Trust and health report
PocketFlow-Tutorial-Codebase-Knowledge - trust report
Sourced, dated trust signals - maintenance label posture, repository provenance, and security scan status. Not a composite safety grade.
GraphCanon updated 2d · GitHub synced 2d
Maintenance
Recency and activity heuristics from public GitHub metadata (maintenance label, momentum); methodology: github_public_v1.
last push 78d ago
+176 stars (30d) · +1 open issues (30d)
Provenance
Repository identity and fork provenance (github_public_v1).
- GitHub repo id: 959473422
- Not a fork
- Verified publisher: organization account
- Computed 2d
Security intelligence
Source-by-source security scan results from public intelligence providers. Missing, partial, or failed queries are shown explicitly and are not treated as clean.
OSV dependency advisories
Published findings- Last query
- 1mo
- Scanner
- osv@v1
- Stored findings
- 23
OpenSSF Scorecard
Not queried- Scanner
- openssf-scorecard@v1
Weekly public scans omit some checks at scale.
View source evidenceDependency advisories (deduplicated)
Method and caveats: these are sourced, dated heuristics from public GitHub data and external security intelligence providers. A status like "no published findings from this source" is not a guarantee of safety. Read the full trust methodology · JSON report at /api/graphcanon/tools/the-pocket-pocketflow-tutorial-codebase-knowledge/trust.
Common questions
- Is PocketFlow-Tutorial-Codebase-Knowledge maintained?
- GraphCanon rates PocketFlow-Tutorial-Codebase-Knowledge "Steady" (60% maintenance signal from public GitHub metadata, computed 2d). Last push was 78 days ago. This is a recency heuristic, not a guarantee the project will stay maintained.
- Is PocketFlow-Tutorial-Codebase-Knowledge safe to use?
- Last scanned 1mo (deps profile). Status: 23 low - 23 low finding(s) in the latest scan. GraphCanon does not claim the project is safe or vulnerability-free; review findings on the trust report. GraphCanon does not certify PocketFlow-Tutorial-Codebase-Knowledge as safe - review maintenance, provenance, and scan findings on this page before adopting.
- Is PocketFlow-Tutorial-Codebase-Knowledge a fork?
- No. PocketFlow-Tutorial-Codebase-Knowledge is not flagged as a fork in GitHub metadata at the time of the last refresh.
- Does PocketFlow-Tutorial-Codebase-Knowledge have known security vulnerabilities?
- Last scanned 1mo (deps profile). Status: 23 low - 23 low finding(s) in the latest scan. GraphCanon does not claim the project is safe or vulnerability-free; review findings on the trust report.
- How often is the PocketFlow-Tutorial-Codebase-Knowledge trust report updated?
- Trust signals refresh on GitHub ingest/refresh cycles and optional dependency/MCP scans. This report was computed 2d (methodology github_public_v1).
- What does GraphCanon never claim about PocketFlow-Tutorial-Codebase-Knowledge?
- We never publish a composite safety grade, pen-test endorsement, or "verified secure" label for PocketFlow-Tutorial-Codebase-Knowledge. Signals are sourced heuristics with explicit limits - see trust methodology.
- How does GraphCanon assess trust for PocketFlow-Tutorial-Codebase-Knowledge?
- Signals are sourced from public GitHub metadata and optional dependency/MCP manifest scans, each tagged with methodology version and computed date. GraphCanon does not publish a composite safety grade. Read trust methodology for full scope and limits.