Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

OSS sustain guard

Sustainability signals for OSS dependencies

Details

External ID
46498786
Source
HN
Company
—
Product
OSS sustain guard
Website domain
github.io
Launched
Jan. 5, 2026
Cohort
—
Upvotes
21
Upvotes percentile
0.6587615283267457
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Hi HN, I made OSS Sustain Guard.After every high-profile OSS incident, I wonder about the packages I rely on right now. I can skim issues/PRs and activity on GitHub, but that doesn’t scale when you have tens or hundreds of dependencies. I built this to surface sustainability signals (maintainer redundancy, activity trends, funding links, etc.) and create awareness. It’s meant to start a respectful conversation, not to judge projects. These are signals, not truth; everything is inferred from public data (internal mirrors/private work won’t show up).Quick start: pip install oss-sustain-guard export GITHUB_TOKEN=... os4g checkIt uses GitHub GraphQL with local caching (no telemetry; token not uploaded/stored), and supports multiple ecosystems (Python/JS/Rust/Go/Java/etc.).Repo: https://github.com/onukura/oss-sustain-guardI’d love feedback on metric choices/thresholds and wording that stays respectful. If you have examples where these signals break down, please share.

Enrichment

Theme
git and repository workflow tools
Vertical
Horizontal
Function
Compliance & governance
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
sustainability signals for open source dependencies
Manually corrected
False

Could you build this?

Yes Scanning open-source dependency files and querying public GitHub/registry APIs to aggregate sustainability metrics like commit frequency and issue resolution times is a standard automation script.

Discussion

6 comments analyzed.

Competitors mentioned: OpenSSF Scorecard, SLSA/artifact provenance technologies, Google Assured OSS

Concerns raised: Metadata (stars, download counts) easy to fake and game, Small/lesser-known projects overlooked despite being supply-chain attack vectors, Users likely only check popular dependencies, not risky transitive ones, Manual checking process limits practical adoption

Feature requests: Harder-to-manipulate signals for sustainability assessment, Automated dependency tree analysis instead of manual checks

Competitors

Other products that read as similar to this one — 80 launches clear the similarity bar, closest 8 shown.

Attention rank: #35 of 81 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 58 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.