OSS sustain guard
Sustainability signals for OSS dependencies
Details
- External ID
- 46498786
- Source
- HN
- Company
- —
- Product
- OSS sustain guard
- Website domain
- github.io
- Launched
- Jan. 5, 2026
- Cohort
- —
- Upvotes
- 21
- Upvotes percentile
- 0.6587615283267457
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Hi HN, I made OSS Sustain Guard.After every high-profile OSS incident, I wonder about the packages I rely on right now. I can skim issues/PRs and activity on GitHub, but that doesn’t scale when you have tens or hundreds of dependencies. I built this to surface sustainability signals (maintainer redundancy, activity trends, funding links, etc.) and create awareness. It’s meant to start a respectful conversation, not to judge projects. These are signals, not truth; everything is inferred from public data (internal mirrors/private work won’t show up).Quick start: pip install oss-sustain-guard export GITHUB_TOKEN=... os4g checkIt uses GitHub GraphQL with local caching (no telemetry; token not uploaded/stored), and supports multiple ecosystems (Python/JS/Rust/Go/Java/etc.).Repo: https://github.com/onukura/oss-sustain-guardI’d love feedback on metric choices/thresholds and wording that stays respectful. If you have examples where these signals break down, please share.
Enrichment
- Theme
- git and repository workflow tools
- Vertical
- Horizontal
- Function
- Compliance & governance
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- sustainability signals for open source dependencies
- Manually corrected
- False
Could you build this?
Yes Scanning open-source dependency files and querying public GitHub/registry APIs to aggregate sustainability metrics like commit frequency and issue resolution times is a standard automation script.
Discussion
6 comments analyzed.
Competitors mentioned: OpenSSF Scorecard, SLSA/artifact provenance technologies, Google Assured OSS
Concerns raised: Metadata (stars, download counts) easy to fake and game, Small/lesser-known projects overlooked despite being supply-chain attack vectors, Users likely only check popular dependencies, not risky transitive ones, Manual checking process limits practical adoption
Feature requests: Harder-to-manipulate signals for sustainability assessment, Automated dependency tree analysis instead of manual checks
Competitors
Other products that read as similar to this one — 80 launches clear the similarity bar, closest 8 shown.
Attention rank: #35 of 81 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 58 days after the earliest competitor.
- sustainability-score · ph · 2026-09-26 · 2 upvotes · similarity 0.40
- github-launch-checklist · github · 2026-09-17 · 194 upvotes · similarity 0.40
- Make open-source contributions fun and meaningful · hn · 2026-09-02 · 5 upvotes · similarity 0.40
- Slop Meter for GitHub · hn · 2026-03-02 · 6 upvotes · similarity 0.40
- DeployLint · ph · 2026-09-15 · 1 upvotes · similarity 0.40
- Safe-install · hn · 2026-05-12 · 19 upvotes · similarity 0.38
- Osscar · hn · 2026-04-28 · 5 upvotes · similarity 0.38
- Deployment freezes for GitHub environments (DeployFreeze) · hn · 2025-12-18 · 5 upvotes · similarity 0.38
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.