheld pending calibration | certificatereportjson | scored on 4 of 11 dimensions — too few to rank |
| automapper | library-csharp | MIT | 2.2 | 2.1 | 2.0 | 2.3 | code 3/5 · process 2/6 low confidence | 4 | Withheld pending calibration | certificatereportjson | scored on 5 of 11 dimensions — too few to rank |
| guava | library-java | Apache-2.0 | 1.9 | 1.8 | 1.6 | 2.2 | code 3/5 · process 2/6 low confidence | 5 | Withheld pending calibration | certificatereportjson | scored on 5 of 11 dimensions — too few to rank |