Skip to content

ToolHive on HVTrust (Grade B, 70.9) β€” and an optional badgeΒ #6744

Description

@YugantM

Hi ToolHive / Stacklok team πŸ‘‹

I maintain HVTracker (hvtracker.net), an independent trust registry for open-source AI-agent and MCP tooling, scored on public supply-chain signals. (Disclosure: I run it β€” heads-up from the author.) As folks who build security tooling, you'll recognize the inputs.

ToolHive scores Grade B, 70.9/100, with an OpenSSF Scorecard of 8.1/10 and 100% signed commits β€” strong, as you'd expect from Stacklok. Full breakdown: https://hvtracker.net/agents/toolhive/

The gap to Grade A is build provenance β€” SLSA/attestations on the Go release artifacts would close most of it (right up your alley). If a self-updating HVTrust badge is useful alongside your other signals:

[![HVTrust](https://hvtracker.net/badge/toolhive.svg)](https://hvtracker.net/agents/toolhive/)

Optional, and I'll fix anything we scored wrong. Thanks for pushing secure-by-default MCP tooling.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageIssue needs initial triage by a maintainer

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions