Know your contributors

Inspect the provenance of any open source contributor at a glance. Trace contribution history, assess license obligations, and surface trust signals before they become risks.

Features

Trust Scoring

23 signals across 5 weighted categories produce a transparent trust score and letter grade for any GitHub contributor.

Risk Narratives

AI-powered analysis explains why a contributor is flagged — not just an abstract number, but full context.

Behavioral Analysis

Historical data-powered heuristics detect burst-vanish patterns, velocity anomalies, and synthetic profiles.

Bot Detection

Identify bot accounts and AI-generated contributions as a separate transparency dimension.

License Footprint

See the license obligations across every repo to which a contributor has committed.

CI/CD Integration

Automate PR author scoring in your repo with a GitHub Action to gate merges on contributor trust.

Compliance Mapping

Signals map to 8 of 20 NIST SSDF practices — audit-ready evidence of contributor vetting.

REST API

Integrate trust scoring into your existing internal systems using the DevTrace API.

How this service is operated

DevTrace has no plans, no pricing, and no subscriptions — every feature is available to every account.

It is operated on a best-effort basis: no SLA, no uptime guarantee, and no support commitment. Per-account limits exist only to keep the shared instance responsive for everyone using it.

The source for this service is on GitHub, under the Apache License 2.0. You are welcome to run your own instance.