Repositories that passed

Every repository here was added by someone who controls it. There is no list of repositories that failed, and there never will be: publishing that would be a target list sorted by vulnerability. This is the opposite, and it is entirely opt-in.

Nobody has joined yet

No repository has opted in so far. Scan a repo you maintain at the repo scanner, and if it passes you will get the badge and the steps to join.

How a repository gets listed

  1. Scan the repository. It has to pass, meaning no critical and no high findings. The license is not part of that: it is shown on its own line (ADOPT, REVIEW or AVOID) so a copyleft or source-available repository is listed honestly rather than hidden or scored.
  2. Add the xlogs badge to its README. That is the consent step: only someone with write access can do it, which is how we know the request came from a maintainer rather than a stranger.
  3. Submit it. We re-scan, confirm it still passes, and confirm the badge is really there before listing it.

We ask for no account and store nothing about you. The listing holds the public repository name and the scan summary, nothing else. Remove the badge and the entry stops re-verifying, or email hello@xlogs.com to be delisted immediately.

What a badge does and does not mean

It means these specific checks found nothing at the time of the scan. It is not a certification, an audit, or a promise that the code is safe. A determined attacker can write code that pattern-based review will not catch, and we say so on the scanner page too. Treat it as one signal among several.