Tools
Tools for finding work, checking a project’s health, licensing, securing, releasing and funding it. Each entry has one line on what it does; Links were checked in October 2026.
Know a tool that belongs here? Suggest it in the Open {re}Source discussions.
Automation#
- actions/first-interaction – Posts a welcome message on a contributor’s first issue or PR.
- actions/labeler – Labels PRs from the paths they touch.
- actions/stale – Marks inactive issues and PRs as stale, then closes them.
- GitHub CLI – GitHub from the terminal: PRs, issues, releases and the API (`gh`).
- Probot – Framework for building GitHub Apps in Node.js.
- Todoctor by Azat S. – Tracks `TODO` comments in JavaScript and TypeScript repositories and charts them by type, with a table of every occurrence.
Community#
- All Contributors – A bot and a spec to credit every kind of contribution in your README, not only code.
- Better GitHub Co-Authors by Chris Swithinbank – Browser extension that adds an "Add co-authors" button to the PR merge UI, collecting every participant as a "Co-authored-by" trailer. It credits reviewers and commenters, not only code contributors.
- Contributor Covenant – The most adopted code of conduct, with translations.
- Discourse – Forum software, open source and self-hostable, for long conversations and support.
- giscus – Comments for your site, stored in GitHub Discussions.
- Zulip – Open source chat organized in topics, so threads stay readable.
Docs and sites#
- cspell – Spell checker for code and docs, with a project dictionary for names and terms.
- DocSearch – Algolia’s free search for open source documentation sites.
- Docusaurus – Meta’s React-based docs framework, with versioning and a blog.
- lychee – Fast link checker for Markdown and HTML, with a GitHub Action.
- MkDocs – Python static site generator for docs. The core project’s last commit dates from October 2025; Material for MkDocs is the usual theme.
- Pagefind – Static search that runs on the built site, with no server.
- Starlight – Documentation theme for Astro, with navigation, search and i18n built in.
- VitePress – Vue-powered static site generator for docs, from Markdown.
Finding work#
- CodeTriage – Subscribe to a repository and get open issues by email to triage or fix.
- ecosyste.ms – Open datasets and tools on packages, repositories and funding, to find critical projects that need help.
- goodfirstissue.dev – Good first issues from popular repositories, filtered by language and topic.
- OSS Insight – Trends, rankings and contributor analytics for GitHub repositories, built on GH Archive.
- Up For Grabs – Projects that tag issues for newcomers, each with the label to search for.
Funding#
FUNDING.yml– The file that adds a Sponsor button to your repository and points to your funding pages.- GitHub Sponsors – Recurring and one-time sponsorships.
- Open Collective – Transparent funding for a project or a group, with a public ledger and a fiscal host.
- Polar – Sponsorships, funded issues and paid benefits for maintainers.
- SponsorKit – Generates an image of your sponsors from several platforms, for a README. Read our article.
- thanks.dev – Splits a monthly amount across the open source dependencies your projects use.
Repository health and stats#
- contrib.rocks – An image of a repository’s top contributors to embed in its README. Read our article.
- deps.dev – Google’s view of a package: versions, dependency graph, advisories, licenses and Scorecard results.
- Libraries.io – Search packages across ecosystems and see who depends on them.
- OpenSSF Scorecard – Automated checks on the security practices of a repository, scored from 0 to 10.
- Repobeats – An image of a repository’s recent activity to embed in its README. Read our article.
- Star History – Star growth charts for one or several repositories, as an image or an embed.
Licensing#
- Choose a License – GitHub’s plain-language guide to picking a license, with a summary of each common one.
- FOSSA – Commercial license compliance and dependency scanning.
- license-checker-rseidelsohn – Lists the licenses of every npm dependency. The maintained fork of `license-checker`, whose last commit dates from January 2024.
- licensee – The Ruby library GitHub uses to detect which license a repository has.
- OSS Review Toolkit – Analyzes dependencies, scans them and produces a compliance report and an SBOM.
- REUSE – A specification and a lint tool (`reuse lint`) to declare the license and copyright of every file.
- ScanCode Toolkit – Scans source code for licenses, copyrights and dependencies, offline.
- SPDX License List – The standard identifiers to use in `LICENSE` metadata, with the full text of each license.
Local AI#
- Obsidian – Local Markdown notes with plugins, one of which talks to Ollama. Read our article.
- Ollama – Runs open models on your machine with one command. Read our article.
Releases#
- Changesets – Contributors add a small file per change; the release bumps versions and writes the changelog. Built for monorepos.
- GitHub generated release notes – Release notes built from merged PRs, grouped by label with a `.github/release.yml` file.
- Keep a Changelog – A format for human-written changelogs: one section per version, grouped by kind of change.
- release-please – Opens a release PR from your Conventional Commits, then tags and publishes on merge.
- semantic-release – Fully automated versioning and publishing, driven by commit messages.
Security#
- CodeQL – GitHub’s code scanning: finds vulnerabilities by querying your code as data.
- Dependabot – GitHub’s alerts and automatic update PRs for vulnerable or outdated dependencies.
- Gitleaks – Finds secrets in a repository and its history, as a CLI or a pre-commit hook.
- Grype – Scans an image, a directory or an SBOM for known vulnerabilities. Pairs with Syft.
- OSV-Scanner – Matches your lockfiles against the OSV vulnerability database.
- Renovate – Dependency update PRs with grouping, schedules and presets, on GitHub, GitLab and others.
- Socket – Flags risky behavior in the packages you add (install scripts, network access, typosquats) before you merge.
- StepSecurity Harden-Runner – Restricts and audits the network calls of a GitHub Actions runner.
- Syft – Generates an SBOM from a directory, a container image or an archive.
Social#
- Bluesky starter packs – Lists of accounts that a newcomer follows in one click, a way to gather a community. Read our article.
- OpenGraph.xyz – Previews how a link looks when shared on social networks, and checks its meta tags.
- Shields.io – Badges for READMEs: build status, version, downloads, sponsors.
- Slidev – Slides from Markdown, for developers. Exports to PDF, which is how we make LinkedIn carousels. Read our article.